Yahoo Armenian National Sentenced for Ryuk Ransomware Scheme
Article Content
- •Karen Vardanyan sentenced to 2 years for Ryuk ransomware attacks.
- •Victims included U.S. companies, with over $1.2 million in restitution ordered.
- •Ransomware payments were made using cryptocurrency.
Karen Vardanyan, a 35-year-old Armenian citizen extradited from Ukraine, was sentenced to two years in federal prison for his involvement in a Ryuk ransomware scheme that targeted U.S. companies, including one in Oregon. He was ordered to pay $1,219,106 in restitution and will serve three years of supervised release. The ransomware attacks occurred from March 2019 to June 2020, affecting various organizations worldwide. Vardanyan pleaded guilty to conspiracy and computer fraud charges, having used the aliases Maneeken and Karl Lagerfeld. The FBI investigated the case, and the U.S. Attorney's Office announced the sentencing. Payments in the scheme were made using cryptocurrency, primarily Bitcoin. This case highlights ongoing issues related to ransomware and international cybercrime.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ryuk in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…
Education Sector Faces Surge in Cyberattacks Amid Open Network Vulnerabilities SonicWall's 2026 Education Protect Brief reveals that educational institutions are experiencing the highest per-device cyberattack intensity of any tracked sector, with 81,879 intrusion prevention system (IPS) hits per device in the first half of 2026. The report highlights that SIPVicious VoIP exploitation accounted…