Back to Feed
RansomwareSep 24, 2026

US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks

US court sentences Armenian national Karen Vardanyan to prison for Ryuk ransomware attacks.

Summary

Karen Vardanyan, an Armenian national, has been sentenced to 24 months in federal prison by a US court for his involvement in Ryuk ransomware attacks between March 2019 and June 2020. He was also ordered to pay over $1.2 million in restitution to victims. Vardanyan pleaded guilty to conspiracy and computer fraud charges.

Full text

Karen Vardanyan, a 35-year-old Armenian national, has been sentenced to prison by a US court for his role in Ryuk ransomware attacks, the Justice Department announced this week. Vardanyan was charged by a grand jury in the United States in February 2024 with conspiracy, fraud, and extortion in connection with computers. He was arrested in Ukraine in April 2025 and extradited to the United States in June 2025. He pleaded guilty to conspiracy and computer fraud in July 2026. Vardanyan has now been sentenced to 24 months in federal prison, followed by 3 years of supervised release. Under federal law, time spent in pretrial detention is credited toward the prison term. Vardanyan has been in custody since his extradition, so he has already served a substantial portion of the 24-month sentence. According to authorities, the Armenian man was involved in Ryuk ransomware attacks between March 2019 and June 2020. Advertisement. Scroll to continue reading. Based on the DOJ’s description, Vardanyan was likely a ransomware affiliate or initial access provider rather than part of the team that developed the malware and operated the infrastructure supporting Ryuk attacks. He extorted more than $1 million from several victims via ransomware attacks, and he has now been ordered to pay more than $1.2 million in restitution to victims. Several individuals involved in ransomware operations have been sentenced to prison this year. Most recently, a Ukrainian Conti ransomware developer received a 4-year prison sentence in the United States, and a Ukrainian accused of creating the Lockergoga, MegaCortex, and Nefilim ransomware families has been sentenced to 13 years in prison by a Swiss court. Related: Two Scattered Spider Hackers Sentenced to Jail in UK Related: Snowflake Hacker Pleads Guilty in US Court Related: Ukrainian Man Pleads Guilty in US to Conti Ransomware Charges Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs ShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityOnly 13% of OT Network Segments Are Fully Isolated: AnalysisJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeDragos Completes NetRise and runZero Acquisitions Following Accenture DealRust Team Members and Popular Crate Owners Targeted via Video CallsColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsGoogle Confirms Gemini AI Breached Three Firms Latest News Astrana Health Data Breach Impacts Private, Confidential InformationCritical WordPress Vulnerability Exploited Immediately After DisclosureIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderWorries About an AI Internet Takeover Gain New Urgency Among Doomsday ScenariosHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareAdobe Patches Critical Flaws in Connect, AEM FormsAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftChrome 154 Patches 108 Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Building Continuous Authorization at Scale September 23, 2026 Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required. Register People on the MoveGwen Gann has become State Chief Information Security Officer for the State of Washington at WaTech.Pietr Lindahal has been named Vice President and Chief Information Security Officer at Boston Scientific.AI agent identity and enforcement company FIOR has appointed Gemma Ungoed-Thomas as Adviser.More People On The MoveExpert Insights “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • malware — Ryuk

Entities

Karen Vardanyan (threat_actor)