Cybersecurity agencies from South Korea and the United States have released a joint advisory warning organizations about active Gunra ransomware campaigns targeting critical infrastructure sectors globally. The attacks have affected healthcare and public health organizations, financial services firms, government facilities, and professional and nonprofit service providers across multiple countries.
Gunra represents another variant in the continuing evolution of ransomware threats against essential services and infrastructure. The joint warning from South Korean and U.S. intelligence agencies indicates coordinated efforts by threat actors to compromise organizations that provide vital services to their communities and economies.
The ransomware operators gain initial access to victim networks by exploiting known vulnerabilities in Fortinet and Schneider Electric products. These vulnerabilities provide attackers with entry points into corporate networks, allowing them to deploy ransomware and potentially exfiltrate sensitive data before encryption. The specific vulnerabilities being exploited have existing patches available from both vendors.
The impact of Gunra attacks extends beyond immediate operational disruption. Healthcare organizations face potential interruptions to patient care, financial institutions risk exposure of customer data, and government services may experience delays or shutdowns. The targeting of nonprofit organizations also demonstrates the indiscriminate nature of these campaigns, affecting entities regardless of their mission or resources.
Organizations in the targeted sectors should immediately apply available security patches for Fortinet and Schneider Electric products. Security teams should conduct thorough reviews of their networks for signs of compromise, implement robust backup procedures, and ensure incident response plans are current and tested. Network segmentation and multi-factor authentication can provide additional layers of defense against initial access attempts by ransomware operators.
Source: https://thehackernews.com/2026/08/gunra-ransomware-exploits-fortinet-and.html


