---
title: "Gunra ransomware hits critical infrastructure v… | Firevault"
description: "CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws#webpage",
      "url": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws",
      "name": "Gunra ransomware hits critical infrastructure v…",
      "description": "CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gunra-ransomware-critical-infrastructure-fortinet-flaws.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Gunra ransomware hits critical infrastructure via Fortinet flaws",
          "item": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Gunra ransomware hits critical infrastructure via Fortinet flaws",
      "description": "CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.",
      "url": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gunra-ransomware-critical-infrastructure-fortinet-flaws.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gunra-ransomware-critical-infrastructure-fortinet-flaws.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gunra-ransomware-critical-infrastructure-fortinet-flaws.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gunra-ransomware-critical-infrastructure-fortinet-flaws.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-08-15T11:12:55.364782+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/gunra-ransomware-critical-infrastructure-fortinet-flaws"
      },
      "inLanguage": "en-GB",
      "articleSection": "Insight",
      "wordCount": 765,
      "keywords": "Gunra, Insight, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "According to reporting by The Register, United States cyber agencies have warned critical infrastructure operators to patch internet facing equipment after affiliates of the Gunra ransomware operation were observed exploiting known vulnerabilities to break into networks. The joint advisory was issued by CISA, the FBI, the NSA, the Secret Service and partner agencies in the United States and South ",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What happenedWhat this means for the sectorThe Firevault viewWhat to do nextMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Insight · 15 August 2026 

# Gunra ransomware hits critical infrastructure via Fortinet flaws

CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fgunra-ransomware-critical-infrastructure-fortinet-flaws)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fgunra-ransomware-critical-infrastructure-fortinet-flaws&text=Gunra%20ransomware%20hits%20critical%20infrastructure%20via%20Fortinet%20flaws%0A%0ACISA%2C%20the%20FBI%2C%20the%20NSA%20and%20partner%20agencies%20have%20warned%20that%20Gunra%20ransomware%20affiliates%20are%20exploiting%20known%20Fortinet%20authentication%20bypass%20flaws%20to%20reach%20critical%20infrastructure%20networks%2C%20then%20stealing%20and%20encrypting%20data.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fgunra-ransomware-critical-infrastructure-fortinet-flaws)[](mailto:?subject=Gunra%20ransomware%20hits%20critical%20infrastructure%20via%20Fortinet%20flaws&body=CISA%2C%20the%20FBI%2C%20the%20NSA%20and%20partner%20agencies%20have%20warned%20that%20Gunra%20ransomware%20affiliates%20are%20exploiting%20known%20Fortinet%20authentication%20bypass%20flaws%20to%20reach%20critical%20infrastructure%20networks%2C%20then%20stealing%20and%20encrypting%20data.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fgunra-ransomware-critical-infrastructure-fortinet-flaws)

![Abstract representation of a disconnected offline storage drive beside a network edge appliance](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gunra-ransomware-critical-infrastructure-fortinet-flaws.jpg)

Abstract representation of a disconnected offline storage drive beside a network edge appliance

Why it matters

## What this means for organisations holding critical data

CISA, the FBI, the NSA and partner agencies have warned that Gunra ransomware affiliates are exploiting known Fortinet authentication bypass flaws to reach critical infrastructure networks, then stealing and encrypting data.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [What this means for the sector](#section-1)
3.  03 [The Firevault view](#section-2)

**On this page**[What happened](#section-0)[What this means for the sector](#section-1)[The Firevault view](#section-2)

According to reporting by The Register, United States cyber agencies have warned [critical infrastructure](/control-for-critical-infrastructure) operators to patch internet facing equipment after affiliates of the Gunra ransomware operation were observed exploiting known vulnerabilities to break into networks. The joint advisory was issued by CISA, the FBI, the NSA, the Secret Service and partner agencies in the United States and South Korea.

## What happened

Gunra first surfaced in 2025 and now operates as ransomware as a service, with affiliates attacking organisations worldwide. Reported targets include healthcare, financial services, government, professional services, nonprofit organisations and other critical infrastructure operators.

The advisory states that affiliates have exploited CVE-2024-55591 and CVE-2025-24472, authentication bypass flaws in Fortinet FortiOS and FortiProxy, to gain administrative access through internet facing appliances. Once inside, the group follows the familiar double extortion playbook: steal data, encrypt systems, then demand payment for a decryptor and for a promise not to publish the stolen material. Negotiations take place through a Tor based portal, with victims typically given between five and seven days before their data is published.

Trend Micro first observed Gunra in April 2025, initially targeting Windows systems and borrowing elements from the Conti ransomware operation. A Linux variant was later uncovered that can run as many as 100 encryption threads in parallel, supports partial encryption of individual files, and can store RSA encrypted keys in separate keystore files. Activity has been seen in Turkey, Taiwan, the United States and South Korea, while the group leak site also claims victims in Brazil, Japan and Canada, including manufacturers, healthcare providers, technology companies and law firms.

## What this means for the sector

The pattern is now well established. The entry point is not a novel exploit but a known, published vulnerability in an internet facing appliance that has not been patched. The edge device is the front door, and once administrative access is obtained the attacker moves quickly to identify and destroy the recovery position before making a demand.

That last point is the one most operators underestimate. Backups that are reachable over the network, including cloud replicas and network attached storage, are part of the same connected estate as the systems being encrypted. If an attacker holds administrative credentials, those copies can be altered, encrypted or deleted in the same intrusion. The five to seven day negotiation window described in the advisory only carries weight when the victim has no clean copy of its own to fall back on.

It is also worth noting the sectors involved. Healthcare, government, financial services, professional services and manufacturing all share one characteristic: downtime carries an immediate cost in service delivery, not just in revenue. Recovery speed, and confidence in the integrity of what is recovered, decides how long that cost runs.

## The Firevault view

The agencies close their advisory with a short list of practical measures: patch known exploited vulnerabilities in internet facing systems, protect VPN gateways and remote desktop access with multifactor authentication, segment networks, and maintain offline, immutable backups. The final item is the one that determines the outcome once prevention has already failed.

[Offline Secure Storage](/offline-secure-storage)® (#OSS) exists for that scenario. A vault is physically disconnected by default, so the data inside it is not present on any network an intruder can reach. Access is enabled deliberately by the account holder, and every session is recorded. Mark Fermor, senior editor at Firevault, notes that the value of a physically disconnected copy is simple to state: an attacker with full administrative control of a connected estate still cannot reach a drive that is not connected to anything. #OSS does not prevent an initial intrusion through an unpatched appliance, and it is not presented as doing so. What it removes is the leverage, because the organisation retains a clean and unalterable copy of the records that matter.

## What to do next

Operators of critical infrastructure and their suppliers should treat this advisory as a prompt to review both prevention and recovery:

-   Inventory every internet facing appliance and confirm that CVE-2024-55591 and CVE-2025-24472 have been remediated on all Fortinet FortiOS and FortiProxy instances.
-   Enforce multifactor authentication on VPN gateways and remote desktop access, and remove standing administrative access from accounts that do not require it.
-   Test whether any current backup copy can be reached, modified or deleted using credentials held on the production network. If it can, it is not a recovery position.
-   Hold a physically disconnected copy of critical records and system images in Offline Secure Storage® (#OSS), and rehearse restoring from it rather than assuming it will work.
-   Segment networks so that a compromised edge appliance does not grant a route into operational technology environments.

Source: [The Register](https://www.theregister.com/cyber-crime/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical-infrastructure/5286263), 11 August 2026, and the joint advisory published by [CISA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-222a).

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://www.theregister.com/cyber-crime/2026/08/11/feds-warn-gunra-ransomware-is-exploiting-known-bugs-to-hit-critical-infrastructure/5286263)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

[![Firevault Bunker, the protected physical location for Offline Secure Storage hardware](/__l5e/assets-v1/75208f4e-fc6f-46d8-80b9-606c43dfef28/firevault-bunker-building.webp)](/why-oss)

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

[![The nine Control modules arranged around the Firevault platform](/__l5e/assets-v1/829a8768-a871-41d0-8a79-3645ca7f5e83/platform-wheel.jpg)](/solutions/control)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

[![Firevault 2TB Vault hardware](/__l5e/assets-v1/ed09bfc1-2f0f-491d-b1aa-861542a5fb33/hero-vault-2tb.png)](/get-started)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. New research shows no hacking was required: server-side marketing API keys sat in the public JavaScript of all three airport websites, unrotated, for more than four years.

27 Aug 2026 8 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)[

![Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/george-house-trust-beacon-charity-data-breach-2026.jpg)

Insight 

### Beacon breach: 1,500 charities exposed and an HIV charity's health data stolen

People supported by a Manchester HIV charity have been told sensitive health information may have been stolen after a breach at Beacon, the shared database platform used by more than a thousand UK charities. One supplier, one connected database, national exposure.

26 Aug 2026 3 min 







](/news/beacon-charity-database-breach-hiv-charity-health-data-2026)[

![Iran-linked hackers shut down a UK power plant for four days](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/iran-uk-power-plant-cyber-attack-2026.jpg)

Insight 

### Iran-linked hackers shut down a UK power plant for four days

A small British generator was taken offline for four days after an Iran-linked cyber attack, reported as the first successful intrusion of its kind against UK power generation. The grid held. The control layer did not.

23 Aug 2026 4 min 







](/news/iran-linked-hackers-uk-power-plant-shutdown-2026)[

![GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/gta6-leaks-rockstar-2026.jpg)

Insight 

### GTA 6 leaks: a nightmare or a blip for the biggest video game of the year?

Unreleased Grand Theft Auto 6 footage has appeared online ahead of Rockstar's official preview, and Take-Two is now in court seeking the identities behind the accounts sharing it. The game will still sell. The material that leaked can never be unseen.

22 Aug 2026 3 min 







](/news/gta-6-leaks-rockstar-development-footage-2026)[

![Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/nine-pbs-archives-cloud-vendor-shutdown-2026.jpg)

Insight 

### Nine PBS: 50 Terabytes of History Trapped by a Cloud Vendor That Closed

A public broadcaster lost access to fifty terabytes of archival footage, spanning seventy years of regional history, when its cloud storage supplier suddenly went out of business. The files are still trapped in a Denver data centre.

18 Aug 2026 4 min 







](/news/nine-pbs-archives-cloud-vendor-shutdown-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)