Ransomware Gang Bypasses MFA on Fortinet VPNs — What to Check Now
A ransomware group called Gunra is actively exploiting known Fortinet VPN vulnerabilities to break into business networks — and they’ve found a way to bypass multi-factor authentication while they’re at it. Six government agencies, including the FBI, CISA, and the NSA, issued a joint advisory about the campaign in August.
This matters for Australian businesses because Fortinet is one of the most commonly deployed firewall platforms in the local SMB market. The vulnerabilities being exploited — CVE-2024-55591 and CVE-2025-24472 — aren’t new. They were disclosed in early 2025 and patches have been available for over a year. But plenty of appliances remain unpatched, and Gunra is taking advantage.
What makes this campaign different is the MFA bypass. After gaining access through the VPN flaw, the attackers modified authentication files on their victim’s VDI portal server so that a specific one-time password they controlled would always work. That’s not a brute-force attack or a phishing trick — it’s a persistent backdoor that survives password resets and keeps MFA switched on in name only. In one case, they also deleted backups at both the primary data centre and DR site before deploying ransomware.
We see a pattern across our Australian client base: businesses invest in MFA and assume the perimeter is handled. But if the device sitting in front of your MFA is itself compromised, none of that matters. It’s a reminder that patching your firewall firmware is just as critical as patching your servers and workstations.
Three things to do this week:
- Check your FortiGate firmware. If you’re running FortiOS or FortiProxy, confirm you’re on a version that patches CVE-2024-55591 and CVE-2025-24472. Both are in CISA’s Known Exploited Vulnerabilities catalogue.
- Review VPN and VDI authentication logs. Look for unusual login patterns, especially successful authentications from unexpected locations or at odd hours.
- Test your backups. Gunra specifically targets backup infrastructure. Make sure your backups are offline or immutable — not just on a NAS sitting on the same network.
If you’re not sure whether your Fortinet appliances are up to date, or you want a second set of eyes on your VPN configuration, get in touch with our cybersecurity team.
Related Guide
Cybersecurity for Sydney SMBs
Explore our complete guide to protecting your business from cyber threats.
