Armenian Ryuk Ransomware Hacker Sentenced to 2 Years in US Prison

Last updated: September 24, 2026 Reading time: 5 minutes
Disclosure
Share
Armenian Man Sentenced to 2 Years in Prison Over Ryuk Ransomware Attacks
  • Armenian national Karen Vardanyan received 24 months in prison and three years of supervised release.
  • Prosecutors said Vardanyan played a crucial role in Ryuk attacks that locked US companies’ servers and workstations.
  • Vardanyan pleaded guilty after authorities extradited him to the US from Ukraine, and must now pay restitution of approximately $1.22 million.

An Armenian man who helped launch Ryuk ransomware attacks against U.S. companies will spend two years in federal prison. Karen Serobovich Vardanyan, 35, got a 24-month prison sentence on September 22. After that, he’ll spend three years on supervised release and pay back $1,219,106 in restitution.

U.S. District Judge Michael Mosman handed down the sentence in Oregon. According to the DoJ’s press release, Vardanyan also used the online names “Maneeken” and “Karl Lagerfeld.” He helped break into several company networks to deploy Ryuk ransomware.

Vardanyan was arrested with the help of Ukrainian authorities in Kyiv in April 2025. From there, the U.S. extradited him. A little over a year later, in July 2026, he pleaded guilty to the charges of conspiracy and computer fraud.

Vardanyan Helped Attackers Penetrate Networks

Court records associated Vardanyan with a hacking group behind the November 2019 to April 2020 attacks targeting US firms. His role? To help criminals gain access to the networks of target companies. After the attackers made it inside, they spread Ryuk across servers and workstations.

The case also highlights the broader importance of protecting personal information and privacy, as shown in our report on Apple reverses rlan to change the Hide My Email domain after privacy concerns. The group then locked files and demanded Bitcoin from its victims.

The Justice Department says the group locked hundreds of servers and workstations across the affected networks. One victim was a company in Michigan. According to the prosecutors, the company made a payment of 200 Bitcoins to the attackers. This amount had a value of more than $1.1 million.

The case also covers attacks against a school in Texas and a technology company in Wilsonville, Oregon. The Oregon victim helped bring the case under federal jurisdiction.

According to the Justice Department, Vardanyan and his partners pulled in around 1,610 Bitcoin in ransom payments, worth over $15 million during that time. Vardanyan is expected to repay some of that money by restituting approximately $1.22. That amount covers losses tied to his case. It does not represent the full ransom total linked to the wider group.

Vardanyan’s Delayed Extradition

Vardanyan was arrested by Ukrainian law enforcement in Kyiv in April 2025. About two months afterwards, he was sent back to America, where he faced judgment at a federal court in Oregon.

The Justice Department’s Office of International Affairs helped arrange the transfer. The FBI was in charge of the investigation. The prosecution happened in Oregon under the leadership of Assistant U.S. Attorney Katherine A. Rykken.

This case highlights the length of time it takes to resolve ransomware investigations. The attacks took place between 2019 & 2020, but Vardanyan’s arrest didn’t happen until five years later. His case forms part of a wider effort to find people who worked with the Ryuk group.

Ryuk Caused Major Damage

Ryuk first appeared in August 2018. It soon became one of the biggest ransomware threats of its time. A joint alert from CISA, the FBI, and the Department of Health and Human Services described Ryuk’s attack methods.

Attackers often used other malware to get inside a target. They then moved through the network, stole account details, and locked files.

Ryuk became known for attacks on hospitals and other key services. In 2020, the ransomware hit a major U.S. hospital network with hundreds of sites. The attack disrupted systems across 250 sites and forced some workers to use paper records.

Ryuk operators also demanded large payments from many other victims. At one time, the group hit around 20 victims every week. People say they pulled in over $150 million in ransom money. That’s a large figure, which explains why U.S. agencies kept chasing Ryuk members, even after the group’s activity died down.

Ryuk Faded, but the Group Moved on

Ryuk activity fell sharply in 2020. However, individuals behind this operation didn’t get off the hook. Cybersecurity experts and investigators have connected the broader network to the hacking group calling itself the Wizard Spider.

Once Ryuk became inactive, the gang moved to the ransomware Conti. Conti went on to become one of the most active ransomware gangs in the world. The group disbanded in 2022 due to someone leaking the private conversations and source code of the group. This helped researchers get a glimpse into how the gang operated and communicated with each other.

Some of the former members of the Conti gang joined other ransomware gangs and criminal groups. That history adds context to the Vardanyan case. A ransomware name can disappear without ending the people behind it. Investigators can spend years tracing payments, online names, and other clues.

Vardanyan’s sentence adds another conviction to that long-running effort. For victims, the attacks ended years ago. For investigators, the cases can stay open long after criminals demand payment. The new sentence shows that authorities can still pursue people linked to major ransomware attacks years after the attacks occur.

Share this article

About the Author

Farwa is an experienced InfoSec writer and cybersecurity journalist skilled in writing articles related to cybersecurity, AI, DevOps, Big Data, Cloud security, VPNs, IAM, and Cloud Computing. Also a contributor on Tripwire.com, Infosecurity Magazine, Security Boulevard, DevOps.com, and CPO Magazine.

More from Farwa Sajjad

Related Posts