An Armenian national involved in Ryuk ransomware attacks has been sentenced to 24 months in U.S. federal prison and ordered to pay more than $1.2 million in restitution to victims.
Karen Vardanyan, 35, participated in attacks carried out between March 2019 and June 2020. He was arrested in Ukraine in April 2025, extradited to the United States two months later, and pleaded guilty to conspiracy and computer fraud in July 2026. His prison sentence will be followed by three years of supervised release.
Providing Access for Ryuk AttacksAccording to U.S. authorities, Vardanyan helped compromise corporate networks that were subsequently infected with Ryuk ransomware.
SecurityWeek notes that the Justice Department’s description suggests he likely operated as a ransomware affiliate or initial access provider, rather than being one of the developers responsible for creating Ryuk or maintaining its core infrastructure.
This type of role became increasingly important as ransomware developed into a specialized criminal ecosystem. Instead of one group handling an entire attack, different participants could specialize in gaining initial access, stealing credentials, moving laterally through networks, deploying ransomware, or negotiating payments.
Access brokers could compromise an organization and then provide that foothold to ransomware operators capable of expanding the intrusion.
More Than $1 Million ExtortedAuthorities linked Vardanyan to attacks that extracted more than $1 million from several victims.
His sentence includes more than $1.2 million in restitution intended to compensate organizations affected by the attacks.
Vardanyan has already spent considerable time in custody. Under U.S. federal rules, time spent in pretrial detention counts toward a prison sentence, meaning his detention since extradition will reduce the amount of the 24-month term he still has to serve.
Ryuk Became a Major Ransomware ThreatRyuk emerged in 2018 and became one of the most prominent ransomware families targeting businesses and public organizations.
Rather than focusing primarily on individual users, its operators pursued organizations where disrupting operations could generate substantial ransom payments. Attackers typically attempted to gain broad control over a network before deploying ransomware across servers and endpoints.
Ryuk was also notable for attacks against hospitals and other healthcare organizations, including during the COVID-19 pandemic.
The operation eventually disappeared, but parts of the criminal ecosystem associated with Ryuk evolved into or became connected with later ransomware operations such as Conti.
Ransomware Cases Continue Years After the AttacksVardanyan’s case illustrates how cybercrime investigations can continue long after the ransomware operation itself disappears.
He was charged by a U.S. grand jury in February 2024 for attacks dating back as far as 2019, arrested in Ukraine the following year, and sentenced in September 2026.
Other major ransomware participants have also received prison sentences during 2026. A Ukrainian Conti ransomware developer was sentenced to four years in the United States, while a Ukrainian linked to the creation of Lockergoga, MegaCortex, and Nefilim received a 13-year sentence in Switzerland.
These cases demonstrate one of the long-term risks for ransomware operators. Criminal groups may rebrand, disappear, or fragment into new organizations, but cryptocurrency transactions, infrastructure records, communications, and other digital evidence can remain useful to investigators years later.
Ryuk may no longer be an active ransomware brand, but authorities are still pursuing the individuals who helped make its attacks possible.