A ShareFile security threat now forces Progress Software The company has sent out an urgent email to all ShareFile customers running so-called Storage Zone Controllers, urging them to immediately shut down their servers. The background is what the company describes as a credible external security threat targeting the file management platform's locally installed components.
ShareFile is Progress' platform for secure file sharing and collaboration in enterprise environments. Most customers store their files in Progress' own cloud infrastructure, but organizations with special requirements can instead install Storage Zone Controllers on their own Windows servers. This way, files can remain in their own storage environment, while ShareFile's cloud service handles authentication, user management, and sharing.

In this type of hybrid setup, Storage Zone Controller as a bridge between the cloud platform and the company's own storage. When a user uploads or downloads a file, the traffic is routed through the customer's own server, which is therefore usually exposed to the internet. This makes the component an attractive target for attackers, and it is precisely this exposure that is now at the center of the warning.
Customers must manually shut down the servers
The warning email, which was sent out on Thursday evening with the headline “"Service Disruption. Immediate Action Required"”, went to all customers using the on-premises component. According to Progress, there is currently no indication that anyone has gained unauthorized access to customer data or ShareFile accounts, but as a precautionary measure, the company has temporarily blocked access to all accounts using Storage Zone Controllers.
Progress, however, is not content with simply disabling access from the cloud side. Customers are also instructed to manually shut down the Windows servers running the component, suggesting that a blocker in the cloud platform is not considered sufficient to ward off the threat. The company calls the extra step crucial to protecting customer data.
The company states that it is working with internal and external cybersecurity experts to investigate this. ShareFile security threats, and that customers should receive a new status update within 24 hours. ShareFile's status page states that the service is currently not operational for customers with Storage Zone Controllers.
Echoes of the Moveit attack
Progress has not confirmed whether the threat is a zero-day vulnerability or if any servers have already been compromised, but the situation is very reminiscent of previous waves of attacks on enterprise file transfer solutions.
In 2023, the Clop ransomware group exploited a zero-day vulnerability in Progress' own product Moveit Transfer to steal data from thousands of organizations worldwide, which was followed by a massive extortion campaign against affected companies and authorities. The attack became one of the most extensive data breaches of the year and had far-reaching consequences for both Progress and the company's customers.
Since then, internet-exposed managed file transfer and file sharing platforms have become a recurring target for attackers, precisely because they often handle sensitive business data such as contracts, financial documents and personal information. The fact that Progress chooses to act proactively this time, before any breach has been confirmed, can be interpreted as a lesson learned from The Moveit event where the damage had already been done when the warnings went out.
This is how Swedish IT departments should act
For Swedish IT departments, operating partners and resellers who manage ShareFile environments for customers, the message is clear. The first step is to immediately verify whether Storage Zone Controllers are being used in the environment at all. Customers who only use Progress cloud storage are not affected by the shutdown and can continue to work as usual.
If the component is used, the affected Windows servers should be shut down manually, in accordance with Progress instructions. It is therefore not enough to rely on the company already blocking access centrally. At the same time, take the opportunity to document which systems and integrations are affected by the downtime, so that the business can plan for alternative ways of working in the meantime.
It is also wise to review logs from the servers in question for any signs of unusual activity, as well as prepare communications to end users who suddenly find themselves without access to their files. Finally, keep an eye out for Progress The next update, which according to the company will come within 24 hours, will include information about when the service can be put into operation again and whether a patch is required.








