Back to News & Insights
Tribal Nations August 24, 2026 5 min read

Six Agencies Named Your VPN the Front Door

A six-agency federal advisory on Gunra ransomware names government services, utilities, and health among its targets. The way in was an unpatched VPN.

On August 10, six agencies put their names on the same document.

The FBI, CISA, the Department of Defense Cyber Crime Center, the NSA, the Secret Service, and the Republic of Korea's National Police Agency jointly published an advisory on Gunra ransomware, carrying product ID AA26-222A. Federal advisories come out often enough that they blur together, and most of them are written for people who already run a security operations center.

This one is worth twenty minutes of a tribal government's attention, for two reasons: who it says is being targeted, and how the attackers are actually getting in.

Who the advisory says it is for

The document names its intended audience in the opening summary. Not enterprises. Not the Fortune 500. It reads: "Organizations: Government, Critical Infrastructure."

Then it lists the sectors where victims have already appeared on the group's leak site. Healthcare and public health. Financial services and insurance. Critical manufacturing and construction. Transportation systems and logistics. Government services and facilities. Utilities. Academia. Media and communications. Retail. Professional and nonprofit services.

The advisory does not single out tribal governments, and we are not going to claim it does. But read that list as an operations chart rather than a list of industries, and something specific comes into view.

Most organizations sit in exactly one of those categories. A tribal government routinely sits in five or six at once. The same small IT function that supports government services and facilities also supports the health clinic, the utility authority, the school, the transit program, and often an enterprise or two. One network. One set of credentials. One person, in many cases, or one contracted provider covering all of it.

That is not a moral failing or a budget failing. It is the structure of tribal government operations. It also means a single compromised account reaches further than it would almost anywhere else.

How they get in

This is the part that should reset expectations about what ransomware actually looks like in practice.

Gunra is ransomware-as-a-service. It first appeared in April 2025, built on the Conti source code that leaked in 2022, and by January 2026 it had opened a formal affiliate program on dark web forums with a management panel, a configurable builder, and cross-platform payloads. The FBI notes the group has been recruiting penetration testers to work as initial access brokers, paying them a share of the ransom for a way into a network. Victims get a ransom note in every affected directory, a Tor negotiation portal, and five to seven days to respond.

None of that is the interesting part. The interesting part is the entry.

The advisory reports that Gunra actors got initial access primarily by exploiting known vulnerabilities in internet-facing devices, specifically firewall and VPN appliances. Two CVEs are named: CVE-2024-55591, an authentication bypass affecting FortiOS, and CVE-2025-24472.

Both were already known. Both already had patches.

The case detail from the Korean National Police is the one we would put in front of a council. In one incident, the attackers reached an administrator account on an SSL-VPN appliance by using default credentials, on an account where lockout controls were not turned on. From there they found an unused account that had access to both the internet-facing and the internal corporate network, changed its configuration to skip the mandatory password change, and used it.

Default credentials. An account nobody had disabled. No lockout policy.

There is no sophisticated exploit in that sequence. There is an appliance somebody installed, configured once, and never revisited.

What the advisory actually asks for

The three actions the authoring agencies put at the top are unglamorous, and that is the point.

Patch known exploited vulnerabilities on anything internet-facing, with VPN gateways and RDP-exposed systems named specifically. Not every vulnerability. The known-exploited ones, which CISA publishes as a free catalog.

Implement and test offline, immutable backups, stored physically separate and segmented. The word "test" is carrying weight there. An untested backup is a hope, not a control. It is also the single measure that defeats half of a double-extortion case, because it takes the encryption threat off the table entirely.

Segment the network so that one compromised device does not reach everything else. For a government running the clinic, the utility, and the school on shared infrastructure, this is the control that limits how far a bad afternoon travels.

The advisory adds two more worth naming: audit accounts with administrative privileges and apply least privilege, and follow CISA's incident response steps before applying countermeasures rather than after.

What we would do this month

If you are responsible for a tribal government network, four questions are answerable this month without a budget cycle.

What is our internet-facing equipment, and when was it last patched? Firewalls and VPN appliances first. If the answer involves finding out who installed it, that is the finding.

Are there default credentials or dormant accounts anywhere on that equipment? The advisory describes both being used in the same intrusion.

When did we last restore from a backup, not just run one? Restore, on real data, with someone timing it.

If the clinic gets encrypted on a Friday, what else goes with it? That question maps your segmentation, or shows you that you do not have any.

None of this is an AI question, and none of it requires a new platform. It is closer to checking whether the locks on a building that got renovated four times still work.

The sovereignty dimension is worth stating too. A ransomware incident that takes down enrollment records, health data, or utility billing is not only an IT event. It is a governance event, with federal reporting obligations attached and a set of records the tribe holds under its own authority. The recovery conversation is easier when it happens before the incident.

If you want a straight assessment of where a tribal network actually stands against this advisory, without a product being sold at the end of it, that is work we do.

Join the conversation

Straight talk welcome. Comments are moderated, no pitches, no spam.

Comments load once the Hyvor Talk Website ID is set in article.html.