Heads Up: A New Ransomware Threat Is Targeting Law Firms

Updated: 47 minutes ago
Federal law enforcement issued a warning in August about a ransomware operation called Gunra, and law firms were named among the targets.

Gunra uses what’s called double extortion. The attackers don’t just lock up your files so you can’t get to them, they steal a copy first. That gives them two forms of leverage behind one ransom demand: you’re paying to unlock your own files and to keep the stolen copy from being published. Firms typically get five to seven days to respond.
The reason this warning matters beyond one criminal group is distribution. Gunra has been around since spring of 2025. What changed this year is that its operators started renting the whole package out to other crews, with a management panel, ready-made builders, and documentation. That takes a fairly advanced toolkit and hands it to people who couldn’t have built it themselves. The name may fade. The tactics will keep showing up.
Most break-ins start through a known security hole in a firewall or VPN that already had a fix available and never got it applied. Investigators even found Gunra getting past multi-factor authentication a couple of times by taking over the VPN equipment itself, which is one more reason that equipment can’t be left to age. From there the attackers move through the network, destroying backups and stealing files before they set off the encryption. That middle stretch is your chance to catch them, and it’s easy to miss, because a login that works looks like an employee.
Four things to do this month:
Confirm your firewalls, VPNs, and remote access tools are fully patched.
Turn on multi-factor authentication, that second login step with a code or an app, for email, remote access, and anything holding client information.
Test your backups instead of just scheduling them, and keep a copy your main network can’t reach or delete.
Have something watching for logins and network activity that don’t add up, not just the software on your computers. It’s usually sold as MDR (managed detection and response).
Contributed by Sawyer Solutions.



