Skip to content
Extradited Armenian National Sentenced Over Ryuk Ransomware Scheme

Extradited Armenian National Sentenced Over Ryuk Ransomware Scheme

Technadu September 23, 2026

Prison sentence: Karen Vardanyan received 24 months in federal prison and three years' supervised release for Ryuk ransomware attacks.

Restitution ordered: The court directed him to pay over $1.2 million to victims of the scheme.

Extradition route: Vardanyan, an Armenian citizen, was extradited from Ukraine to face charges in the United States.

An Armenian national extradited from Ukraine has been sentenced to 24 months in federal prison for his role in Ryuk ransomware attacks and an extortion conspiracy that hit companies across the United States, including in Oregon. Karen Vardanyan, 35, was also ordered to pay $1,219,106.00 in restitution to his victims.

Vardanyan Sentenced in Portland Federal Court

U.S. Attorney Scott E. Bradford for the District of Oregon announced the sentence on September 22, 2026. Court documents show the individual sometimes went by the monikers "Maneeken" or "Karl Lagerfeld" while taking part in the scheme.

Ryuk Ransomware Conspiracy Extorted Victims Worldwide

Vardanyan was a member of a conspiracy that deployed Ryuk ransomware against victims' computer networks, extorting more than $1 million from several of them.

Vardanyan took part in the conspiracy from March 2019 to roughly June 2020, targeting companies, schools, and other organizations worldwide. Victim companies included the French IT services firm Sopra Steria, Universal Health Services (UHS), Oregon’s Sky Lakes Medical Center, and New York’s Lawrence Health System.

In the CrowdStrike 2020 Global Threat Report, Ryuk accounts for three of the top 10 largest ransom demands of the year: $5.3 million, $9.9 million, and $12.5 million, targeting large companies – called by hackers “big game hunting” (BGH).

From Indictment to Guilty Plea

A federal grand jury in Portland returned a superseding indictment against Vardanyan on February 22, 2024, charging him with conspiracy, fraud in connection with computers, and extortion in connection with computers.

He made his initial appearance after extradition from Ukraine on June 20, 2025, and the magistrate judge detained him at that time. Vardanyan pleaded guilty to conspiracy and fraud in connection with computers on July 8, 2026.

A variant of the older Hermes ransomware, Ryuk is one of the most dangerous ransomware attacks, which was attributed to the Russian hacker group WIZARD SPIDER – also associated with Trickbot (sometimes using Emotet ), DEV-0193, UNC2053, or Periwinkle Tempest.

A 2021 Microsoft report observed Ryuk operators distributing ransomware through Group Policy, SYSVOL startup items, and PsExec, and Kaspersky recently outlined that a threat actor leveraged PAYLOAD ransomware to obtain domain admin-equivalent control of Active Directory and turned Group Policy itself into the attack's delivery mechanism.

In March, a suspected Armenian was extradited for operating a RedLine malware scheme following a co-conspirator arrest.