A 34-year-old Armenian, Karen Serobovich Vardanyan, pleaded guilty in the US for his role in Ryuk ransomware, in a case linked to extortion and encryption of corporate networks in 2019-2020, according to a statement from the US Department of Justice.

The case concerns attacks on American businesses and organizations, where the perpetrators installed Ryuk ransomware on servers and workstations, blocking access to critical data until a ransom was paid in Bitcoin.
See also: Ukrainian accused of participating in Conti ransomware attacks
What did he admit to and what punishments does he face?
According to the same announcement, Vardanyan pleaded guilty to conspiracy and computer fraud, while the maximum sentence mentioned is up to 5 years for conspiracy and up to 10 years for computer fraud.
The prosecution arose from a three-count indictment handed down by a federal grand jury in Portland in February 2024, with the case also including a charge of extortion.

Ryuk ransomware: the operational pattern of attacks
Authorities say that, from November 2019 to April 2020, the defendant and his accomplices gained illegal access to victims' networks and then deployed the Ryuk ransomware to hundreds of systems, leaving a ransom note with payment instructions in Bitcoin and an email address for contact.
In one of the examples described, a company in Michigan paid 200 BTC (about $1.1 million "at the time") to regain access to its network, while additional victims are reported in Oregon and a school in Texas (attacked in February 2020).
For targeted organizations, such incidents are not just a matter of paying the ransom: encryption is often accompanied by loss of service availability, freezing of internal processes, and the need for time-consuming restores from backups. Moreover, even when recovery occurs, the risk of re-infection remains if the initial “entry” into the network is not isolated.
Experience from past campaigns shows that the ransomware attack chain often starts with stolen credentials, poor remote access protection, or another breach that allows lateral movement. At this stage, attackers seek out highly privileged accounts, hit management servers, and attempt to weaken recovery mechanisms so that the eventual deployment of Ryuk ransomware can have the greatest possible impact.
See also: Russian basketball player arrested for involvement in ransomware attacks
For law enforcement, such trials also serve as a deterrent, especially when combined with international cooperation for arrests and extraditions. For businesses, it is a reminder that ransomware preparedness should be treated as a business continuity issue, not an “emergency.”.
Compensation and penalty assessment date
As part of the agreement, Vardanyan agreed to pay more than $1.1 million in restitution, while sentencing is scheduled for September 22, 2026, according to the US authorities' announcement.

What it means for organizations' defense against ransomware
Although the case concerns incidents from 2019-2020, it reminds us that ransomware remains one of the most costly threats to organizations. The SecNews technical team points out that basic measures such as multi-factor authentication (MFA), proper privilege management, backup isolation, and regular remediation exercises can significantly reduce the risk.
For additional technical background on how Ryuk ransomware works and how it has historically been used in targeted “big game hunting” attacks, readers can see a related analysis on CrowdStrike or the MITRE ATT&CK entry on Ryuk.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Rising Ransomware attacks worry the US

BleepingComputer 's report highlights that such cases continue to concern authorities, as the economic footprint of ransomware attacks often extends to downtime, lost productivity, and recovery costs beyond the ransom amount itself.
