LawFlash

Kiteworks Warns of Imminent Cyber Threat, Urges Customers to Shut Down Systems

25 сентября 2026 г.

Kiteworks has issued an unusual precautionary warning to customers after receiving what the company describes as credible intelligence indicating that a threat actor may attempt to exploit a newly discovered vulnerability that Kiteworks is working to address. There is no evidence that any system has been compromised or that a zero-day vulnerability has been exploited, so this is a proactive and precautionary measure.

Kiteworks has recommended that customers temporarily shut down affected Kiteworks systems this weekend while the company and law enforcement continue to assess the threat. For East Coast US organizations, published reports identify the recommended shutdown window as 10:00 pm ET Friday, September 25 through 4:00 am ET Saturday, September 26, with Kiteworks reportedly advising customers to take systems offline before that window where practicable.

At this time, Kiteworks has stated that it is not aware of any compromise of Kiteworks systems and that the advisory is precautionary rather than a response to a confirmed breach.

All organizations should take the following steps immediately:

  • Determine whether the organization operates or relies upon Kiteworks systems and identify the affected environment, deployment model, and business processes.
  • Review and follow any emergency instructions received directly from Kiteworks.
  • Preserve relevant system, authentication, network, and security logs before shutdown and ensure appropriate logging and monitoring are available when systems are restored.
  • Take affected Kiteworks systems offline and keep them offline at least until September 28. Restore service only when Kiteworks provides sufficient confirmation that it is safe to do so. Organizations should avoid restoring systems merely because the initially announced precautionary window has expired.
  • Review recent activity involving Kiteworks for alerts, anomalous authentication, administrative activity, unexpected transfers, newly created accounts or tokens, unusual outbound communications, or other indicators that may warrant escalation and investigation.
  • Identify the categories of confidential, personal, regulated, or other sensitive information accessible through the environment so that incident-response and notification obligations can be evaluated promptly if evidence of unauthorized access emerges.
  • Coordinate cybersecurity, legal, privacy, compliance, business-continuity, and communications personnel now rather than waiting for confirmation of exploitation.
  • Contact the Morgan Lewis cybersecurity team for further assistance and information.

Organizations should be careful not to treat the current warning as evidence that any environment has been compromised. At present, publicly available information does not establish that a zero-day vulnerability has been successfully exploited or that data has been accessed without authorization. The circumstances remain fluid, however, and additional technical information or mitigation guidance may emerge quickly.

Morgan Lewis's cybersecurity, incident response, and privacy team is monitoring developments and is available to assist organizations with assessing exposure, coordinating technical response efforts under privilege, preserving evidence, evaluating legal and regulatory obligations, and responding to inquiries from customers and other stakeholders.