Filezilla and Cloudberry have inputs for S3 encryption, on this bucket, we had a specific KMS key set for the encryption. Apparently WinSCP only supports the default AWS controlled encryption, and there is no option to add the arn for the kms key for a per-bucket encryption key.
So this is now a feature request.
This request has been added to the tracker:
You can vote for it there.