Ryuk ransomware member sentenced to 24 months in prison
An Armenian individual was sentenced to 24 months in prison and 3 years of supervised release for involvement in Ryuk ransomware attacks targeting U.S. companies. The attacks occurred between March 2019 and June 2020, resulting in significant ransom payments. Ryuk ransomware was a ransomware-as-a-service operation active from 2018 to mid-2020, known for targeting sectors including healthcare. After Ryuk's shutdown, related cybercrime groups shifted to other ransomware operations. The sentenced individual specialized in initial network access and pleaded guilty following extradition from Ukraine.
AI Analysis
Technical Summary
Karen Serobovich Vardanyan, also known as "Maneeken" or "Karl Lagerfeld," was sentenced for his role in Ryuk ransomware attacks against multiple U.S. organizations from March 2019 to June 2020. He gained initial access to corporate networks and deployed ransomware on hundreds of servers and workstations. The group received approximately 1,610 bitcoins in ransom payments, valued at over $15 million at the time. Ryuk operated as a ransomware-as-a-service from August 2018 until mid-2020, targeting various sectors including healthcare during the COVID-19 pandemic. Following Ryuk's shutdown, the cybercrime gang behind it transitioned to Conti ransomware, which later disbanded in 2022.
Potential Impact
The Ryuk ransomware attacks led to unauthorized access and encryption of systems across multiple U.S. companies, resulting in ransom payments exceeding $15 million. Victims included a Michigan company that paid over $1.1 million in bitcoin, a school in Texas, and a technology company in Oregon. The attacks disrupted operations by encrypting hundreds of servers and workstations. The financial impact was significant, with the Ryuk group collecting more than $150 million in ransoms at its peak.
Mitigation Recommendations
This report concerns a criminal prosecution outcome rather than a software vulnerability or active exploit. No specific technical mitigation is applicable. Organizations should continue to follow best practices for ransomware defense, but no new remediation or patch is indicated by this information.
Ryuk ransomware member sentenced to 24 months in prison
Description
An Armenian individual was sentenced to 24 months in prison and 3 years of supervised release for involvement in Ryuk ransomware attacks targeting U.S. companies. The attacks occurred between March 2019 and June 2020, resulting in significant ransom payments. Ryuk ransomware was a ransomware-as-a-service operation active from 2018 to mid-2020, known for targeting sectors including healthcare. After Ryuk's shutdown, related cybercrime groups shifted to other ransomware operations. The sentenced individual specialized in initial network access and pleaded guilty following extradition from Ukraine.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Karen Serobovich Vardanyan, also known as "Maneeken" or "Karl Lagerfeld," was sentenced for his role in Ryuk ransomware attacks against multiple U.S. organizations from March 2019 to June 2020. He gained initial access to corporate networks and deployed ransomware on hundreds of servers and workstations. The group received approximately 1,610 bitcoins in ransom payments, valued at over $15 million at the time. Ryuk operated as a ransomware-as-a-service from August 2018 until mid-2020, targeting various sectors including healthcare during the COVID-19 pandemic. Following Ryuk's shutdown, the cybercrime gang behind it transitioned to Conti ransomware, which later disbanded in 2022.
Potential Impact
The Ryuk ransomware attacks led to unauthorized access and encryption of systems across multiple U.S. companies, resulting in ransom payments exceeding $15 million. Victims included a Michigan company that paid over $1.1 million in bitcoin, a school in Texas, and a technology company in Oregon. The attacks disrupted operations by encrypting hundreds of servers and workstations. The financial impact was significant, with the Ryuk group collecting more than $150 million in ransoms at its peak.
Defensive Guidance
This report concerns a criminal prosecution outcome rather than a software vulnerability or active exploit. No specific technical mitigation is applicable. Organizations should continue to follow best practices for ransomware defense, but no new remediation or patch is indicated by this information.
Technical Details
- Classification
- {"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/","fetched":true,"fetchedAt":"2026-09-23T08:32:47.782Z","wordCount":618}
Threat ID: 6ab38eaff7a7c5410682e5c1
Added to database: 09/23/2026, 08:32:47 UTC
Last enriched: 09/23/2026, 08:32:52 UTC
Last updated: 09/23/2026, 13:54:31 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.