Skip to main content
Emerging ThreatsMalware & Ransomware

US Sentences Ryuk Ransomware Operator to 2 Years in Prison

Federal courthouse interior with defendant seated in courtroom.

“Like Vardanyan, many cybercriminals are not masterminds of a complex ransomware or extortion scheme but nonetheless play an integral part in the success of these crimes,” wrote U.S. attorneys in the District of Oregon — a line that frames a recent sentence in a Ryuk ransomware case now closed in federal court.

Karen Vardanyan: extradition, plea, and sentence

A 35-year-old Armenian national, Karen Vardanyan was sentenced to two years in prison after pleading guilty in July to computer fraud and conspiracy to commit fraud and extortion, the Justice Department said. Vardanyan had been extradited from Ukraine to the United States last year. The sentence — and an order for about $1.2 million in restitution to victims — conforms to terms of a plea agreement reached with prosecutors.

The scope of the Ryuk campaign and listed co-conspirators

Prosecutors say Vardanyan and his co-conspirators illegally accessed computer networks to deploy Ryuk ransomware on hundreds of compromised servers and workstations between March 2019 and September 2020. The indictment named Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, and Armenian national Levon Georgiyovych Avetisyan as co-conspirators in the campaign.

Victims, ransom payments, and restitution

Court records cited by prosecutors list multiple named and described victims. Among them were:

  • a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020;
  • a Watsonville, Oregon-based technology company attacked in December 2019; and
  • a Texas-based school breached in February 2020.

Justice Department officials said Vardanyan and his co-conspirators received about 1,160 bitcoins — valued at more than $15 million at the time — in ransom payments from victim companies. The court ordered Vardanyan to make approximately $1.2 million in restitution to victims as part of his sentence.

Ryuk’s reach and the prosecution’s posture

Ryuk ransomware was prevalent in 2019 and 2020, according to the Justice Department materials cited by prosecutors, infecting thousands of victims globally across the private sector, state and local municipalities, local school districts and critical infrastructure. Prosecutors specifically noted a wave of attacks on U.S. hospitals and listed victims that included Hollywood Presbyterian Medical Center, Universal Health Services, Electronic Warfare Associates, a North Carolina water utility and multiple U.S. news outlets.

In arguing for punishment that matches the plea agreement, U.S. attorneys emphasized that many participants in such schemes occupy roles that are critical to the success of complex operations even if they are not the architects. “Unfortunately, high rewards and a relatively low risk of detection are basic features of cybercrime. The only way to affect the cost-benefit analysis of these crimes is to impose meaningful sentences on those who are caught,” the memo added.

Legal aftermath: supervision, immigration, and enforcement claims

After serving his two-year sentence, Vardanyan will be subject to three years of supervised release. Prosecutors said they found no evidence Vardanyan was still engaged in criminal activity at the time of his arrest. The conviction also carries immigration consequences: Vardanyan faces removal from the United States after serving his sentence.

What this means for the Michigan company, Watsonville technology company, and Texas school

  • Michigan-based company that paid nearly $1.2 million: The restitution order addresses part of the monetary harm identified by prosecutors, but the records cited show ransom payments across multiple victims and do not indicate that all losses will be fully recovered.
  • Watsonville, Oregon-based technology company attacked in December 2019: The prosecution and naming of specific incidents in the court record provide a concrete example of how private-sector technology firms were targeted during the Ryuk campaign.
  • Texas-based school breached in February 2020: The case highlights how educational institutions were among the categories of victims hit during the 2019–2020 period.

This sentence closes one chapter in a multi-defendant prosecution that traces a concentrated period of Ryuk activity. The case record, the ordered restitution and the public tally of bitcoins received are discrete, documented measures of harm and of the government’s response; they leave unanswered how much of the total value of ransoms paid to the group will be recovered for victims and how prosecutions of co-conspirators will proceed.

Original story