Legacy Core™
Official GuidanceArchived record

CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors

On August 10, 2026, CISA, the FBI, and partners published a joint advisory on Gunra ransomware. Criminal affiliates have used it against healthcare, financial services, government, and professional services. CISA corrected one vulnerability link in a revision the next day.

This record is retained for review history. It is not presented as the latest update. Confirm current requirements with the official source.
Official source
Cybersecurity and Infrastructure Security Agency ↗
Jurisdiction
United States
Publication date
August 10, 2026
Legacy Core review
August 14, 2026 · Chris Green
Source checked
August 14, 2026
Affected sectors
Medical and Dental, Financial Services, General Professional Services

Summary

On August 10, 2026, CISA, the FBI, and partners published a joint advisory on Gunra ransomware. Criminal affiliates have used it against healthcare, financial services, government, and professional services. CISA corrected one vulnerability link in a revision the next day.

Why it matters

Gunra is offered to criminal affiliates as a service. They get in through known flaws on internet-facing devices, steal files, and encrypt systems. Victims are told the stolen files will be published if a ransom is not paid within five to seven days. This advisory is a warning. It is not a finding that a particular business was hit.

Recommended action

Ask your IT owner or managed service provider to read the CISA advisory and check internet-facing devices, including Fortinet flaws CVE-2024-55591 and CVE-2025-24472. Confirm backups are kept separate from the main network and that a restore has been tested. This is not legal advice.

CISA, FBI and Partners Warn Organizations of Gunra Ransomware Actors Targeting Multiple Critical Infrastructure Sectors | Legacy Core Intelligence | Legacy Core