A member of the Ryuk ransomware operation has been sentenced to two years in a US federal prison for participating in cyberattacks that encrypted corporate networks and extracted more than $1 million from victims.
Karen Vardanyan, a 35-year-old Armenian citizen, received a 24-month prison sentence followed by three years of supervised release. A federal judge also ordered him to pay $1,219,106 in restitution to victims affected by the ransomware operation.
Vardanyan, who used the online aliases “Maneeken” and “Karl Lagerfeld,” participated in the Ryuk conspiracy from March 2019 until approximately June 2020. Prosecutors said the operation targeted companies, schools, and other organizations around the world, including victims in the United States.
The group gained unauthorized access to corporate networks before deploying Ryuk ransomware across compromised servers and workstations. The malware encrypted files and prevented organizations from using affected systems, while ransom notes instructed victims to make cryptocurrency payments, typically in Bitcoin, to obtain decryption keys.
Court records previously detailed several attacks linked to Vardanyan and his co-conspirators. One Michigan company paid 200 Bitcoin, worth more than $1.1 million at the time, to regain access to its network. The attackers also targeted a company in Wilsonville, Oregon, and compromised a school in Texas in February 2020.
Vardanyan’s case followed an international effort to identify and prosecute people involved in the ransomware operation. A federal grand jury in Portland returned a superseding indictment against him in February 2024, charging him with conspiracy, computer fraud, and computer-related extortion.
Ukrainian authorities later arrested Vardanyan before extraditing him to the United States. He made his first appearance in federal court in June 2025 and remained in custody while the criminal case proceeded.
In July 2026, Vardanyan pleaded guilty to conspiracy and fraud in connection with computers. His sentence was handed down in Oregon on September 22 following an investigation by the FBI, with Ukrainian authorities assisting US officials in securing his arrest and extradition.
Ryuk emerged in 2018 and became known for targeting larger organizations capable of paying substantial ransoms. The ransomware was used in attacks against businesses, healthcare organizations, schools, and other institutions, often causing significant disruption by encrypting large numbers of systems.
Vardanyan’s prosecution focused on his participation in attacks between 2019 and 2020 rather than the full history of Ryuk activity worldwide. His 24-month prison term will be followed by three years of supervised release, while the restitution order requires him to pay more than $1.2 million to victims covered by the case.