August 31, 2026

Gunra Ransomware: What Boston Businesses Need to Know

Gunra ransomware is a fast-growing extortion operation that federal agencies warned about on August 10, 2026, and it gets into networks through unpatched VPN and firewall appliances, not through some exotic new hack. If your business runs an internet-facing Fortinet device, an old VPN box, or any remote-access gear that hasn’t been patched in a while, you’re in the group this advisory was written for. The fix isn’t complicated, but it does require action this week, not next quarter.

  • CISA, the FBI, NSA, and international partners issued a joint advisory (AA26-222A) on Gunra ransomware on August 10, 2026.
  • Gunra affiliates break in mainly through two known Fortinet flaws, CVE-2024-55591 and CVE-2025-24472, both patched by the vendor over a year ago.
  • The group steals data before encrypting it and gives victims five to seven days to pay before it starts publishing files on a leak site.
  • Small and midsize businesses are absorbing the worst of it: Verizon’s 2026 Data Breach Investigations Report found ransomware tied to 88% of breaches at smaller organizations.
  • Only 34% of small organizations stopped an attack before encryption or data theft, according to Sophos, well behind larger companies.

What is Gunra ransomware and how does it get in?

Gunra first showed up in April 2025 and is built on code leaked from the old Conti ransomware operation. By early 2026 it had grown into a full ransomware-as-a-service business, meaning the core group rents its malware and infrastructure out to affiliates who run the actual attacks. Per the CISA advisory, those affiliates get their initial foothold by exploiting two specific vulnerabilities in FortiOS and FortiProxy, CVE-2024-55591 and CVE-2025-24472. Both have patches available. Attackers are still finding them because plenty of organizations never applied the fix or don’t know which devices on their network are even affected.

Why does a federal advisory about one ransomware group matter to a small Boston company?

Because the entry point isn’t picky about company size. Ransomware crews scan the entire internet for exposed, unpatched devices and then work down the list. A 12-person accounting firm in Quincy with an old firewall is just as visible on that scan as a hospital system. The advisory itself notes Gunra has hit healthcare, financial services, government, and professional services organizations, a mix that includes plenty of businesses the size of a typical Boston-area SMB.

How much damage are we actually talking about?

More than the ransom demand itself. Sophos’s State of Ransomware 2026 report puts the average recovery cost, cleanup, downtime, lost business, at $1.7 million per incident, even as median ransom payments have actually dropped. That gap matters: paying the ransom was never the expensive part. Rebuilding servers, notifying customers, and losing a week or more of billable work is. Verizon’s 2026 DBIR also found that 64% of organizations now refuse to pay at all, which means recovery capability, not negotiation skill, decides how the incident ends.

What should you check this week?

Start with an inventory of anything facing the public internet: VPN gateways, firewalls, remote-access portals. If any of it runs Fortinet software, confirm it’s patched against CVE-2024-55591 and CVE-2025-24472 and check the vendor’s advisory for your exact model. This is the same pattern we flagged with the Citrix NetScaler VPN vulnerability earlier this year: edge devices sit outside your normal desktop patch cycle, so they’re the ones most likely to get missed. Turn on multi-factor authentication for every remote-access account, and segment your network so a compromised VPN account can’t reach your file servers directly.

Does this change how you should think about backups?

Yes, and it’s the part most businesses underinvest in. Gunra steals your data before it encrypts anything, so a backup alone won’t stop the extortion threat, but it does determine whether you’re forced to negotiate at all. Backups need to be offline or immutable, meaning an attacker who gets admin access to your network can’t also delete or encrypt the backup copies. If you haven’t tested a real restore in the last six months, you don’t actually know your recovery time, you’re guessing. Our business continuity plan generator is a free starting point if you want to see the gaps on paper before an attacker finds them for you.

Frequently asked questions

Is Gunra ransomware targeting Boston businesses specifically?
No evidence points to Boston as a specific target. The risk comes from exposed, unpatched devices anywhere, and local businesses are just as reachable by internet-wide scans as anyone else.

Do I need to worry if I don’t use Fortinet products?
The current advisory centers on FortiOS and FortiProxy flaws, but the underlying lesson applies to any internet-facing appliance. Any VPN, firewall, or remote-access device that isn’t on a regular patch schedule is a similar risk.

How fast do attackers move once a vulnerability is public?
Recent CISA data shows the gap between a patch being released and active exploitation has shrunk to as little as five days in some 2026 cases, which is why patching on a schedule rather than “when we get to it” matters.

What’s the single most useful thing a small business can do this month?
Confirm every internet-facing device is patched and then test a real backup restore. Those two steps address both how Gunra gets in and what happens if it does.

This advisory is really about exposed edge devices and untested backups, the two things that turn a blocked intrusion attempt into a five-figure recovery bill. If you’re not sure whether your firewall or VPN is patched, or when your backups were last actually restored and verified, that’s exactly what a free 15-minute Microsoft 365 or security review from Boston Managed IT is for. Call (617) 322-5155 or visit bostonmit.com/contact to get on the calendar.

— Boston Managed IT

About the Author

Your IT Partner Is Just a Click Away. Are you ready to stop thinking about IT?

We handle the infrastructure, helpdesk, and security — Boston businesses rely on us so they never have to think about IT again.