Ryuk Conspirator Karen Vardanyan Gets Two Years in Oregon Federal Court
The U.S. Attorney's Office for the District of Oregon announced that Karen Vardanyan, 35, was sentenced to 24 months in federal prison and 3 years' supervised release, and that he was also ordered to pay $1,219,106.00 in restitution to the victims in the case. BleepingComputer first reported the sentencing to a wider tech audience. The Justice Department describes him as an Armenian citizen, extradited from Ukraine to the United States, sentenced for his role in RYUK ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including in Oregon.
According to the DOJ, Vardanyan went online as Maneeken or Karl Lagerfeld and was a member of a conspiracy that deployed Ryuk ransomware on victim computer networks to extort over $1 million from several victims. BleepingComputer says he specialized in getting initial access to corporate networks. Put simply, his job was to get the attackers inside. At the plea stage, BleepingComputer described him as arrested in Kyiv in April 2025 for providing initial access to corporate networks. The Justice Department's sentencing release doesn't spell out his role in those terms.
The restitution figure is the most precise number in the case. It's a separate figure from the ransom totals, and the two are easy to mix up. In July the DOJ said only that as part of the plea agreement, Vardanyan has agreed to pay over $1.1 million in restitution. The final order of $1,219,106 is consistent with that rounded figure.
What Ryuk Actually Did to Windows Servers and Workstations
The court record describes a standard extortion intrusion. The July plea announcement says Vardanyan illegally accessed computer networks of victim companies to deploy Ryuk ransomware on compromised servers and workstations. The DOJ describes Ryuk as designed to encrypt data on a victim's computer or network and prevents the victim from accessing the encrypted files until a ransom is paid, with ransom payments were extorted from victim companies in exchange for decryption keys to regain access to their data.
The scale was large. The DOJ said in July that the conspirators "illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations". Several outlets reported the government's allegation that the group collected around 1,610 Bitcoin, valued at more than $15 million when the ransoms were paid. CyberScoop printed the figure as roughly 1,160 bitcoins. That looks like a transposition, because the DOJ-derived reporting in Infosecurity Magazine, Security Affairs and BleepingComputer all gives 1,610.
Prosecutors named three victims. Among the victims were a Michigan company that paid 200 Bitcoin (worth over $1.1 million at the time), a company in Oregon, and a school in Texas. The Oregon victim was a technology company in Wilsonville, and the source packet dates the Texas school attack to February 2020. The sentencing release goes wider, saying Vardanyan helped deploy the Ryuk ransomware against companies, schools, and other entities throughout the world.
The public record does not identify how Vardanyan got in: no vulnerability, no stolen-credential method, no misconfiguration. Any claim that a specific control would have stopped these attacks goes beyond what the court has disclosed.
The Dates in the Vardanyan Case Don't Line Up
The government's descriptions of when this happened differ, and anyone reading the case file should know that. The sentencing announcement says Vardanyan participated in the conspiracy from March 2019 to approximately June 2020. The July plea release is narrower: between November 2019 through April 2020. A July 2025 DOJ release put the alleged activity between March 2019 and September 2020.
The releases don't explain why the windows differ. The most likely reading, and it is only an inference, is that the narrow window covers the conduct he admitted in his plea. The wider windows would then describe the whole conspiracy he joined, or the original charges. CyberScoop's plea-stage reporting fits that reading: it said he admitted to participating in cybercrime from November 2019 to April 2020 when he and his co-conspirators deployed Ryuk ransomware against three U.S.-based organizations.
The charges changed as well. On February 22, 2024, a federal grand jury in Portland returned a superseding indictment charging Vardanyan with conspiracy, fraud in connection with computers, and extortion in connection with computers. He was convicted on fewer counts than that. On July 8, 2026, Vardanyan pleaded guilty to conspiracy and fraud in connection with computers. The extortion count is not among the charges he pleaded guilty to.
| Date | Event |
|---|---|
| March 2019 – ~June 2020 | Period of conspiracy participation, per the sentencing release |
| November 2019 – April 2020 | Period described in the July 2026 plea release |
| February 22, 2024 | Superseding indictment returned in Portland |
| April 2025 | Arrest in Kyiv, per BleepingComputer |
| June 20, 2025 | Initial U.S. court appearance after extradition |
| July 8, 2026 | Guilty plea to conspiracy and computer fraud |
| September 22, 2026 | Sentenced: 24 months, 3 years' supervision, $1,219,106 restitution |
Why the Sentence Came In Far Below the 15-Year Maximum
When he pleaded guilty, the potential penalty sounded severe. The DOJ said Vardanyan faces a maximum sentence of five years in prison, a $250,000 fine, and three years of supervised release for conspiracy. It added that he faces a maximum sentence of 10 years in prison, a $250,000 fine, and three years of supervised release for computer fraud. Coverage in July added those together as a 15-year exposure.
