Secure file-transfer vendor KiteWorks has told customers to shut their servers down this weekend, after what its chief information security officer calls credible information from law-enforcement agencies about an imminent attack.

In an email reviewed by heise security, KiteWorks CISO Frank Balonis wrote that the company had received "credible information from law enforcement about a threat situation indicating that an attack on Kiteworks systems may be imminent this weekend," and urged recipients to take their systems down for six hours. The warning appears to be global: the listed time zones run from Australian Eastern Standard Time to Pacific Daylight Time, and in Central Europe the window falls on Saturday, 26 September, from 04:00 to 10:00. KiteWorks recommends switching servers off before the window opens — including machines that are not reachable from the internet, because the company says it cannot be sure which access paths exist.

Asked for confirmation, KiteWorks customer support told heise: "The reason why we ask you to shut down the servers is to protect against possible zero-day attacks." Germany's Federal Office for Information Security (BSI) and the Federal Criminal Police Office (BKA) did not respond to requests for comment in time; heise notes that the authenticity of the warning itself is not in doubt.

Why this is not a routine maintenance notice

KiteWorks sells secure, confidential communication and file exchange, aimed squarely at public authorities and financial institutions — exactly the kind of data an attacker would want. According to heise, German customers include several state banks and insurers, a media group, consultancies and prominent automotive suppliers. The security industry is on the list too: KiteWorks advertises a partnership with Mandiant, a Google subsidiary.

The pattern will look familiar to anyone who followed the MOVEit and FlexPLM campaigns, in which the cl0p extortion gang compromised widely deployed transfer software and then ransomed the organizations downstream of it. Ransomware crews favour zero-days precisely because a working exploit against a popular enterprise tool scales: one flaw, thousands of victims.

What administrators should take away

- Follow the instruction and take instances offline regardless of version and regardless of whether they face the internet. - Ask the vendor for specifics in writing — patch status, indicators of compromise, and whether a fix is coming. - Plan for the fact that a six-hour outage in the middle of a weekend is not free: file transfers, partner integrations and automated workflows that depend on the platform will stall. - Treat the warning as an emergency action taken on law-enforcement intelligence, not as proof an attack has already occurred. The threat may not materialize.

The caveat worth stating out loud

Vendors almost never ask an entire customer base to go dark. That KiteWorks did so suggests the information it received was specific and that it has no patch ready. But a shutdown based on unverifiable threat intelligence is a blunt instrument: it costs customers real money and, if repeated often enough, trains them to ignore the next alarm. The coming hours will show whether the intelligence was well founded — and whether KiteWorks can convert a blanket outage into a fix.