Bleepingcomputer Ryuk Ransomware Operator Pleads Guilty to $15M Extortion Scheme
Article Content
- •Vardanyan pleaded guilty to charges related to a ransomware scheme that extorted over $15 million.
- •The Ryuk ransomware operation targeted U.S. businesses from late 2019 to early 2020.
- •Vardanyan faces a maximum sentence of 15 years and has agreed to pay significant restitution.
Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty on July 8, 2026, to conspiracy and computer fraud related to his role in a Ryuk ransomware campaign that extorted over $15 million from U.S. businesses between November 2019 and April 2020. Vardanyan, extradited from Ukraine, admitted to illegally accessing corporate networks and deploying Ryuk ransomware, which encrypted victims' files and demanded ransom payments in Bitcoin. The operation targeted multiple organizations, including a Michigan company that paid 200 Bitcoin (approximately $1.1 million at the time) to regain access to its data. Vardanyan faces a maximum sentence of 15 years in prison and has agreed to pay over $1.1 million in restitution. His sentencing is scheduled for September 22, 2026. The investigation involved the FBI and international law enforcement agencies, highlighting the ongoing threat of ransomware despite the dismantling of the Ryuk group.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Common questions
What companies were affected?
What is the current status of Vardanyan?
What restitution has Vardanyan agreed to pay?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…