Jessica Entwistle
August 12 2026
The Gunra ransomware gang, operating as a ransomware-as-a-service model, has been successfully exploiting known vulnerabilities in Fortinet firewalls and VPN appliances to gain initial access to target networks. The group is using leaked Conti ransomware code and has demonstrated the ability to bypass multi-factor authentication protections. Security researchers note that Gunra has been particularly successful against critical infrastructure targets, suggesting a focus on organisations where operational disruption creates significant pressure to pay ransoms. The attacks rely on older, publicly known vulnerabilities in Fortinet devices, indicating that many organisations have not yet applied available patches or implemented compensating controls.
The operational concern here is not the novelty of the attack techniques, but the effectiveness of well-understood methods against organisations that should have patched these vulnerabilities months or years ago. Fortinet has been a consistent target for ransomware groups because VPN and firewall appliances provide direct access to internal networks, and because many organisations treat these devices as set-and-forget infrastructure. The fact that Gunra is bypassing MFA suggests they are either exploiting session handling flaws, using stolen session tokens, or leveraging vulnerabilities that allow authentication bypass entirely. For UK organisations in critical infrastructure sectors, this is a reminder that perimeter devices require the same patch discipline and monitoring as any other critical system. The targeting of critical infrastructure is particularly concerning because operational technology environments often have limited resilience to disruption, and the business impact of ransomware in these sectors can extend beyond data loss to include safety risks, regulatory consequences and significant operational downtime.
Organisations using Fortinet devices should verify the patch status of all internet-facing VPN and firewall appliances, prioritising any devices that provide access to internal networks or operational technology environments. It is worth reviewing whether MFA is correctly configured, whether session timeout policies are appropriate, and whether logging is enabled and monitored for authentication anomalies or unusual access patterns from VPN endpoints. Organisations should also consider whether they have visibility of all Fortinet devices in their estate, including any that may have been deployed by third parties or managed service providers. For critical infrastructure organisations, this is a prompt to review whether VPN access is appropriately segmented, whether privileged access to operational systems is protected by additional controls beyond MFA, and whether you have the monitoring in place to detect lateral movement from compromised VPN accounts. It is also worth reviewing whether your incident response plans account for the possibility of ransomware entering through perimeter devices rather than through user endpoints, as this can change the speed and scope of an attack significantly.
Source: Dark Reading