Web_Logo
Remote Support
Security Alert: Ransomware Gang Exploiting Unpatched VPNs
Home » Security Alerts  »  Security Alert: Ransomware Gang Exploiting Unpatched VPNs

Security Alert: Ransomware Gang Exploiting Unpatched VPNs

Federal cyber agencies, including the FBI and CISA, have issued a joint warning about Gunra, a ransomware group that has hit at least 51 organisations worldwide, including hospitals, government agencies and financial firms.

  • What it is: Gunra is a "double extortion" ransomware operation - it steals your data and encrypts your systems, then threatens to leak the stolen data if you do not pay.
  • How it gets in: Attackers are exploiting known, unpatched vulnerabilities in Fortinet VPN and firewall appliances to gain a foothold, then moving through the network using stolen logins.
  • Who is affected: Any business running internet-facing VPN gateways, firewalls or remote access infrastructure that is not fully patched.
  • The risk: Once inside, attackers exfiltrate business data before encrypting files on both Windows and Linux systems, disrupting operations and threatening a data leak.

We recommend confirming all VPN and firewall appliances are on the latest firmware, reviewing remote access logs for unusual activity, and ensuring offline backups are in place and tested. If you are unsure whether your perimeter devices are up to date, get in touch and we can check for you.

Source: CISA Advisory AA26-222A