Ransomware Awareness Training: Gunra Targets Nonprofits

Abstract digital representation of cybersecurity protection

On August 10, 2026, CISA, the FBI, the National Security Agency, and South Korea’s National Police Agency issued a joint advisory warning organizations worldwide about Gunra ransomware, a fast-growing criminal operation that has already claimed Canadian victims. Advisory AA26-222A names healthcare providers, nonprofit services, financial institutions, and government agencies as active targets and describes an attack chain that begins, in many cases, with a single phishing email reaching an unprepared employee.

For Canadian organizations still treating ransomware as a technology problem to be solved with patching alone, the Gunra advisory is a direct challenge to that assumption.

What the CISA Advisory Actually Says

Gunra first emerged in April 2025, built on the leaked source code of the Conti ransomware family. By January 2026, its operators had launched a formal ransomware-as-a-service (RaaS) affiliate program, recruiting penetration testers and access brokers through dark web forums and offering them a share of ransom proceeds. The result is a structured criminal operation, not a lone actor running improvised campaigns.

The advisory identifies two primary attack vectors. The first is exploitation of known vulnerabilities (CVE-2024-5559 and CVE-2025-24472) in unpatched Fortinet VPN and firewall devices. The second, and the one most directly relevant to anyone building a security awareness program, is phishing. CISA confirmed that Gunra affiliates use phishing as a primary delivery method for their malicious payloads, often combined with credentials harvested during those same campaigns.

The targeted sectors include healthcare and public health, professional and nonprofit services, financial services, government facilities, and academic institutions. Canada’s involvement is already confirmed: Gunra’s leak site lists Canadian manufacturers, healthcare providers, and law firms among its victims. Nonprofits and healthcare organizations enrolled in POPP3R’s Security101 structured awareness program receive training modules specifically designed for high-risk sectors operating on constrained budgets, which is precisely the organizational profile Gunra affiliates are now targeting.

The Canadian Centre for Cyber Security’s Ransomware Threat Outlook 2025 to 2027, released in December 2025, described ransomware as one of Canada’s most serious and persistent cyber threats, noting that 336 pre-ransomware notifications were issued to more than 300 Canadian organizations between 2024 and 2025, with estimated economic savings of up to CAD $18 million for those who acted on the alerts in time. Not every organization will receive a warning before encryption begins.

Why Phishing Remains the Door That Ransomware Walks Through

Patching CVE-2024-5559 and CVE-2025-24472 is urgent, and every IT team should prioritize those vulnerabilities this week. But Gunra’s use of phishing as a parallel attack vector means patching alone does not close the exposure. A fully updated network can still be compromised by an employee who clicks a convincing lure and enters credentials on a spoofed login page, because no patch addresses a person’s judgment under pressure.

The 2026 Verizon Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches, found the human element present in 62 per cent of incidents, up from 60 per cent the previous year. Social engineering accounted for 16 per cent of all breach patterns overall. Those figures describe the same dynamic the Gunra advisory illustrates: attackers keep investing in phishing because that is still where the reliable returns are.

What Ransomware Awareness Training Must Cover Right Now

In our work with Canadian nonprofits, we consistently see organizations operating with security budgets a fraction of their commercial peers, while facing the same threat actors. The pattern in this story is one we encounter monthly: well-meaning staff, no formal training program, and a single click away from a crisis they cannot afford to recover from.

Effective ransomware awareness training in 2026 needs to go beyond telling employees not to click suspicious links. Gunra affiliates use professional-grade phishing tools capable of bypassing basic spam filters and mimicking internal communications convincingly. Training must address the social engineering mechanics underneath the technical delivery: impersonation of vendors and IT staff, artificially urgent language designed to override careful thinking, requests to open attachments from unfamiliar senders, and login prompts appearing in unexpected contexts.

The single highest-leverage investment a Canadian nonprofit or healthcare organization can make right now is building a culture where employees report suspicious activity immediately, before a compromise spreads laterally. Organizations that contain ransomware incidents quickly are, almost without exception, the ones where someone picked up the phone and reported what they saw within minutes of encountering it. POPP3R’s approach to managing human cyber risk puts reporting culture at the centre of program design, because click rates measure who failed a test but not whether your organization can actually contain a real threat when it arrives.

The IBM Cost of a Data Breach Report 2026 found that the average Canadian data breach now costs $7.11 million, a record high. That figure is not an abstract statistic for the sectors Gunra is actively targeting. The time to build the training program is before the ransom note appears on the screen. For organizations wanting to understand where their human risk exposure actually sits today, POPP3R’s cybersecurity services include both posture review and structured awareness program design.

Sources