{"id":257539,"date":"2026-09-24T12:26:31","date_gmt":"2026-09-24T09:26:31","guid":{"rendered":"https:\/\/digitrendz.blog\/z\/?p=257539"},"modified":"2026-09-24T12:26:31","modified_gmt":"2026-09-24T09:26:31","slug":"ryuk-ransomware-member-sentenced-to-24-months-in-prison","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/tech-news\/257539\/ryuk-ransomware-member-sentenced-to-24-months-in-prison\/","title":{"rendered":"Ryuk Ransomware Member Sentenced to 24 Months in Prison"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\" open=\"\"><summary>\u25bc Summary<\/summary><p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Karen Serobovich Vardanyan was sentenced to 24 months in prison for hacking U.S. companies using Ryuk ransomware between 2019 and 2020.<br>&#8211; Vardanyan, who specialized in gaining initial network access, pleaded guilty after being extradited from Ukraine following his arrest in April 2025.<br>&#8211; The cybercriminals targeted multiple organizations including a Michigan company, a Texas school, and an Oregon technology firm, collecting over $15 million in ransoms.<br>&#8211; Ryuk operated as a ransomware-as-a-service model that peaked during the pandemic before shutting down in mid-2020.<br>&#8211; After Ryuk&#8217;s dissolution, the Wizard Spider gang switched to Conti ransomware until it disbanded in 2022 due to a data leak.<br><\/p><\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">K<\/mark>aren Serobovich Vardanyan<\/strong>, a 35-year-old national of Armenia, has been sentenced to <strong>24 months in prison<\/strong> followed by three years of supervised release. The penalty stems from his role as an initial access broker for the notorious <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/ryuk-ransomware\/\" class=\"acp-entity-link\" data-entity-id=\"301036\" data-entity-category=\"product\" title=\"Learn more about Ryuk ransomware\" target=\"_blank\" rel=\"noopener noreferrer\">Ryuk ransomware<\/a><\/strong> group, which targeted United States corporations by encrypting their critical data and demanding payment. Vardanyan, who operated under the online aliases &#8220;<strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/maneeken\/\" class=\"acp-entity-link\" data-entity-id=\"301035\" data-entity-category=\"Person\" title=\"Learn more about Maneeken\" target=\"_blank\" rel=\"noopener noreferrer\">Maneeken<\/a><\/strong>&#8221; and &#8220;<strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/karl-lagerfeld\/\" class=\"acp-entity-link\" data-entity-id=\"267167\" data-entity-category=\"Person\" title=\"Learn more about Karl Lagerfeld\" target=\"_blank\" rel=\"noopener noreferrer\">Karl Lagerfeld<\/a><\/strong>,&#8221; pleaded guilty in July after being extradited from <a href=\"https:\/\/digitrendz.blog\/z\/entity\/kyiv\/\" class=\"acp-entity-link\" data-entity-id=\"35345\" data-entity-category=\"Location\" title=\"Learn more about Kyiv\" target=\"_blank\" rel=\"noopener noreferrer\">Kyiv<\/a>, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/ukraine\/\" class=\"acp-entity-link\" data-entity-id=\"2429\" data-entity-category=\"Location\" title=\"Learn more about Ukraine\" target=\"_blank\" rel=\"noopener noreferrer\">Ukraine<\/a>, where he had been arrested in April 2025.<\/p>\n\n<p class=\"wp-block-paragraph\">Court records indicate that between March 2019 and June 2020, Vardanyan facilitated unauthorized entry into the networks of several U. S. entities. In one significant incident, he and his accomplices breached a <a href=\"https:\/\/digitrendz.blog\/z\/entity\/michigan\/\" class=\"acp-entity-link\" data-entity-id=\"12922\" data-entity-category=\"Location\" title=\"Learn more about Michigan\" target=\"_blank\" rel=\"noopener noreferrer\">Michigan<\/a>-based firm, resulting in a ransom payment of <strong>200 BTC<\/strong>, valued at more than $1.1 million at the time. Prosecutors also identified victims including a school district in <a href=\"https:\/\/digitrendz.blog\/z\/entity\/texas\/\" class=\"acp-entity-link\" data-entity-id=\"3107\" data-entity-category=\"Location\" title=\"Learn more about Texas\" target=\"_blank\" rel=\"noopener noreferrer\">Texas<\/a> and a technology firm located in <a href=\"https:\/\/digitrendz.blog\/z\/entity\/wilsonville\/\" class=\"acp-entity-link\" data-entity-id=\"276393\" data-entity-category=\"Location\" title=\"Learn more about Wilsonville\" target=\"_blank\" rel=\"noopener noreferrer\">Wilsonville<\/a>, <a href=\"https:\/\/digitrendz.blog\/z\/entity\/oregon\/\" class=\"acp-entity-link\" data-entity-id=\"17174\" data-entity-category=\"Location\" title=\"Learn more about Oregon\" target=\"_blank\" rel=\"noopener noreferrer\">Oregon<\/a>. The scale of the financial impact was substantial. As stated by the <strong>U. S. Department of Justice<\/strong> in July:<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;Vardanyan and his co-conspirators illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations.