CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Healthcare Orgs Warned About Gunra Ransomware Attacks

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5827

As cited

Copy frozen at (site build).

ransomware

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners issued a joint advisory warning of Gunra ransomware-as-a-service (RaaS) attacks targeting government, critical infrastructure, and healthcare organizations across multiple regions. The group, which transitioned to RaaS in 2026, recruits affiliates with an 80% ransom share, exploits known vulnerabilities in firewalls and virtual private networks (VPNs) such as CVE-2024-55591 and CVE-2025-24472, and conducts double extortion by stealing data before encryption. The advisory recommends prioritizing patches for VPN and remote desktop protocol exposed infrastructure, network segmentation, and immutable backups in separate locations.

Why it matters: Healthcare organizations and other critical infrastructure operators face immediate threats from a rapidly expanding RaaS group; teams should patch known FortiOS/FortiProxy and VPN vulnerabilities and validate backup isolation to prevent both encryption and data exfiltration losses.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Healthcare Orgs Warned About Gunra Ransomware Attacks

CISA, the FBI, and international partners issued a joint advisory warning of Gunra ransomware-as-a-service (RaaS) attacks targeting government, critical infrastructure, and healthcare organizations across multiple regions. The group, which transitioned to RaaS in 2026, recruits affiliates with an 80% ransom share, exploits known vulnerabilities in firewalls and virtual private networks (VPNs) such as CVE-2024-55591 and CVE-2025-24472, and conducts double extortion by stealing data before encryption. The advisory recommends prioritizing patches for VPN and remote desktop protocol exposed infrastructure, network segmentation, and immutable backups in separate locations.

Why it matters: Healthcare organizations and other critical infrastructure operators face immediate threats from a rapidly expanding RaaS group; teams should patch known FortiOS/FortiProxy and VPN vulnerabilities and validate backup isolation to prevent both encryption and data exfiltration losses.

VendorsMicrosoftFortinet
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary