September 27, 2026
Kiteworks Precautionary Shutdown Advisory for Customers
Intro

By SOCFortress
3 min read
Intro
Kiteworks has released a preventive advisory urging clients to execute a nine-hour system shutdown over the weekend, following federal warnings about potential targeting by threat actors. Officials emphasize that this measure is purely proactive, as there is no evidence of any actual security breaches or compromised environments. Users who manage their own platforms on-premises or through cloud providers must manually power down their systems, while the company will handle the process for hosted clients. Although all known system weaknesses have already been resolved in version 9.5.1, the organization is cooperating with government authorities out of an abundance of caution. Customers seeking further clarification or technical assistance regarding the scheduled maintenance window can reach out directly to Kiteworks support channels.
Advisory Intelligence
This protocol is issued following the receipt of credible threat intelligence from federal intelligence authorities. Intelligence indicates that a threat actor may attempt to target specific Kiteworks systems. In response, we have shifted to a proactive risk posture to maintain availability and long-term operational resiliency during an active threat window. This tactical de-escalation โ a preventative shutdown of infrastructure โ prioritizes the preservation of system integrity over the high-stakes remediation required following a confirmed breach.
By executing this "abundance of caution" approach, organizations implement a strategic barrier that preserves the foundational trust of the Zero Trust Data Exchange. This protocol is a preemptive measure; there is currently no indication that Kiteworks or customer systems have been compromised. This advisory is strictly localized to the Kiteworks platform and does not extend to subsidiary environments, including Zivver, DRACOON, totemo, ownCloud, WAMNET, Maytech, Bonfy.ai, or 123FormBuilder.
Successful execution of this protocol requires a clear understanding of the demarcation of duties between Kiteworks and its client base to ensure no infrastructure remains exposed.
Scope of Operational Responsibility
To ensure a comprehensive security posture during the identified threat window, a clear division of operational tasks is required. The responsibility for executing the power-down sequence is dictated by the specific deployment model of the Kiteworks environment.
Responsibility Matrix for Precautionary Shutdown
For organizations maintaining a "Self-Managed" status โ whether infrastructure is hosted on-premises or within a virtual private cloud (AWS/Azure) โ the mandate for manual execution lies with internal IT and security operations. Conversely, customers utilizing the Kiteworks-hosted model require no manual intervention, as the process is managed centrally by Kiteworks.
Once the scope of responsibility is established, adherence to the specific chronological triggers of the shutdown window is the next priority for global synchronization.
The Nine-Hour Shutdown Window
This execution framework serves as a calculated tactical pause. The nine-hour duration is designed to span the most probable period of identified actor activity while simultaneously minimizing the Mean Time To Recovery (MTTR) for critical business units. Synchronizing this window to the customer's specific local time zone ensures that the global security posture is hardened during the period of highest localized risk.
Timing Requirements for Implementation:
- Duration: The shutdown must be maintained for a total of nine hours.
- Scheduling: This window must be implemented this weekend.
- Time Zone Adherence: Execution must occur according to the customer's specific local time zone.
Adhering to these chronological requirements is an operational necessity. By temporarily removing the attack surface, organizations effectively neutralize the threat vector identified by federal intelligence authorities. Once the shutdown window concludes, the protocol transitions to the technical requirements for system restoration and hardening.
Technical Remediation and Version Compliance
Prior to re-admitting traffic, system restoration must be treated as a "Pre-Restoration Gate." In a Zero Trust architecture, rigorous versioning is the primary defense mechanism against known vulnerabilities.
IT teams are directed to verify and, if necessary, update all environments to Version 9.5.1. This release is the current official version and has been specifically engineered to account for all known vulnerabilities. Restoring an outdated version constitutes a breach of protocol and significantly elevates the organizational risk profile.
Official Risk Management Recommendation: Kiteworks officially recommends that all customers consistently run the latest version of the platform โ currently Version 9.5.1 โ to ensure all known security patches and hardening measures are active.
As organizations move through the restoration phase, regional support infrastructure is available to ensure business continuity and technical guidance.
Regional Support Pathways and Escalation Matrix
The strategic value of localized support infrastructure is critical for maintaining continuity during the shutdown process. Kiteworks provides the following digital and telephonic pathways for direct escalation to technical subject matter experts.
Technical Support Contacts
Digital Pathways
- Support Email: support@kiteworks.com
- Community Portal: https://community.kiteworks.com
- Web Support: https://kiteworks.com/support
North America
- Phone: +1โ888โ654โ3778
International Escalation
- General: +1โ650โ485โ4350
- Australia: +61 (0)2 7908 3819
- Germany: +49 (0)711 9533โ9989
- Israel: +972 (0)2 374โ0148
- New Zealand: +64 (0)4 831โ0761
- Singapore: +65 3159 3269
- United Kingdom: +44 (0)20 3608โ6370
This protocol is a fundamental component of our mission-critical goal: empowering organizations to effectively manage risk in every send, share, receive, and use/save of private data.