Gunra Uses Fortinet and Schneider Flaws for Extortion

Gunra ransomware campaigns have been tied to two internet-facing flaws — Schneider Electric PowerLogic P5 CVE-2024-5559 and Fortinet FortiOS/FortiProxy CVE-2025-24472 — in attacks hitting healthcare, finance, government, and other critical-infrastructure targets. U.S. and South Korean agencies warned that the group is using those appliances and controllers to break into networks, then steal and encrypt data for double extortion. The pattern is simple: compromise the exposed device first, use that foothold to get inside, and then turn the breach into both data theft and file encryption. That means the apparent edge-device incident can quickly become a wider operational intrusion, especially where the appliance or controller sits in front of internal systems that matter to the business or plant. For Fortinet and Schneider operators, the important map point is that the exposed box is not the blast wall; it can be the door. If the device gates access to internal IT or OT/ICS environments, one initial-access flaw can widen the impact from a single product to the network behind it.

Part of the PlainSec briefing for 2026-08-11

Editions

Sources