decrypted · 26 september 2026 · vulnerabilities and patching · supply chain · uk policy and law

Kiteworks asks customers to switch off for six hours, and has not said why

Kiteworks, the maker of a widely used secure file-sharing product, has asked customers worldwide to switch their servers off for six hours. In the UK the window runs from 3am to 9am on Saturday 26 September. The company says law enforcement gave it credible intelligence that an attack may be imminent. It has not said a flaw has been found, and it says it knows of no compromise. It is an unusual request, and it tells you something about your own estate.

What has actually been said

Chief information security officer Frank Balonis told customers that Kiteworks had received credible threat intelligence that a threat actor may attempt to target some customer systems. The company calls the advice precautionary, not a response to a breach. It says every vulnerability it knows of is fixed in version 9.5.1, and tells customers to run the latest release.

What is missing matters as much. There is no CVE number and no technical detail. The agency behind the warning is unnamed, and the FBI declined to comment. Customer support staff mentioned a possible zero-day, meaning a flaw the vendor has not yet found, but neither official statement confirms one. Treat everything beyond the warning itself as unverified. An analyst quoted by The Record called a weekend power-down request with no technical detail unprecedented.

Why switching off is the only move left

Picture a building manager told by police that a burglar holds a master key for the lock on the front door. Nobody has seen the key, so the locks cannot be changed. The one certain defence is to bolt the building for the risky hours. You cannot patch a flaw nobody has described, so the remaining control is availability. Heise reports the advice applies even to servers not reachable from the internet, because the route in is unknown.

The history explains the nerves. Kiteworks was formerly Accellion, whose file-transfer product was exploited at scale by the Clop extortion gang, with hundreds of organisations having data stolen. File-transfer tools attract that crowd because they exist to hold other people's sensitive files and they sit at the edge of the network. TechCrunch says thousands of customers span healthcare, education, government and more.

The Secure by Design lesson

This is opinion, not advice, but the lesson is bigger than Kiteworks. Any internet-facing product that stores your most sensitive data will one day prompt a warning like this. Four cheap checks:

The costs are configuration and a phone tree, not a new budget line. Organisations that have rehearsed will lose six quiet hours. Those that have not will discover their dependencies live, on a Saturday.

We found no Kiteworks statement issued after the window opened. Watch for a CVE, a named actor or confirmed compromise; until then, this is a warning, not an incident.

Also this week

Dyfed-Powys Police. The force confirmed on Friday a cyber attack it identified on 14 September. Non-emergency systems and online contact were disrupted, while 999 and 101 stayed available. It says it has found no evidence that public data was accessed, and is still investigating whether staff information was. Tarian, the regional organised crime unit, leads the inquiry, and no group had claimed responsibility. The design lesson is segmentation: keep the systems that must not fail on their own island. Eleven days from discovery to public confirmation is a useful benchmark against your own plan.

JetBrains TeamCity. CISA warned this week that CVE-2026-63077, a critical authentication bypass in TeamCity On-Premises, is now used in ransomware campaigns. JetBrains patched it on 25 July, CISA listed it as exploited on 5 August, and Shadowserver counts just over 160 unpatched servers still online, down from about 700. Separately, JetBrains disclosed that attackers used the flaw to breach its own Cadence service between 8 and 24 August, taking AWS credentials. A build server holds the keys to everything it builds, so patch it like production and keep it off the open internet.

TikTok and the ICO. On 24 September the ICO said TikTok has withdrawn two appeals. The £12.7 million fine issued in 2023 over children's data, including inadequate age checks and missing parental consent, is now final. The ICO can also resume its investigation into how TikTok's recommender systems use the data of 13 to 17 year olds, which the appeal had stalled. ICO Deputy Commissioner Emily Keaney said: "How companies design online services and use children's personal information has a significant impact on young people's experience in the digital world." Design for children first, because a regulator will eventually ask.

Sources

If your file-transfer or build servers need a Secure by Design review before the next warning arrives, get in touch.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.

Play here Loads Apple's player when you press it.