Download Privacy Needle App

Type to search

Cybersecurity

Armenian Actor Sentenced to Prison for Ryuk Ransomware Attacks

Share

An Armenian national has been sentenced to 24 months in prison and three years of supervised release for his role in a series of Ryuk ransomware attacks targeting organisations in the United States.

Karen Serobovich Vardanyan, 35, specialised in gaining initial access to corporate networks. Vardanyan, who also operated under the aliases “Maneeken” and “Karl Lagerfeld”, pleaded guilty in July following his extradition from Kyiv, Ukraine, after being arrested in April 2025.

Court documents reveal that Vardanyan breached the networks of multiple US entities between March 2019 and approximately June 2020. In one instance, Vardanyan and his accomplices targeted a Michigan company that paid 200 Bitcoin (BTC) in ransom, valued at more than $1.1 million at the time.

The criminal activity also included breaches of a school in Texas and a technology firm based in Wilsonville, Oregon.

Scale of the Ryuk Criminal Operation

The United States Department of Justice stated that Vardanyan and his co-conspirators deployed ransomware on hundreds of compromised servers and workstations. The group is alleged to have received approximately 1,610 bitcoins in ransom payments, a sum valued at over $15 million at the time of the transactions.

Ryuk was a notorious ransomware-as-a-service (RaaS) operation active between August 2018 and mid-2020. The group became particularly well-known for launching massive waves of attacks against the healthcare sector during the COVID-19 pandemic. At its peak, the group was estimated to target around 20 victims every week, collecting more than $150 million in total ransoms.

Following the shutdown of Ryuk in 2020, the Wizard Spider cybercrime gang associated with the malware transitioned to Conti ransomware. Conti remained a prolific threat until its disbandment in 2022, following the leak of its internal source code and communications.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.