Gunra
Gunra is an emerging ransomware group first identified in April 2025. It employs a classic double-extortion model—encrypting sensitive data and exfiltrating it for publication via a Tor-hosted leak site. Since its emergence, Gunra has struck a diverse set of global targets—reportedly spanning sectors like manufacturing, healthcare, IT, real estate, agriculture, and consulting in countries including Brazil, Japan, Canada, Turkey, South Korea, Taiwan, Egypt, and the U.S.
Most affected countries
- Spain1
- Indonesia1
- Thailand1
Most affected sectors
- Other4
- Pharma & chemicals2
- Finance & insurance1
- Hospitality & tourism1
- Legal1
- Technology1
Recent victims
| Organisation | Country | Sector | Claimed | Status |
|---|---|---|---|---|
| 🔒 Organización sin clasificar | — | Other | 8/19/2026 | ◌ Claimed (unverified) |
| PT All Cosmos Biotek | Indonesia | Pharma & chemicals | 8/6/2026 | ◌ Claimed (unverified) |
| 🔒 Entidad de tecnología | — | Technology | 8/5/2026 | ◌ Claimed (unverified) |
| Weilhotel | — | Hospitality & tourism | 8/2/2026 | ◌ Claimed (unverified) |
| Siam Stabilizers and Chemicals | Thailand | Pharma & chemicals | 8/2/2026 | ◌ Claimed (unverified) |
| Dissinger and Dissinger Law Firm | — | Legal | 7/18/2026 | ◌ Claimed (unverified) |
| New Tiles S.L. | Spain | Other | 7/13/2026 | ◌ Claimed (unverified) |
| Pirámide Seguros | — | Finance & insurance | 7/10/2026 | ◌ Claimed (unverified) |
| 🔒 Entidad comercial | — | Other | 7/10/2026 | ◌ Claimed (unverified) |
| Yuditec S.A. | — | Other | 7/10/2026 | ◌ Claimed (unverified) |
Claims are published by the criminal groups themselves and are unverified until the organisation or the press confirms them. Names of natural persons (sole traders, individual professionals) are anonymised under the GDPR. We never link to leak sites or stolen data. To request the removal or anonymisation of an entry, contact the site administrator.
Sources: RansomLook (CC BY 4.0), MITRE ATT&CK®, MISP Galaxy, Google News.