Gunra ransomware hits critical infrastructure via Fortinet flaws
CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.
Article record
Why it matters
What this means for organisations holding critical data
CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.
According to reporting by The Register, United States cyber agencies have warned critical infrastructure operators to patch internet facing equipment after affiliates of the Gunra ransomware operation were observed exploiting known vulnerabilities to break into networks. The joint advisory was issued by CISA, the FBI, the NSA, the Secret Service and partner agencies in the United States and South Korea.
What happened
Gunra first surfaced in 2025 and now operates as ransomware as a service, with affiliates attacking organisations worldwide. Reported targets include healthcare, financial services, government, professional services, nonprofit organisations and other critical infrastructure operators.
The advisory states that affiliates have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet FortiOS and FortiProxy, to gain administrative access through internet facing appliances. Once inside, the group follows the familiar double extortion playbook: steal data, encrypt systems, then demand payment for a decryptor and for a promise not to publish the stolen material. Negotiations take place through a Tor based portal, with victims typically given between five and seven days before their data is published.
Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. A Linux variant was later uncovered that can run as many as 100 encryption threads in parallel, supports partial encryption of individual files, and can store RSA encrypted keys in separate keystore files. Activity has been seen in Turkey, Taiwan, the United States and South Korea, while the group leak site also claims victims in Brazil, Japan and Canada, including manufacturers, healthcare providers, technology companies and law firms.
What this means for the sector
The pattern is now well established. The entry point is not a novel exploit but a known, published vulnerability in an internet facing appliance that has not been patched. The edge device is the front door, and once administrative access is obtained the attacker moves quickly to identify and destroy the recovery position before making a demand.
That last point is the one most operators underestimate. Backups that are reachable over the network, including cloud replicas and network attached storage, are part of the same connected estate as the systems being encrypted. If an attacker holds administrative credentials, those copies can be altered, encrypted or deleted in the same intrusion. The five to seven day negotiation window described in the advisory only carries weight when the victim has no clean copy of its own to fall back on.
It is also worth noting the sectors involved. Healthcare, government, financial services, professional services and manufacturing all share one characteristic: downtime carries an immediate cost in service delivery, not just in revenue. Recovery speed, and confidence in the integrity of what is recovered, decides how long that cost runs.
The Firevault view
The agencies close their advisory with a short list of practical measures: patch known exploited vulnerabilities in internet facing systems, protect VPN gateways and remote desktop access with multifactor authentication, segment networks, and maintain offline, immutable backups. The final item is the one that determines the outcome once prevention has already failed.
Offline Secure Storage® (#OSS) exists for that scenario. A vault is physically disconnected by default, so the data inside it is not present on any network an intruder can reach. Access is enabled deliberately by the account holder, and every session is recorded. Mark Fermor, senior editor at Firevault, notes that the value of a physically disconnected copy is simple to state: an attacker with full administrative control of a connected estate still cannot reach a drive that is not connected to anything. #OSS does not prevent an initial intrusion through an unpatched appliance, and it is not presented as doing so. What it removes is the leverage, because the organisation retains a clean and unalterable copy of the records that matter.
What to do next
Operators of critical infrastructure and their suppliers should treat this advisory as a prompt to review both prevention and recovery:
- Inventory every internet facing appliance and confirm that CVE-2024-55591 and CVE-2025-24472 have been remediated on all Fortinet FortiOS and FortiProxy instances.
- Enforce multifactor authentication on VPN gateways and remote desktop access, and remove standing administrative access from accounts that do not require it.
- Test whether any current backup copy can be reached, modified or deleted using credentials held on the production network. If it can, it is not a recovery position.
- Hold a physically disconnected copy of critical records and system images in Offline Secure Storage® (#OSS), and rehearse restoring from it rather than assuming it will work.
- Segment networks so that a compromised edge appliance does not grant a route into operational technology environments.
Source: The Register, 11 August 2026, and the joint advisory published by CISA.
Sources
Where this reporting comes from
How Firevault would handle this
Physical disconnection removes the path an attacker needs
Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.






