Key Takeaways
- Gunra uses double extortion and often gains access through exposed internet-facing systems
- Media, leisure, and entertainment victims reported a 64% ransom payment rate in 2026
- Offline backups, segmentation, access controls, and rehearsed recovery plans can limit operational damage
Ransomware remains a stubborn operational threat for broadcasters, streaming services, publishers, and other media businesses that depend on tightly connected production systems. A joint CISA and FBI advisory issued in August 2026 highlights Gunra, a ransomware-as-a-service operation that combines data encryption with the threat of publishing stolen information.
Gunra first emerged in April 2025 and has since targeted multiple critical infrastructure sectors. According to the advisory, its operators commonly seek entry through internet-facing systems, including infrastructure exposed through virtual private networks and Remote Desktop Protocol. Known vulnerabilities and weak access controls can offer a route from an overlooked edge device into more sensitive environments.
That matters in media. A compromised business network can interfere with advertising systems, scheduling, newsroom operations, payroll, archives, audience data, and digital publishing. If production and corporate environments are insufficiently separated, attackers may gain opportunities to move farther than the initially compromised system.
An Audacy ransomware topic page brings these risks into the media and broadcasting conversation, although it functions as a collection of updates rather than a report about one newly disclosed incident at the company. The distinction is important. The available material supports a sector-level warning, not a claim that Audacy experienced a specific attack associated with Gunra.
Media businesses face unusually intense pressure when systems go offline. Broadcast schedules continue, advertisers expect campaigns to run, and audiences quickly notice unavailable programming. Sensitive material may also include unreleased content, source information, contracts, employee records, and customer data. Attackers can use that time sensitivity to strengthen their leverage.
The payment figures illustrate the problem. The Sophos State of Ransomware 2026 findings put the ransom payment rate among media, leisure, and entertainment victims at 64%, compared with 48% across encrypted victims overall. Payment does not remove the operational work of investigation and rebuilding. It may also leave questions about stolen data, persistence inside the network, regulatory exposure, and whether criminals retained copies.
Double extortion makes backup strategy only part of the answer. A business may restore encrypted systems and still face threats that confidential files will be leaked. So what reduces the attackers' leverage? CISA and FBI emphasize immutable offline backups and network segmentation, alongside stronger protection for exposed services. Media companies can also review privileged accounts, enforce multifactor authentication, restrict unnecessary RDP access, and prioritize patches for VPN appliances and other edge infrastructure.
Segmentation deserves particular attention. Broadcast automation, editing systems, content repositories, advertising operations, email, identity services, and general office technology do not all need unrestricted communication. Carefully designed boundaries can slow lateral movement and give incident responders more room to isolate affected assets. Shorter access paths also make monitoring less noisy.
Preparation should extend beyond the security team. Editors, producers, sales leaders, legal counsel, communications staff, and senior executives may all have decisions to make during an outage. Which programming functions receive priority? Who can authorize service isolation? How will advertising partners and audiences be updated? Those details are awkward to settle while an extortion clock is already running.
The broader threat environment offers little reason for complacency. ENISA's 2025 Threat Landscape tracked 82 deployed ransomware variants and described ransomware as the most impactful threat in the EU during its reporting period. Rhysida has also publicly claimed media-sector victims, including KISS FM, showing that criminal groups continue to view broadcasting and content businesses as viable targets.
For governance, NIST Cybersecurity Framework 2.0 provides a practical structure for connecting technical controls with executive oversight, while CISA's Cross-Sector Cybersecurity Performance Goals offer a baseline for reducing common attack paths. Neither turns ransomware into a checklist exercise. They can, however, help media leaders test whether recovery plans, identity controls, asset inventories, vendor access, and executive decision processes work together.
The real measure is not whether every intrusion attempt can be stopped. It is whether CISA and FBI's warning prompts media companies to reduce exposed access, contain breaches quickly, preserve trustworthy recovery copies, and keep essential content operations running when attackers get through.
⬇️