Home / The Long Read / Research
Long Read

Progress tells ShareFile customers to pull the plug: an ICT supplier's threat becomes everyone's downtime

On 10 July 2026 Progress Software told ShareFile customers running Storage Zone Controllers to shut down the hosting Windows servers over a credible external threat. No patch, no CVE, and cloud access to affected accounts disabled. The pattern is concentration risk: one widely used file-sharing supplier is a single point of exposure, and its emergency is inherited by everyone downstream, including firms that only touch it through a vendor.

Progress tells ShareFile customers to pull the plug: an ICT supplier's threat becomes everyone's downtime
TL;DR

On 10 July 2026 Progress Software told ShareFile customers running Storage Zone Controllers to shut down the hosting Windows servers over a credible external threat. No patch, no CVE, and cloud access to affected accounts disabled. The pattern is concentration risk: one widely used file-sharing supplier is a single point of exposure, and its emergency is inherited by everyone downstream, including firms that only touch it through a vendor.

When one supplier tells thousands of customers to switch off a server, the supplier's problem has just become their problem. On 10 July 2026 Progress Software emailed ShareFile customers who run Storage Zone Controllers and told them to shut those servers down at once, citing a credible external security threat. Storage Zone Controllers are on-premises Windows servers that keep files in a customer's own storage while using ShareFile's cloud for logins and sharing. Every organisation that runs one had to choose between exposure and taking a file-sharing service offline. The lesson: a widely used ICT supplier is a single point of exposure, and its emergency is inherited by everyone downstream.

Progress ShareFile (July 2026): one supplier advisory, downtime across the customer base A widely used ICT file-sharing supplier is a single point of exposure for everyone downstream. The threat “credible external security threat” nature undisclosed; no CVE assigned ICT supplier Progress ShareFile Storage Zone Controllers Vendor instruction (10 July 2026): shut down the on-prem servers cloud access cut off no patch available at the advisory separate from the April 2026 CVEs Downstream customers Every org running a controller Suppliers who use it with you (fourth-party data flows) inherit both the risk and the downtime. No customer breach named. What is confirmed (10 July 2026): Progress issued a shutdown advisory. No CVE assigned; no confirmed compromise of accounts or data at that date. Third-party risk, in one line: A supplier used by many is a shared point of failure, so know which of your systems and vendors depend on it. Sources: BleepingComputer, The Hacker News (10–11 July 2026). Draft diagram for Breach Wire, Supplier Shield.

What happened

On 10 July 2026 Progress Software instructed ShareFile customers using Storage Zone Controllers to manually shut down the Windows servers hosting them, according to reporting by BleepingComputer and The Hacker News. Progress said disabling access through the ShareFile cloud was not enough to reduce the threat, and it also cut off cloud access for affected accounts while it investigated with internal and external experts. Progress has not said whether a software vulnerability is involved, whether any controller was compromised, or assigned a CVE identifier to the incident. It stated it had no indication of unauthorised access to ShareFile accounts or data as of that date. The company is the maker of MOVEit, the file-transfer product mass-exploited by the Clop group in 2023. The July advisory is separate from two critical ShareFile flaws disclosed by watchTowr Labs in April 2026 (CVE-2026-2699 and CVE-2026-2701, a chainable pre-authentication remote code execution), which Progress had already patched. Progress has not linked the current threat to those flaws.

Why it matters for third-party risk

The pattern is concentration risk. ShareFile is one supplier embedded in many organisations' file workflows, so a single advisory forces action across the whole customer base at once. The cost is not only the unknown threat; it is the guaranteed downtime of switching a service off with no patch to apply. There is a fourth-party edge too. A supplier may use ShareFile to exchange files with you, so its shutdown can interrupt data flows you depend on even if you do not run the product yourself. A reader who cannot answer, within hours, whether they or their vendors run this software is carrying a risk they cannot yet see.

What teams should take from it

Two takeaways. First, keep a current inventory of ICT suppliers and the products they operate, including file-transfer and file-sharing tools, so a vendor advisory becomes a targeted action rather than a scramble to find affected systems. Second, ask your key suppliers directly whether they use ShareFile Storage Zone Controllers to move data with you, and agree in advance how they will tell you when they take a shared system offline.

For teams mapping which suppliers could force this kind of decision, this is a prompt to see how continuous vendor monitoring works, so a supplier's emergency does not catch you unprepared.

FAQ

What did Progress actually tell customers to do?

Progress emailed ShareFile customers who run Storage Zone Controllers on 10 July 2026 and told them to shut down the hosting Windows servers manually. It said turning off cloud access alone was not enough, and it disabled access to affected accounts while investigating.

Is a specific vulnerability being exploited?

Progress has not confirmed one. As of its 10 July advisory it had not disclosed the nature of the threat, assigned a CVE, or said whether any controller was compromised. It reported no indication of unauthorised access to accounts or data at that point. Those details are unconfirmed.

We do not run ShareFile. Are we exposed?

Possibly, at one step removed. If a supplier uses ShareFile Storage Zone Controllers to exchange files with you, their shutdown can interrupt your data flows. Confirm which vendors rely on the product and how they will notify you of outages.

What to do next

Want this applied to your supplier ecosystem? See the platform in action and map your top vendor risks live in one walkthrough.

Read next

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

ChainDrop npm worm hits 400-plus packages: one stolen login becomes a self-spreading supply-chain attack

A self-propagating worm named ChainDrop infected more than 400 npm packages, including keyv, flat-cache and cache-manager, Microsoft reported on 4 August 2026. The malware steals developer and cloud credentials, then uses stolen publishing tokens to poison further packages on its own. For third-party risk teams, it is a fourth-party exposure most vendor registers never capture.

Read article
Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen says patient data was stolen from third-party cloud systems, not its own network

Amgen told the US SEC that attackers stole patient health information and proprietary company data from cloud systems run by external service providers, not from its own network. The company concluded the incident was material on 29 July 2026. It says medicine supply was not affected. The lesson: data placed in a supplier's cloud is still the owner's breach to disclose.

Read article
Xsolis breach reached hospital patients through one shared healthcare AI vendor

Xsolis breach reached hospital patients through one shared healthcare AI vendor

A phishing attack at Xsolis, a US healthcare vendor that many hospitals and insurers use to review whether care is covered, exposed the data of about 1.4 million people. Patients at Mayo Clinic, UW Medicine and VHC Health were among those affected, because one vendor held records from many providers at once.

Read article
Progress ShareFile shutdown order: the concentration risk in one ICT supplier | Breach Wire | Supplier Shield