Kiteworks
   HOME

TheInfoList



OR:

Kiteworks, formerly known as Accellion, Inc., is an American technology company that secures sensitive content communications over channels such as
email Electronic mail (usually shortened to email; alternatively hyphenated e-mail) is a method of transmitting and receiving Digital media, digital messages using electronics, electronic devices over a computer network. It was conceived in the ...
, file share,
file transfer File transfer is the transmission of a computer file through a communication channel from one computer system to another. Typically, file transfer is mediated by a communications protocol. In the history of computing, numerous file transfer protoc ...
, managed file transfer, web forms, and application programming interfaces. The company was founded in 1999 in
Singapore Singapore, officially the Republic of Singapore, is an island country and city-state in Southeast Asia. The country's territory comprises one main island, 63 satellite islands and islets, and one outlying islet. It is about one degree ...
and is now based in
San Mateo, California San Mateo ( ) is the most populous city in San Mateo County, California, United States, on the San Francisco Peninsula. It is part of the San Francisco Bay Area metropolitan region, and is located about south of San Francisco. San Mateo border ...
. The Kiteworks Private Data Network consolidates file and email data communications onto a single platform, enabling organizations to reduce data privacy exposure risk and demonstrate conformance with a variety of regulations. In 2022, Kiteworks stated that its products were used by over 3,800 organizations worldwide. In late 2020, a zero-day exploit in Accellion’s legacy 20-year-old File Transfer Appliance (FTA) product led to data breaches of dozens of government and private organizations. The vulnerabilities were confirmed only in the FTA and not in the Kiteworks platform, which has a separate
codebase In software development, a codebase (or code base) is a collection of source code used to build a particular software system, application, or software component. Typically, a codebase includes only human-written source code system files; thu ...
. In August 2024, Kiteworks raised US$456 million from
Insight Partners Insight Venture Management, LLC (commonly referred to as Insight Partners and previously Insight Venture Partners) is a global venture capital and private equity firm that invests in high-growth technology, software, and internet businesses. The ...
and Sixth Street, valuing it at over US$1 billion.


History

The company was founded as Accellion in Singapore in 1999 and was originally focused on distributed file storage. The company moved to
Palo Alto Palo Alto ( ; Spanish language, Spanish for ) is a charter city in northwestern Santa Clara County, California, United States, in the San Francisco Bay Area, named after a Sequoia sempervirens, coastal redwood tree known as El Palo Alto. Th ...
,
California California () is a U.S. state, state in the Western United States that lies on the West Coast of the United States, Pacific Coast. It borders Oregon to the north, Nevada and Arizona to the east, and shares Mexico–United States border, an ...
and shifted its focus on secure file transmission. Accellion reached a total funding of about $35 million in 2011, and it was valued at $500 million in 2014. The company's
chief executive officer A chief executive officer (CEO), also known as a chief executive or managing director, is the top-ranking corporate officer charged with the management of an organization, usually a company or a nonprofit organization. CEOs find roles in variou ...
, Yorgen Edholm, credited aversion to "
National Security Agency The National Security Agency (NSA) is an intelligence agency of the United States Department of Defense, under the authority of the director of national intelligence (DNI). The NSA is responsible for global monitoring, collection, and proces ...
—style snooping" as a factor in their success. In January 2012, Accellion raised $12.2 million in funding from Riverwood Capital to continue their expansion. In 2016, Accellion started to focus on security and compliance and released features that included
data security Data security or data protection means protecting digital data, such as those in a database, from destructive forces and from the unwanted actions of unauthorized users, such as a cyberattack or a data breach. Technologies Disk encryption ...
, governance, and compliance. They also began integrations with major cybersecurity
independent software vendor An independent software vendor (ISV), also known as a software publisher, is an organization specializing in making and selling software, in contrast to computer hardware, designed for mass or niche markets. This is in contrast to in-house softwa ...
s (ISVs). In April 2020, the company received $120 million investment from Bregal Sagemount. In October 2020, Accellion was rebranded as Kiteworks. In January 2022, Kiteworks acquired totemo, an email encryption gateway provider based in
Zurich Zurich (; ) is the list of cities in Switzerland, largest city in Switzerland and the capital of the canton of Zurich. It is in north-central Switzerland, at the northwestern tip of Lake Zurich. , the municipality had 448,664 inhabitants. The ...
, Switzerland. It is integrated into the Kiteworks Private Data Networks and Kiteworks Email Protection Gateway. In November 2023, it was announced that Kiteworks had acquired German
ownCloud ownCloud is a Free Software Foundation, free and open-source software project for content collaboration, File sharing, file-sharing, and file-syncing. It's usable in distributed and Federation (information technology), federated enterprise scena ...
and DRACOON which it intends to use as stepping stones into the European market, and Maytech, based in
Tunbridge Wells Royal Tunbridge Wells (formerly, until 1909, and still commonly Tunbridge Wells) is a town in Kent, England, southeast of Central London. It lies close to the border with East Sussex on the northern edge of the High Weald, whose sandstone ...
, to bolster its UK market presence and secure data transfer capabilities. In October 2023, Kiteworks completed a SOC 2 Type II audit examination and received ISO/IEC 27001:2013, 27017:2015, and 27018:2019 certifications for its platform. As of 2024, Kiteworks is used by 100 million users across over 3,800 organizations.


