← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

Ryuk Ransomware Member Sentenced to 24 Months in Prison for Hacking US Companies

🔄 Updated 9h ago — new reporting from The Record
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Karen Serobovich Vardanyan sentenced to 24 months in prison.
  • Pled guilty to hacking US companies in Ryuk ransomware attacks.
  • Responsible for initial access to corporate networks.
  • Ryuk group collected over $15 million in Bitcoin ransoms.
  • Karen Vardanyan ordered to pay over $1.2 million in restitution.
  • Vardanyan was involved in over 2,400 ransomware attacks.
  • Vardanyan was extradited from Ukraine in July 2025.
  • Vardanyan is 35 years old.

Ransomware Member Sentenced

Karen Serobovich Vardanyan, 35, an Armenian national known online as "Maneeken" or "Karl Lagerfeld," was sentenced to 24 months in prison and three years of supervised release. The sentencing follows his guilty plea in July for his involvement in Ryuk ransomware attacks against U.S. companies. Vardanyan was extradited from Kyiv, Ukraine, after his arrest in April 2025.

Role in Ryuk Attacks

Court documents indicate that Vardanyan specialized in gaining initial access to corporate networks. He hacked into multiple U.S. organizations between March 2019 and June 2020. One attack involved a Michigan company that paid 200 BTC, valued at over $1.1 million at the time. Other targets included a school in Texas and a technology company in Oregon.

Ryuk Ransomware Operations

The U.S. Department of Justice stated that Vardanyan and his co-conspirators illegally accessed computer networks, deploying ransomware on hundreds of compromised servers and workstations. The group allegedly received approximately 1,610 bitcoins in ransom payments, valued at over $15 million at the time of payment. Ryuk was an active ransomware-as-a-service (RaaS) operation from August 2018 to mid-2020, known for targeting the healthcare sector during the COVID-19 pandemic and collecting over $150 million in ransoms.

Evolution of Cybercrime Groups

After Ryuk's shutdown in 2020, the Wizard Spider cybercrime gang, which was behind Ryuk, transitioned to Conti ransomware. Conti became a prolific hacker group but disbanded in 2022 following leaks of its internal chats and source code. Its members subsequently splintered into smaller units, joining existing ransomware gangs or forming new operations.

Updates

🕒 2026-09-23 · new reporting from The Record
  • Karen Vardanyan ordered to pay over $1.2 million in restitution.
  • Vardanyan was involved in over 2,400 ransomware attacks.
  • Vardanyan was extradited from Ukraine in July 2025.
  • Vardanyan is 35 years old.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Karen Vardanyan, an Armenian national and Ryuk ransomware operator, received a two-year U.S. federal prison sentence and was ordered to pay over $1.2 million in restitution after pleading guilty to conspiracy and fraud. Vardanyan was involved in over 2,400 ransomware attacks that disrupted various entities globally, including state and local municipalities.

Karen Serobovich Vardanyan, a member of the Ryuk ransomware group, received a 24-month prison sentence for hacking US companies and deploying ransomware. Vardanyan specialized in gaining initial access to corporate networks, contributing to attacks that extorted over $15 million in Bitcoin from victims.