Those numbers were statutory ceilings, not predictions. The court imposed 24 months. The sentencing release doesn't say whether time already served counts toward it. It does note that after his initial appearance he was detained by the magistrate judge, which means he has been in custody since June 2025. The release gives no reasons for the length of the sentence, and it doesn't say whether he cooperated with prosecutors.
Deportation is also likely. According to CyberScoop, Vardanyan, as part of his guilty plea, also acknowledged that his conviction will have immigration consequences resulting in removal from the United States after serving his sentence.
Extradition From Ukraine Made the Ryuk Prosecution Possible
Without international cooperation this case would not have reached a courtroom. The Justice Department credits Ukrainian authorities and its own Office of International Affairs with the arrest and extradition. Bitdefender's plea-stage writeup says the investigation involved the FBI alongside Europol, authorities in Ukraine and France, and other international partners. Most ransomware operators live in countries that won't extradite them, so each case that ends in a U.S. sentence depends on a suspect being within reach of a cooperating government.
The case was part of a wider indictment. The July 2025 DOJ release named three other alleged co-conspirators. One, Armenian national Levon Georgiyovych Avetisyan, was then the subject of a U.S. extradition request in France. The other two, Ukrainian nationals Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko, were not in custody at the time. The September sentencing announcement gives no update on any of them.
Ryuk's Legacy Runs Through Conti and Its Splinter Groups
Ryuk hasn't been active for years, but people who worked with it may still be. BleepingComputer describes Ryuk as a ransomware-as-a-service operation active from August 2018 to mid-2020 that became known for a wave of attacks on healthcare during the COVID-19 pandemic. It reports that at its peak, the Ryuk ransomware gang hacked around 20 organizations every week and made more than $150 million. Infosecurity Magazine separately references a $150 million estimate for Ryuk's earnings and calls it one of the most prolific ransomware groups around when it operated from 2018 to 2020.
BleepingComputer also traces what happened next. The Wizard Spider gang behind Ryuk moved to Conti ransomware after 2020. Conti disbanded in 2022 after its internal chats and source code were leaked, with its members splintering into numerous cybercrime groups, some of which remain active today. Bitdefender makes a similar point: although Ryuk has largely disappeared from today's ransomware landscape, its influence is still felt. Treat the Conti lineage as security-industry reporting. It is not part of the court record in this case.
What this means for you
This sentencing doesn't call for any patch, configuration change or urgent task. It's useful mainly as context for risk planning and incident response. The details that matter to IT staff come from the court record. The attackers got into networks, encrypted hundreds of servers and workstations, and demanded Bitcoin for decryption keys. One victim paid about $1.1 million. The restitution eventually ordered covers roughly that amount, and it arrived more than six years later.
- Ryuk member Karen Vardanyan received 24 months in federal prison, three years of supervised release and a $1,219,106 restitution order on September 22, 2026.
- The plea-stage 15-year figure was a statutory maximum. The actual sentence was far shorter, which is worth remembering when you read about future guilty pleas.
- The government has given three different activity windows (March 2019–June 2020, November 2019–April 2020, March 2019–September 2020), and none of the releases explains the difference.
- Court documents describe servers and workstations encrypted after unauthorized network access, but they don't disclose the entry method, so no specific defensive lesson follows from this case alone.
- Restitution after a conviction is slow and partial. The groupwide ransom total alleged by prosecutors, about $15 million, is more than ten times the restitution ordered here.
- Three other named co-conspirators appeared in the 2025 charging announcement, and the sentencing release gives no update on their status.
Vardanyan's two-year sentence closes one of the few Ryuk prosecutions to reach a U.S. judgment. It depended on an arrest in Kyiv and an extradition that most ransomware suspects never face. For the Michigan company that paid 200 bitcoin in 2020, the result is a court-ordered payback of about $1.2 million, spread across victims. For the rest of the industry, the people who learned their trade under Ryuk and Conti are still in business, and the next case like this, if there is one, may again take half a decade to reach sentencing.