Breaking NewsUpdated as information becomes available
Insight·15 August 2026·Breaking

Gunra ransomware hits critical infrastructure via Fortinet flaws

CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.

Mark Fermor
Mark FermorDirector & Co-Founder, Firevault
4 min read
Share
Abstract representation of a disconnected offline storage drive beside a network edge appliance
Insight

Article record

InsightCategory
15 August 2026Published
4 min readReading time
Mark FermorWritten by
Abstract representation of a disconnected offline storage drive beside a network edge appliance

Why it matters

What this means for organisations holding critical data

CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.

According to reporting by The Register, United States cyber agencies have warned critical infrastructure operators to patch internet facing equipment after affiliates of the Gunra ransomware operation were observed exploiting known vulnerabilities to break into networks. The joint advisory was issued by CISA, the FBI, the NSA, the Secret Service and partner agencies in the United States and South Korea.

What happened

Gunra first surfaced in 2025 and now operates as ransomware as a service, with affiliates attacking organisations worldwide. Reported targets include healthcare, financial services, government, professional services, nonprofit organisations and other critical infrastructure operators.

The advisory states that affiliates have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet FortiOS and FortiProxy, to gain administrative access through internet facing appliances. Once inside, the group follows the familiar double extortion playbook: steal data, encrypt systems, then demand payment for a decryptor and for a promise not to publish the stolen material. Negotiations take place through a Tor based portal, with victims typically given between five and seven days before their data is published.

Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. A Linux variant was later uncovered that can run as many as 100 encryption threads in parallel, supports partial encryption of individual files, and can store RSA encrypted keys in separate keystore files. Activity has been seen in Turkey, Taiwan, the United States and South Korea, while the group leak site also claims victims in Brazil, Japan and Canada, including manufacturers, healthcare providers, technology companies and law firms.

What this means for the sector

The pattern is now well established. The entry point is not a novel exploit but a known, published vulnerability in an internet facing appliance that has not been patched. The edge device is the front door, and once administrative access is obtained the attacker moves quickly to identify and destroy the recovery position before making a demand.

That last point is the one most operators underestimate. Backups that are reachable over the network, including cloud replicas and network attached storage, are part of the same connected estate as the systems being encrypted. If an attacker holds administrative credentials, those copies can be altered, encrypted or deleted in the same intrusion. The five to seven day negotiation window described in the advisory only carries weight when the victim has no clean copy of its own to fall back on.

It is also worth noting the sectors involved. Healthcare, government, financial services, professional services and manufacturing all share one characteristic: downtime carries an immediate cost in service delivery, not just in revenue. Recovery speed, and confidence in the integrity of what is recovered, decides how long that cost runs.

The Firevault view

The agencies close their advisory with a short list of practical measures: patch known exploited vulnerabilities in internet facing systems, protect VPN gateways and remote desktop access with multifactor authentication, segment networks, and maintain offline, immutable backups. The final item is the one that determines the outcome once prevention has already failed.

Offline Secure Storage® (#OSS) exists for that scenario. A vault is physically disconnected by default, so the data inside it is not present on any network an intruder can reach. Access is enabled deliberately by the account holder, and every session is recorded. Mark Fermor, senior editor at Firevault, notes that the value of a physically disconnected copy is simple to state: an attacker with full administrative control of a connected estate still cannot reach a drive that is not connected to anything. #OSS does not prevent an initial intrusion through an unpatched appliance, and it is not presented as doing so. What it removes is the leverage, because the organisation retains a clean and unalterable copy of the records that matter.

What to do next

Operators of critical infrastructure and their suppliers should treat this advisory as a prompt to review both prevention and recovery:

  • Inventory every internet facing appliance and confirm that CVE-2024-55591 and CVE-2025-24472 have been remediated on all Fortinet FortiOS and FortiProxy instances.
  • Enforce multifactor authentication on VPN gateways and remote desktop access, and remove standing administrative access from accounts that do not require it.
  • Test whether any current backup copy can be reached, modified or deleted using credentials held on the production network. If it can, it is not a recovery position.
  • Hold a physically disconnected copy of critical records and system images in Offline Secure Storage® (#OSS), and rehearse restoring from it rather than assuming it will work.
  • Segment networks so that a compromised edge appliance does not grant a route into operational technology environments.

Source: The Register, 11 August 2026, and the joint advisory published by CISA.

Sources

Where this reporting comes from

01
Original reportPrimary coverage referenced in this analysisView original article

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

HardwareYour data sits on dedicated encrypted hardware
DisconnectOffline by default, connected only when you say so
CommandAccess windows and retrieval under your control
LocationHeld in a secure Firevault Bunker

Share this article

Breaking News
Insight15 August 20264 min read

Gunra ransomware hits critical infrastructure via Fortinet flaws

CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.

Gunra ransomware hits critical infrastructure via Fortinet flaws
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy