BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Sep 23, 2026 · 2 min read · Original story

Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million

Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million

An Armenian national was sentenced to two years in U.S. federal prison after pleading guilty in July to charges related to multiple ransomware attacks.

Karen Vardanyan, 35, will also have three years of supervised release and will have to pay $1,219,106 in restitution to victims of the cyberattacks he launched. Vardanyan was extradited from Ukraine in July 2025 after being arrested in Kyiv.

Prosecutors accused Vardanyan of being a core member of the Ryuk ransomware gang, noting in court documents that he and his co-conspirators launched over 2,400 ransomware attacks on victims around the world, including state and local municipalities.

The attacks “severely disrupted these entities’ abilities to function by restricting access to data and impacting communications,” prosecutors said.

At the height of the COVID-19 pandemic in 2020, the FBI and several other U.S. agencies warned that Ryuk actors were heavily targeting hospitals across the country. Hospital chain Universal Health Services was hit with a Ryuk attack that ultimately cost the company $67 million.

The DOJ said Vardanyan and his team received at least $15 million in ransoms from their attacks over the years.

Vardanyan personally launched several ransomware attacks and extorted more than $1 million from victims before he was placed on an international wanted list by the FBI. He pleaded guilty on July 8 to conspiracy and fraud in connection with computers.

Ryuk was first detected in August 2018, and the malware has previously been linked to Russian cybercriminals. U.S. officials took down Ryuk’s money laundering operations and experts tied the ransomware gang to a Russian group that also manages the Trickbot malware.

Several other members of the group have been identified and arrested over the last three years, including another Armenian national, Levon Georgiyovych Avetisyan, and two Ukrainians — Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, both 53.

A Russian man pleaded guilty in 2023 in an Oregon federal court to laundering funds for Ryuk over the course of three years after he was accused of being a middleman for the group alongside 13 unnamed co-conspirators.

References in this story

  1. Alleged Ryuk ransomware gang member arrested in Ukraine and extradited to US therecord.media A 33-year-old man arrested in Ukraine will face charges in the U.S. of working for the Ryuk cybercrime operation, known for high-profile targets and large ransom demands.
  2. The Investigators: Collierville ransomware attack cost over $100,000; town now considering legal action www.actionnews5.com The simple task of opening an email could end with hackers holding your digital life hostage. That is what happened to the Town of Collierville last summer.
  3. Ransomware Activity Targeting the Healthcare and Public Health Sector | CISA www.cisa.gov
  4. Universal Health Services lost $67 million due to Ryuk ransomware attack www.bleepingcomputer.com Universal Health Services (UHS) said that the Ryuk ransomware attack it suffered during September 2020 had an estimated impact of $67 million.
  5. US sanctions Russian accused of laundering virtual currency for ransomware affiliate therecord.media According to the Office of Foreign Assets Control, Ekaterina Zhdanova worked to help other Russians evade sanctions imposed on the country’s financial system after the invasion of Ukraine.
  6. Russian crypto exchange exec pleads guilty to laundering Ryuk ransomware funds therecord.media Denis Dubnikov pleaded guilty on Monday in an Oregon court on charges related to laundering funds for the Ryuk ransomware group.
  7. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  8. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  9. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  10. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

← Back to all news