
The FBI and its federal partners have issued a new #StopRansomware advisory regarding Gunra, a ransomware variant first identified in 2025 that has expanded into a ransomware-as-a-service operation. Notably, the advisory specifically lists professional services among the sectors Gunra is targeting. This isn’t a general-purpose warning, but instead is directed at lawyers and law firms among other specific professions.
Like many modern ransomware attacks, Gunra uses a double-extortion model. Attackers don’t just encrypt an organization’s files and demand payment to unlock them. They also steal the data first and threaten to publish it if the ransom isn’t paid, typically giving victims about a week before they follow through.
For law firms, that distinction is particularly important. A good backup may help a firm restore its files, but it cannot undo the theft or disclosure of confidential client information.
The FBI also reports that Gunra actors have tried a more direct tactic: emailing firm management to demand payment personally. If a partner or managing attorney gets an email like that, it’s worth knowing it’s part of a known pattern, not a one-off scam attempt.
The FBI’s recommendations are technical, but their meaning and implementation for law firms don’t have to be.
Three Things to Discuss with Your IT Provider
1. Keep Internet-Facing Systems Up to Date
FBI recommendation: Prioritize patching known exploited vulnerabilities in internet-facing systems, including VPN gateways and Remote Desktop Protocol (RDP) infrastructure.
In plain English: Keep anything that connects your firm’s systems to the internet up to date, especially software or systems used for remote access.
Software and hardware sometimes contain security flaws. When a manufacturer discovers one, it generally issues an update, or “patch,” to fix it. In fact, the FBI has confirmed that Gunra attackers are getting into networks through flaws that already have fixes available. They’re simply counting on firms not having installed them yet.
Think of it as discovering that the lock on a particular model of door is defective. The manufacturer has provided a replacement, but it only protects you if you install it. Don’t assume automatic updates on individual computers take care of everything. Firewalls, servers, VPNs, and other network equipment may require separate maintenance.
Ask your IT provider:
Are all of our computers, servers, firewalls, VPNs, remote-access systems, and other internet-facing devices receiving security updates promptly?
2. Have a Backup the Criminals Can’t Reach
FBI recommendation: Implement and test offline, immutable backups stored separately from the firm’s primary systems.
In plain English: Your firm needs a backup that an attacker cannot alter, encrypt, or delete.
Simply saying “we back everything up to the cloud” may not be enough. If an attacker gains sufficient access to the firm’s systems or cloud accounts, the attacker may also be able to reach accessible backups. This isn’t hypothetical. The FBI reports that in at least one Gunra attack, the criminals disabled the victim’s backup system entirely and deleted backup files stored at both the main office and the separate disaster-recovery site. The organization thought it had a safety net. It didn’t. A backup isn’t much of a safety net if the criminals can cut the net.
An offline backup is not continuously connected to the firm’s network. An immutable backup is designed so stored data cannot be changed or deleted for a specified period.
And don’t overlook one important word in the FBI’s recommendation: TEST. A successful backup notification doesn’t necessarily mean the firm can successfully restore its systems and files.
Ask your IT provider:
If ransomware encrypted our systems today, could we restore our files from a backup the attacker could not access or delete? When was the last time we tested that restoration?
3. Don’t Let One Compromised Computer Become an All-Access Pass
FBI recommendation: Segment networks to restrict “lateral movement.”
In plain English: If an attacker gets into one employee’s computer, make it difficult to get into everything else.
Imagine an office where every interior door is separately secured. Getting through the reception-area door doesn’t automatically provide access to accounting, the file room, and every lawyer’s office.
Network segmentation applies a similar concept to technology. Barriers between employee computers, servers, accounting systems, backups, and other sensitive resources can help contain an attack rather than allowing it to spread throughout the firm.
Ask your IT provider:
If one employee’s computer is compromised, what prevents an attacker from reaching our server, accounting system, backups, and other computers?
Think in Layers
No single security measure can eliminate ransomware risk. Instead, think in layers:
Keep them out. Promptly update and patch systems, particularly those accessible from the internet.
Limit their reach. Configure the network so compromising one device or account does not provide access to everything.
Be ready to recover. Maintain backups that attackers cannot alter or destroy — and test them.
Protect the information itself. Remember that modern ransomware may involve data theft as well as encryption. Restoring from a backup doesn’t solve the problem if confidential client information has already been stolen. Ensure you discuss with your IT provider what protections you have in place to prevent an attacker from accessing and removing confidential client information.
If you don’t know the answers to the questions above, now is a good time to ask. Then, calendar to ask them again.
Cybersecurity doesn’t require lawyers to become IT professionals. But protecting client information and maintaining the ability to operate after a cyberattack requires law firms to understand the questions they should be asking.
Additional Protection for Firms
Proactive measures like regular updates and recommended security practices can help to protect you and your firm from threats like these. But not all ransomware attacks and cyber incidents can be prevented, even with the best practices put in place. This is where something like our Cyber Liability Endorsement comes into play. If you are already one of our Florida Lawyers Mutual members, then your policy includes an Automatic Cyber Liability Endorsement, which provides you with specific cyber liability coverage in the event of a cybersecurity incident or breach. We also offer our members the opportunity to purchase additional cyber liability coverage through our Cyber Liability Increased Limits Program.
For more information about our policies and exclusive member benefits, explore our site or apply today.
Source: FBI/CISA #StopRansomware: Gunra Ransomware Advisory (AA26-222A), August 10, 2026.