Software

Accellion was working on file transfer systems by late 2002. The company released a file transfer appliance in 2005, a physical machine aiming to reduce server load when sending large files. In March 2011, the company released an online file collaboration product, emphasizing security. In 2012, the company launched a service allowing file sharing between mobile devices. It included a synchronization feature called kitedrive. Early demand for the company's file transfer applications came from organizations that needed to transfer large files, including healthcare companies and universities. In January 2014, Accellion launched Kiteworks, a file sharing product allowing users to edit files and projects remotely, with interoperability with services like
Google Drive Google Drive is a file-hosting service and synchronization service developed by Google. Launched on April 24, 2012, Google Drive allows users to store files in the cloud (on Google servers), synchronize files across devices, and share files ...
and
Dropbox Dropbox is a file hosting service operated by the American company Dropbox, Inc., headquartered in San Francisco, California, that offers cloud storage, file synchronization, personal cloud, and Client (computing), client software. Dropbox w ...
. That December, the company released a set of programming interfaces extending secure file access to mobile devices. In 2015, ''
PCMag ''PC Magazine'' (shortened as ''PCMag'') is an American computer magazine published by Ziff Davis. A print edition was published from 1982 to January 2009. Publication of online editions started in late 1994 and continues . Overview ''PC Magaz ...
'' reviewer, Fahmida Y. Rashid, praised Kiteworks for its interface, support for mobile devices, and privacy tools. In June 2017, Kiteworks received FedRAMP Authorization for Moderate Level Impact of Controlled Unclassified Information (CUI). It has achieved FedRAMP certification every year since. In November 2018, Kiteworks released the CISO Dashboard. In March 2022, Kiteworks was recognized by the Information Security Registered Assessors Program (IRAP) after being evaluated for up to the Protected data classification level. In August 2022, Kiteworks introduced the Kiteworks Private Data Network, a zero-trust protection and compliance platform for unstructured data communications. In April 2023, Kiteworks announced that it had achieved Cyber Essentials and Cyber Essentials Plus accreditation, the highest standard for IT security in the United Kingdom. Also, in the same month, it announced that the Kiteworks Private Data Network supports the
National Institute of Standards and Technology The National Institute of Standards and Technology (NIST) is an agency of the United States Department of Commerce whose mission is to promote American innovation and industrial competitiveness. NIST's activities are organized into Outline of p ...
Cybersecurity Framework (NIST CSF), which allows users to better manage content-based risks. In February 2024, Kiteworks introduced a feature called SafeEDIT, which is a
digital rights management Digital rights management (DRM) is the management of legal access to digital content. Various tools or technological protection measures, such as access control technologies, can restrict the use of proprietary hardware and copyrighted works. DRM ...
(DRM) technology that enables users to edit various file types natively and share files with third parties using video streaming.


2020–21 security breaches

In mid-December 2020, the company's File Transfer Appliance product—now a 20-year-old legacy system—was subject to a zero-day exploit, which was patched on December 23. Three additional vulnerabilities were discovered and patched over the next month. The first vulnerability was a
SQL injection In computing, SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the database contents to the attacker). SQL injec ...
, allowing an attacker to use a
web shell A web shell is a Shell (computing), shell-like interface that enables a web server to be remotely accessed, often for the purposes of cyberattacks. A web shell is unique in that a web browser is used to interact with it. A web shell could be pro ...
to run arbitrary commands and extract data. The four vulnerabilities were assigned
Common Vulnerabilities and Exposures The Common Vulnerabilities and Exposures (CVE) system, originally Common Vulnerability Enumeration, provides a reference method for publicly known information security, information-security vulnerability (computing), vulnerabilities and exposures ...
(CVE) codes 2021-27101 through 2021-27104 on February 16, 2021. Out of approximately 300 total FTA clients, up to 25 appeared to have suffered significant data theft including
Kroger The Kroger Company, or simply Kroger, is an American retail company that operates (either directly or through its subsidiaries) supermarkets and multi-department stores throughout the United States. Founded by Bernard Kroger in 1883 in Cinc ...
, Shell Oil Company, the
University of California The University of California (UC) is a public university, public Land-grant university, land-grant research university, research university system in the U.S. state of California. Headquartered in Oakland, California, Oakland, the system is co ...
system, the
Australian Securities and Investments Commission The Australian Securities and Investments Commission (ASIC) is an independent commission of the Australian Government tasked as the national corporate regulator. ASIC's role is to regulate company and financial services and enforce laws to pro ...
, the
Reserve Bank of New Zealand The Reserve Bank of New Zealand (RBNZ) () is the central bank of New Zealand. It was established in 1934 and is currently constituted under the ''Reserve Bank of New Zealand Act 2021''. The current acting governor of the Reserve Bank, Christian ...
, and
Singtel Singapore Telecommunications Limited, trading as Singtel, is a Singaporean telecommunications conglomerate, the country's principal fixed-line operator and one of the four major mobile network operators operating in the country. Overview T ...
. Data stolen included Social Security numbers and other identification numbers, images of
passport A passport is an official travel document issued by a government that certifies a person's identity and nationality for international travel. A passport allows its bearer to enter and temporarily reside in a foreign country, access local aid ...
s, financial information, driver's license data, and emails. According to computer security firm FireEye, the attackers comprised two hacking groups: one with ties to " Clop", a ransomware group, and one connected to financial crime group "FIN11". Many victims received extortion emails containing a .onion link to a website containing data dumps of multiple organizations. Prior to the attacks, Accellion had maintained that the FTA was a legacy product nearing the end of its life, with support ending on April 30, 2021, asking customers to move to their Kiteworks system. In January 2022, Accellion proposed that it would pay an $8.1m settlement in relation to these breaches. The proposed settlement will settle all legal actions against Accellion only. These do not take into account legal actions against clients impacted by the data breach.


References


External links


Official website
{{DEFAULTSORT:Kiteworks Cloud applications Data synchronization File sharing services One-click hosting File hosting File sharing American companies established in 1999