Gunra Ransomware Hits Three Uruguayan Firms in Three Months
Uruguay · Cybersecurity
A ransomware group called Gunra has posted three Uruguayan companies on its leak site in less than three months. The victims include an ad agency, a commercial interiors maker, and a law firm.
Key Facts
- What happened:Gunra ransomware listed three Uruguayan companies on its leak site.
- Who it hits:Victims: an ad agency, a commercial interiors maker, and a law firm.
- How big:Gunra claims it stole 40 GB, 30 GB, and 300 GB of data.
- The catch:The law firm has not confirmed the attack, so its name is withheld.
- What comes next:Gunra is under FBI watch, according to Uruguayan newspaper El Observador.

Gunra ransomware has listed three Uruguayan companies on its leak site in less than three months. The victims include an advertising agency, a commercial interiors maker, and a law firm.
Three Uruguayan Victims in Three Months
Gunra ransomware has posted three Uruguayan companies on its leak site since June 2026. The first victim, an advertising agency, appeared on 12 June 2026.
The second, a company that designs and manufactures commercial interiors, was listed on 30 June 2026. The third, a law firm, was added on 4 September 2026.
Sectors, Not Names, in Initial Report
The first report, from Uruguayan newspaper El Observador, described the victims by sector only. It did not publish the company names.
Threat-intelligence trackers have separately identified the law firm as Blanco & Etcheverry. The firm has not commented on the alleged attack.
What Is Ransomware and Double Extortion?
Ransomware is malicious software that encrypts a victim’s files. Attackers demand payment to unlock them.
Double extortion adds a second threat: attackers steal data before encrypting. They then threaten to publish the stolen data on a public leak site if the victim does not pay.
Gunra’s Claims About Data and Revenue
Gunra’s leak site claims it published 40 GB of files from the advertising agency after non-payment. It also claims it stole 30 GB from the commercial interiors company.
For the law firm, Gunra says it leaked 300 GB of data and estimates the firm’s revenue at US$5 million. These are the group’s own claims, not verified by independent sources.
Gunra Under FBI Watch
El Observador reported on 7 September 2026 that Gunra is under the FBI’s watch. The article described how Gunra operates.
Gunra uses a leak site with a countdown clock to pressure victims. It demands payment and publishes stolen files when victims do not pay.
Uruguay’s Cybersecurity Response
Uruguay’s cybersecurity bodies have not yet issued a public statement about these specific attacks. The government’s national cybersecurity agency, known as CERTuy, has not commented.
Experts advise companies to back up data and train staff to spot phishing emails. They also recommend having a response plan ready.
What Victims Should Do
Companies hit by ransomware should not pay the ransom, experts say. Paying encourages more attacks and does not guarantee data recovery.
Instead, they should report the incident to authorities and seek help from cybersecurity professionals. They should also notify affected customers and partners.
Who Gunra Are
Gunra surfaced in April 2025. The United States FBI and the cybersecurity agency CISA issued a joint advisory on the group on 10 August 2026.
That advisory says Gunra appears to be built on Conti ransomware code leaked in 2022. Conti was one of the largest criminal ransomware operations before it broke up.
Frequently Asked Questions
What is Gunra ransomware?
Gunra is an international ransomware group that uses double extortion. It encrypts files and threatens to leak stolen data if victims do not pay.
Which Uruguayan companies were hit?
Gunra listed an advertising agency, a commercial interiors maker, and a law firm. The law firm is believed to be Blanco & Etcheverry, but it has not confirmed the attack.
How much data was stolen?
Gunra claims it stole 40 GB from the ad agency, 30 GB from the interiors maker, and 300 GB from the law firm. These figures are unverified.
Is the FBI involved?
El Observador reported that Gunra is under FBI watch. However, there is no official confirmation of an FBI investigation.
Sources: El Observador; FBI and CISA joint advisory, 10 August 2026; ransomware.live.
This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error
LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.
Read More from The Rio Times