Ryuk Ransomware Operator Sentenced to Two Years in US Prison
Karen Vardanyan, a 35-year-old Armenian national, has been sentenced to two years in prison for his part in a series of Ryuk ransomware attacks conducted while he was based in Ukraine and Russia. He was extradited to the United States and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion. The sentence also requires him to pay about $1.2 million in restitution to victims.
Vardanyan and his co-conspirators were accused of breaking into computer networks and deploying Ryuk ransomware on hundreds of servers and workstations between March 2019 and September 2020. Victims named in court records include a Michigan company that paid nearly $1.2 million in ransom, a technology firm in Oregon, and a school district in Texas. Ryuk was one of the most damaging ransomware strains of that period, hitting hospitals, local governments, school districts and news outlets, with the group receiving an estimated $15 million worth of bitcoin from victims.
Prosecutors said the case shows how even lower-level participants in ransomware operations, not just the masterminds, play a critical role in these crimes and can still face significant prison time when caught.