Karen Serobovich Vardanyan, an Armenian national extradited from Ukraine, pleaded guilty to computer fraud and conspiracy charges tied to Ryuk ransomware attacks carried out in 2019 and 2020, the Department of Justice announced Thursday. He faces up to 15 years in prison and agreed to pay nearly $1.2 million in restitution.
What happened
Vardanyan pleaded guilty to computer fraud and conspiracy to commit fraud and extortion. Between November 2019 and April 2020, he and his co-conspirators deployed Ryuk ransomware against three US-based organizations while he lived in Ukraine and Russia. His victims included a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon-based technology company attacked in December 2019, and a Texas-based school breached in February 2020. He is 34 years old and agreed to pay nearly $1.2 million in restitution as part of his plea.
The backstory
Prosecutors previously accused Vardanyan and his co-conspirators, Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, and Armenian national Levon Georgiyovych Avetisyan, of illegally accessing computer networks to deploy Ryuk ransomware on hundreds of compromised servers and workstations between March 2019 and September 2020.
Going deeper
Ryuk ransomware operators extorted victims by demanding Bitcoin payments in exchange for decryption keys. Justice Department officials said Vardanyan and his co-conspirators received about 1,160 bitcoins, valued at more than $15 million at the time, in ransom payments from victim companies. Vardanyan also acknowledged as part of his plea that his conviction will trigger immigration consequences, resulting in his removal from the United States after he serves his sentence. The U.S. District Court for the District of Oregon has not yet scheduled his sentencing.
What was said
Cynthia Kaiser, a former FBI Deputy Assistant Director of the Cyber Division now with the Halcyon Ransomware Research Center, told the U.S. House in April 2026 that reports to the FBI only capture a fraction of actual ransomware crime, and that reported attacks have risen more than 20% since 2023. She added that attacks which used to take weeks now take just a few hours, and that ransomware gangs target small and medium-sized businesses four times as often as large ones, a pattern that lines up with Vardanyan's victims, which included a school and two smaller companies rather than a large enterprise.
By the numbers
- Vardanyan agreed to pay nearly $1.2 million in restitution.
- He faces up to 15 years in prison.
- He and his co-conspirators received roughly 1,160 bitcoins in ransom payments, valued at more than $15 million at the time.
- The Michigan-based victim paid a ransom of nearly $1.2 million in January 2020.
Why it matters
This case shows that ransomware operators who targeted a small business, a tech company, and a school don't always stay out of reach, extradition from Ukraine and Russia proves cross-border cooperation can eventually catch up with attackers years after the fact. It also puts a number on the human cost behind Ryuk's spread, a single ransom payment near $1.2 million from one Michigan company, multiplied across hundreds of compromised servers and workstations tied to this group alone.
This case also fits a broader pattern of Ryuk's successor groups facing consequences. A Ukrainian national extradited from Ireland to the United States pleaded guilty to conspiracy charges tied to the Conti ransomware operation, a group that emerged from the Ryuk cybercrime group and became notorious for large-scale attacks against healthcare organizations. Unlike Vardanyan's case, which hit a school and two companies, that plea directly involved a healthcare-targeting operation, showing how the same lineage of ransomware actors moved from hitting schools and businesses to systematically targeting hospitals.
The bottom line
Vardanyan's guilty plea closes one chapter of the Ryuk ransomware campaigns that disrupted schools, tech companies, and businesses across the country, but his co-conspirators' cases and his own sentencing remain unresolved. The size of the ransom payments involved, nearly $15 million in bitcoin across the group's activity, shows why ransomware prosecutions like this one remain a priority for federal authorities and why the same lineage of attackers keeps resurfacing against new sectors, including healthcare, long after the original group disbands.
FAQs
What is Ryuk ransomware?
Ryuk is a strain of malicious software that encrypts a victim's files and systems, blocking access until a ransom is paid, and it was one of the most active ransomware strains targeting organizations worldwide between 2018 and 2020.
How does ransomware extortion work?
Attackers infiltrate a network, encrypt or steal data, then demand a cryptocurrency payment in exchange for a decryption key or a promise not to leak the stolen information.
Why do ransomware gangs demand payment in Bitcoin?
Cryptocurrency payments are harder to trace and easier to move across borders than traditional banking transactions, which makes them useful to cybercriminals operating internationally.
