On September 22, 2026, the United States Department of Justice announced that a federal court in the District of Oregon had sentenced Karen Vardanyan, a 35 year old Armenian national, to 24 months in federal prison, three years of supervised release, and $1,219,106 in restitution for his role in Ryuk ransomware attacks carried out between 2019 and 2020. The sentence closes a case that began with his arrest in Ukraine and extradition to the United States, and it places a rare, specific price tag on a ransomware operation that prosecutors say harvested millions from victims around the world.
Ryuk first appeared in August 2018, according to The Record, and it quickly became one of the most disruptive ransomware families of its era. The malware infected thousands of victims globally across the private sector, state and local municipalities, local school districts, and critical infrastructure, according to CyberScoop. Hospitals were especially vulnerable. At the height of the COVID-19 pandemic in 2020, the FBI and several other US agencies warned that Ryuk actors were heavily targeting hospitals across the country, and Universal Health Services, a major hospital chain, was hit with a Ryuk attack that ultimately cost the company $67 million.
Prosecutors described Vardanyan as a core member of the Ryuk ransomware gang. They said he and his co-conspirators launched more than 2,400 ransomware attacks on victims around the world, including state and local municipalities, and that these attacks severely disrupted the entities' abilities to function by restricting access to data and impacting communications. The Justice Department said Vardanyan and his team received at least $15 million in ransoms over the years, a figure that prosecutors tied to about 1,160 bitcoins valued at more than $15 million at the time.
Vardanyan's path through the US legal system was not simple. He was charged by a grand jury in the United States in February 2024 with conspiracy, fraud, and extortion in connection with computers. He was arrested in Ukraine in April 2025, extradited to the United States in June 2025, and pleaded guilty in July 2026 to conspiracy and computer fraud. SecurityWeek reported on September 24 that Vardanyan had been in custody since his extradition, so under federal law, the time he spent in pretrial detention is credited toward his 24 month prison term, meaning he has already served a substantial portion of the sentence.
Key Facts
CyberScoop reported on September 23 that Vardanyan, 35, was sentenced to two years in prison and about $1.2 million in restitution for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020. The Justice Department said Tuesday that the sentence matched the terms of a plea agreement. The exact restitution figure, according to The Record, is $1,219,106, and Vardanyan will also serve three years of supervised release.
The Record reported on September 23 that prosecutors accused Vardanyan of being a core member of the Ryuk ransomware gang. In court documents, prosecutors said he and his co-conspirators launched over 2,400 ransomware attacks on victims around the world, including state and local municipalities. The attacks severely disrupted these entities' abilities to function by restricting access to data and impacting communications. The same outlet reported that Vardanyan personally launched several ransomware attacks and extorted more than $1 million from victims before he was placed on an international wanted list by the FBI.
SecurityWeek reported on September 24 that Vardanyan was charged by a grand jury in the United States in February 2024 with conspiracy, fraud, and extortion in connection with computers. He was arrested in Ukraine in April 2025, extradited to the United States in June 2025, and pleaded guilty to conspiracy and computer fraud in July 2026. SecurityWeek also reported that Vardanyan was involved in Ryuk ransomware attacks between March 2019 and June 2020, while CyberScoop reported that prosecutors accused him and his co-conspirators of deploying Ryuk on hundreds of compromised servers and workstations between March 2019 and September 2020.
Victims named in court records include a Michigan based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon based technology company attacked in December 2019, and a Texas based school breached in February 2020, according to CyberScoop. The Justice Department said Vardanyan and his co-conspirators received about 1,160 bitcoins, valued at more than $15 million at the time, in ransom payments from victim companies. The Record reported on September 23 that Universal Health Services was hit with a Ryuk attack that ultimately cost the company $67 million.
Vardanyan's co-conspirators were identified in court documents as Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, and Armenian national Levon Georgiyovych Avetisyan, according to CyberScoop. The Record reported that Lyulyava and Prykhodchenko are both 53 years old, and that several other members of the group have been identified and arrested over the last three years. Prosecutors said they found no evidence that Vardanyan was still engaged in criminal activity at the time of his arrest, CyberScoop reported. His conviction will have immigration consequences resulting in removal from the United States after he serves his sentence.
Analysis
The sentence is notable less for its length than for its specifics. Vardanyan received 24 months, three years of supervised release, and $1,219,106 in restitution. The Record reported that the Ryuk group as a whole took in at least $15 million, and CyberScoop reported that the gang received about 1,160 bitcoins valued at more than $15 million at the time. The restitution order therefore covers a fraction of the group's total haul, and it is attached to one member rather than the enterprise. What this really means is that US prosecutors are using restitution as a targeted tool: they can impose a concrete, victim specific debt on an individual even when the broader criminal network remains partially beyond reach.
