A Key Player Behind the Devastating Ryuk Ransomware Operation Pleads Guilty in the US, Faces Up to 15 Years in Prison
Karen Serobovich Vardanyan, a 34-year-old Armenian man, has pleaded guilty to deploying the notorious Ryuk ransomware on multiple US companies’ systems between November 2019 and April 2020. This significant development marks a major breakthrough in the ongoing efforts to bring those responsible for the devastating attacks to justice.
The Ryuk ransomware operation was a highly organized and prolific threat actor that exploited vulnerabilities in corporate networks, encrypting sensitive data and extorting massive sums of money from its victims. At its peak, the gang is estimated to have hacked around 20 organizations every week, netting over $150 million in ransom payments. Many of its members are believed to have transitioned to other notorious groups, such as Conti, after Ryuk’s shutdown in 2020.
Vardanyan was extradited to the United States in April 2025 and is now facing charges for his role in deploying Ryuk on the networks of multiple US organizations. According to court documents, he helped deploy the ransomware on hundreds of compromised servers and workstations, resulting in significant financial losses for the affected companies. In one notable attack, a Michigan company was breached, with its attackers demanding 200 BTC (worth over $1.1 million at the time) in exchange for restoring access to their encrypted data.
The Ryuk operation’s impact extends far beyond the financial losses it inflicted on its victims. The gang’s activities are also believed to have exacerbated the challenges faced by healthcare providers during the COVID-19 pandemic, as many of these organizations were forced to divert resources away from patient care to deal with the aftermath of the attacks.
As part of his plea agreement, Vardanyan has agreed to pay over $1.1 million in restitution and is facing a maximum sentence of 15 years in prison for two separate charges. The guilty plea marks an important milestone in the ongoing efforts to hold those responsible for ransomware attacks accountable for their actions.
The case serves as a stark reminder that security teams must remain vigilant in protecting against evolving threats like Ryuk, which exploited vulnerabilities in corporate networks to wreak havoc on its victims. By understanding how these attacks work and staying one step ahead of attackers, organizations can mitigate the risk of being caught off guard by sophisticated threat actors.
In light of this case, it’s essential for security teams to review their incident response plans and ensure that they are adequately equipped to handle the consequences of a ransomware attack. Regular breach and attack simulation tests can help identify vulnerabilities in an organization’s defenses, allowing them to take proactive measures to prevent such attacks from occurring in the first place.
Source: Bleeping Computer — 2026-07-10