Armenian hacker receives two-year sentence for Ryuk ransomware attacks

Karen Serobovich Vardanyan, a 35-year-old Armenian national, was sentenced to 24 months in prison and three years of supervised release for his role in Ryuk ransomware attacks against U.S. organizations between 2019 and 2020. He pleaded guilty in July after being extradited from Ukraine, where he was arrested in April 2025. Court records show he and accomplices collected about 1,610 bitcoins in ransom payments, valued at over $15 million at the time.
Vardanyan’s role focused on breaching corporate networks, a critical first step in Ryuk’s operations. His targets included a Michigan firm, a Texas school, and an Oregon tech company, with one victim paying 200 bitcoin. The group’s total haul reached roughly 1,610 bitcoin, worth over $15 million at the time. Ryuk itself operated as a ransomware-as-a-service model, peaking at about 20 victims weekly before shutting down in 2020. Its successor, Conti, later collapsed after internal leaks, fragmenting into smaller cybercrime units.
The case highlights the international reach of ransomware investigations. Vardanyan was arrested in Ukraine and extradited to the U.S., where he pleaded guilty in July. His sentence includes supervised release, reflecting a pattern of prosecuting individual enablers rather than just the core gang leaders. The Justice Department’s July statement emphasized the coordinated nature of the attacks, which involved hundreds of compromised servers and workstations across multiple victims.
This sentencing may reinforce deterrence for lower-level ransomware operatives, showing that even initial-access specialists face prison time and extradition. Organizations in sectors like healthcare and education—frequent Ryuk targets—could see this as a signal that law enforcement is actively dismantling attack chains, though the broader threat persists as successor groups evolve. Victims may gain some reassurance, but the financial and operational damage from such attacks remains a lasting concern for businesses and public institutions alike.