SecurityWeek reported that, based on the DOJ's description, Vardanyan was likely a ransomware affiliate or initial access provider rather than part of the team that developed the malware and operated the infrastructure supporting Ryuk attacks. That distinction matters. Affiliates and access brokers are often the most exposed participants because they interact with victims, handle ransom negotiations, or leave traces that investigators can follow. The developers and infrastructure operators may be more insulated. The 24 month sentence reflects a plea agreement and a cooperation posture, but it also reflects the difficulty of proving the full scope of a distributed ransomware operation in a single courtroom.
The bigger picture here is that ransomware sentencing is becoming a spectrum. SecurityWeek reported on September 24 that a Ukrainian Conti ransomware developer received a 4 year prison sentence in the United States, and that a Ukrainian accused of creating the Lockergoga, MegaCortex, and Nefilim ransomware families has been sentenced to 13 years in prison by a Swiss court. Against those outcomes, Vardanyan's 24 months looks lenient. Yet the comparison is not apples to apples. Vardanyan pleaded guilty, was credited for pretrial detention, and was described by prosecutors as no longer engaged in criminal activity at the time of his arrest. He also faced immigration consequences that will result in removal from the United States after his sentence. Those factors can reduce a sentence even when the underlying losses are enormous.
The $67 million cost to Universal Health Services, reported by The Record, illustrates the asymmetry at the heart of ransomware enforcement. A single hospital chain can absorb tens of millions of dollars in disruption, while a core operator may be ordered to pay just over $1.2 million. Restitution is not designed to make whole every victim of a sprawling criminal conspiracy, and it rarely does. It is designed to assign responsibility and to create a financial consequence for a defendant. The Vardanyan case shows both the reach and the limits of that approach: the Justice Department can name a figure down to the dollar, but it cannot recover the full social cost of the attacks.
Why It Matters
CyberScoop reported on September 23 that Ryuk infected thousands of victims globally across the private sector, state and local municipalities, local school districts, and critical infrastructure, including a wave of attacks on US hospitals such as Universal Health Services. When hospitals lose access to data and communications, the consequences can be measured in patient care, not just in dollars. The Record reported that at the height of the COVID-19 pandemic in 2020, the FBI and several other US agencies warned that Ryuk actors were heavily targeting hospitals across the country. That warning turned out to be prescient.
The case also matters because it shows international cooperation in action. Vardanyan was arrested in Ukraine, extradited to the United States, and prosecuted in the District of Oregon. The FBI placed him on an international wanted list, according to The Record. The Justice Department's announcement on September 22, 2026, followed years of investigation across multiple countries and involved co-conspirators from Ukraine and Armenia. Even so, the co-conspirators named in court documents, Oleg Nikolayevich Lyulyava, Andrii Leonydovich Prykhodchenko, and Levon Georgiyovych Avetisyan, illustrate how many participants a single ransomware operation can involve.
For defenders, the numbers are a reminder of the scale. More than 2,400 attacks, at least $15 million in ransoms, about 1,160 bitcoins, and a $67 million loss for one hospital chain. Those figures describe an ecosystem, not an isolated incident. The sentencing of one operator does not dismantle that ecosystem, but it does impose a cost and a public record. It also puts other participants on notice that US authorities are willing to pursue extradition and restitution, even when the defendant is not the malware's original author.
Next Up
Vardanyan will serve his 24 month sentence, followed by three years of supervised release, and then face removal from the United States as a result of his conviction, according to CyberScoop. Because he has been in custody since his extradition, he has already served a substantial portion of the prison term, SecurityWeek reported. The remaining question is whether prosecutors will pursue the other named co-conspirators with the same intensity. The Record reported that several members of the group have been identified and arrested over the last three years, including Avetisyan, Lyulyava, and Prykhodchenko. Their cases, and any future extraditions, will test whether the Ryuk network can be unwound one defendant at a time.
More broadly, the Justice Department's announcement arrives amid a steady stream of ransomware sentencings. SecurityWeek reported on September 24 that a Ukrainian Conti ransomware developer received a 4 year prison sentence in the United States, and that a Ukrainian accused of creating the Lockergoga, MegaCortex, and Nefilim ransomware families has been sentenced to 13 years in prison by a Swiss court. Those cases, along with Vardanyan's, suggest that courts are still searching for a consistent scale of punishment for ransomware crimes. The next sentencings will show whether 24 months becomes an outlier or a benchmark.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.