Ryuk ransomware member pleads guilty in the U.S., faces up to 15 years in prison
A 34-year-old Armenian national, Karen Serobovich Vardanyan, has pleaded guilty in a U.S. federal court to breaking into the networks of American companies and deploying Ryuk ransomware, BleepingComputer reports. Vardanyan, who specialized in gaining initial access to corporate systems, was arrested in Kyiv in April 2025 and later extradited to the United States.
According to the U.S. Department of Justice, Vardanyan and his co-conspirators compromised the networks of multiple U.S. organizations between November 2019 and April 2020, encrypting hundreds of servers and workstations. Named victims include a Michigan company that paid a ransom of 200 bitcoin — worth over $1.1 million at the time — as well as a technology firm in Wilsonville, Oregon, and a school in Texas. Prosecutors say the conspirators collected roughly 1,610 bitcoin in ransom payments, valued at about $15 million when paid.
Ryuk was among the most damaging ransomware operations of its era, active from 2018 to mid-2020 and notorious for attacks on healthcare providers during the COVID-19 pandemic. At its peak the gang was estimated to hit around 20 organizations per week, and after it wound down many members migrated to the Conti operation, whose later splinter groups remain active in the cybercrime ecosystem today.
Vardanyan, indicted by a federal grand jury in Portland in February 2024, is scheduled for sentencing in September 2026. He faces a maximum of 15 years in prison across two charges, fines of up to $250,000 on each, and has agreed to pay more than $1.1 million in restitution as part of his plea deal.