Skip to main content

Ryuk ransomware member sentenced to 24 months in prison

0
High
Malwareransomware
Published: 09/23/2026 (09/23/2026, 08:20:05 UTC)
Source: Bleeping Computer

Description

An Armenian individual was sentenced to 24 months in prison and 3 years of supervised release for involvement in Ryuk ransomware attacks targeting U.S. companies. The attacks occurred between March 2019 and June 2020, resulting in significant ransom payments. Ryuk ransomware was a ransomware-as-a-service operation active from 2018 to mid-2020, known for targeting sectors including healthcare. After Ryuk's shutdown, related cybercrime groups shifted to other ransomware operations. The sentenced individual specialized in initial network access and pleaded guilty following extradition from Ukraine.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/23/2026, 08:32:52 UTC

Technical Analysis

Karen Serobovich Vardanyan, also known as "Maneeken" or "Karl Lagerfeld," was sentenced for his role in Ryuk ransomware attacks against multiple U.S. organizations from March 2019 to June 2020. He gained initial access to corporate networks and deployed ransomware on hundreds of servers and workstations. The group received approximately 1,610 bitcoins in ransom payments, valued at over $15 million at the time. Ryuk operated as a ransomware-as-a-service from August 2018 until mid-2020, targeting various sectors including healthcare during the COVID-19 pandemic. Following Ryuk's shutdown, the cybercrime gang behind it transitioned to Conti ransomware, which later disbanded in 2022.

Potential Impact

The Ryuk ransomware attacks led to unauthorized access and encryption of systems across multiple U.S. companies, resulting in ransom payments exceeding $15 million. Victims included a Michigan company that paid over $1.1 million in bitcoin, a school in Texas, and a technology company in Oregon. The attacks disrupted operations by encrypting hundreds of servers and workstations. The financial impact was significant, with the Ryuk group collecting more than $150 million in ransoms at its peak.

Defensive Guidance

This report concerns a criminal prosecution outcome rather than a software vulnerability or active exploit. No specific technical mitigation is applicable. Organizations should continue to follow best practices for ransomware defense, but no new remediation or patch is indicated by this information.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.69,"severitySource":"heuristic","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/","fetched":true,"fetchedAt":"2026-09-23T08:32:47.782Z","wordCount":618}

Threat ID: 6ab38eaff7a7c5410682e5c1

Added to database: 09/23/2026, 08:32:47 UTC

Last enriched: 09/23/2026, 08:32:52 UTC

Last updated: 09/23/2026, 13:54:31 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses