CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors
On August 10, 2026, CISA, the FBI, and partners published a joint advisory on Gunra ransomware. Criminal affiliates have used it against healthcare, financial services, government, and professional services. CISA corrected one vulnerability link in a revision the next day.
- Official source
- Cybersecurity and Infrastructure Security Agency ↗
- Jurisdiction
- United States
- Publication date
- August 10, 2026
- Legacy Core review
- August 14, 2026 · Chris Green
- Source checked
- August 14, 2026
- Affected sectors
- Medical and Dental, Financial Services, General Professional Services
Summary
On August 10, 2026, CISA, the FBI, and partners published a joint advisory on Gunra ransomware. Criminal affiliates have used it against healthcare, financial services, government, and professional services. CISA corrected one vulnerability link in a revision the next day.
Why it matters
Gunra is offered to criminal affiliates as a service. They get in through known flaws on internet-facing devices, steal files, and encrypt systems. Victims are told the stolen files will be published if a ransom is not paid within five to seven days. This advisory is a warning. It is not a finding that a particular business was hit.
Recommended action
Ask your IT owner or managed service provider to read the CISA advisory and check internet-facing devices, including Fortinet flaws CVE-2024-55591 and CVE-2025-24472. Confirm backups are kept separate from the main network and that a restore has been tested. This is not legal advice.