&#8221;<\/p>\n\n<p class=\"wp-block-paragraph\">The department further noted the immense value extracted from these operations:<\/p>\n\n<p class=\"wp-block-paragraph\">&#8220;Vardanyan and his co-conspirators are alleged to have received approximately 1,610 bitcoins in ransom payments from the victim companies, which was valued at over $15 million at the time of payment.&#8221;<\/p>\n\n<h2 class=\"wp-block-heading\">The Rise and Fall of Ryuk<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/ryuk\/\" class=\"acp-entity-link\" data-entity-id=\"205075\" data-entity-category=\"Organization\" title=\"Learn more about Ryuk\" target=\"_blank\" rel=\"noopener noreferrer\">Ryuk<\/a><\/strong> operated as a <strong>ransomware-as-a-service (RaaS)<\/strong> platform from August 2018 until its dissolution in mid-2020. It gained infamy for launching large-scale attacks against the healthcare sector during the <strong>COVID-19 pandemic<\/strong>. At the height of its activity, the group compromised roughly 20 victims weekly, accumulating over $150 million in ransoms. The operation relied heavily on specialized actors like Vardanyan to gain initial footholds in corporate environments before other members deployed the encryption tools.<\/p>\n\n<p class=\"wp-block-paragraph\">After the Ryuk infrastructure was dismantled in 2020, the underlying criminal organization, known as <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/wizard-spider\/\" class=\"acp-entity-link\" data-entity-id=\"231512\" data-entity-category=\"Organization\" title=\"Learn more about Wizard Spider\" target=\"_blank\" rel=\"noopener noreferrer\">Wizard Spider<\/a><\/strong>, transitioned to developing and distributing <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/conti-ransomware\/\" class=\"acp-entity-link\" data-entity-id=\"301037\" data-entity-category=\"product\" title=\"Learn more about Conti ransomware\" target=\"_blank\" rel=\"noopener noreferrer\">Conti ransomware<\/a><\/strong>. This new iteration quickly established itself as one of the most active and damaging hacker groups in existence. However, Conti\u2019s reign ended abruptly in May 2022 when its internal communication logs and source code were leaked publicly. This breach forced the group to disband, with various splinter cells either joining existing ransomware syndicates or initiating independent criminal enterprises.<\/p>\n\n<em>(Source: <a href='https:\/\/bleepingcomputer.com\/news\/security\/ryuk-ransomware-member-sentenced-to-24-months-in-prison\/' target='_blank'>BleepingComputer<\/a>)<\/em>","protected":false},"excerpt":{"rendered":"<p>Karen Serobovich Vardanyan was sentenced to 24 months in prison for acting as an initial access broker for the Ryuk ransomware group, which targeted U.S. corporations by encrypting their data and demanding payment. Prosecutors revealed that Vardanyan and his co-conspirators extracted approximatel&#8230;<\/p>\n","protected":false},"author":1,"featured_media":257538,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[57,3297,3327,3254],"tags":[258041,255533,254027,258040,251177],"entities":[143457,44983,258043,232509,223084,25361,258044,7576,10920,161970,258042,2818,6077,2697,3672,232510,185749],"class_list":["post-257539","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-tech-news","category-cybersecurity","category-newswire","category-technology","tag-conti","tag-kyiv","tag-oregon","tag-ryuk","tag-texas","entity-armenian","entity-conti","entity-conti-ransomware","entity-karen-serobovich-vardanyan","entity-karl-lagerfeld","entity-kyiv","entity-maneeken","entity-michigan","entity-oregon","entity-ryuk","entity-ryuk-ransomware","entity-texas","entity-u-s-department-of-justice","entity-ukraine","entity-us","entity-wilsonville","entity-wizard-spider"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257539","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=257539"}],"version-history":[{"count":2,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257539\/revisions"}],"predecessor-version":[{"id":257561,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/257539\/revisions\/257561"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/257538"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=257539"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=257539"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=257539"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=257539"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}