Karen Serobovich Vardanyan, a 34-year-old Armenian national, pleaded guilty in federal court in Oregon in July 2026 to conspiracy and computer fraud charges tied to a Ryuk ransomware campaign that ran from November 2019 through April 2020. Prosecutors say Vardanyan and his co-conspirators breached U.S. victim organizations, deployed Ryuk across hundreds of servers and workstations, and collected ransom payments valued at more than $15 million at the time of payment. He was arrested in Kyiv in April 2025 and extradited from Ukraine in June 2025, according to The Record. He faces up to 15 years in prison and as much as $500,000 in fines, with sentencing scheduled for September 22.
One sourcing note up front. One of the documents circulated with this incident is a Justice Department press release about Connor Riley Moucka, a Canadian who pleaded guilty on August 5, 2026 to hacking a U.S. cloud storage provider and extorting over 165 victim organizations. That is a separate case with a separate defendant, and nothing in it bears on the Vardanyan prosecution. We are not blending the two. The only overlap is thematic: both are DOJ wins against extortion actors operating from outside the United States.
What Happened
According to the Justice Department, quoted consistently across The Record, Bitdefender, Adbytes and the Daily Hodl syndication, Vardanyan illegally accessed the computer networks of victim companies and deployed Ryuk ransomware on compromised servers and workstations. Ransom notes were dropped on the encrypted systems demanding payment in Bitcoin, with an email address for victims to negotiate through. Payment bought a decryption key.
Three victims are named in the prosecutors' statement. A Michigan company paid 200 bitcoin, worth over $1.1 million at the time of payment, to restore access to its network. A company in Wilsonville, Oregon was also hit. And in February 2020, the group attacked a school in Texas. Daily Security Review, posting on LinkedIn, describes that third victim as a Texas school district rather than a single school; the DOJ language quoted elsewhere says only "a school in Texas," so treat the district characterization as unconfirmed.
Bitdefender goes further than the other sources on victim scope, reporting that prosecutors say the conspiracy targeted hospitals, municipalities, manufacturers, schools and large enterprises. No other source in this set repeats that list, and it should be read as Bitdefender's characterization of the wider Ryuk campaign rather than an established roster of Vardanyan's specific victims.
The total take is where the reporting genuinely diverges. Adbytes, the Daily Hodl syndication and Daily Security Review all put the haul at approximately 1,610 bitcoin, valued at over $15 million at the time of payment. VPN.social reports the figure as roughly 1,160 bitcoins for the same "more than $15 million" valuation. Given that three sources agree on 1,610 and the dollar figure is identical across all four, the 1,160 number reads as a digit transposition, but we are stating the range rather than quietly picking one. Restitution is similarly split: The Record and Daily Security Review both report more than $1.1 million, while Bitdefender says nearly $1.2 million.
What Was Taken
This is an encryption-and-extortion case, not a data theft case, and the distinction matters for anyone reading across to their own risk model. None of the sources describe stolen customer records, exfiltrated databases, or a leak site. What the sources describe is availability destruction: file servers, backup systems and domain controllers encrypted, and organizations paying to get their own data back.
The measurable loss is therefore financial and operational. Roughly 1,610 bitcoin (or 1,160 by VPN.social's count) left victim wallets, worth over $15 million at 2019 to 2020 prices. The Michigan company's 200 BTC payment is the only individual figure disclosed. Adbytes notes that ransomware of this era was methodical rather than smash-and-grab, with attackers probing networks and harvesting credentials before detonation, which means dwell time and credential exposure at these victims was almost certainly broader than the encryption event itself. That is inference from the reporting, not a prosecutorial finding.
Why It Matters
The enforcement timeline is the story here. The offense conduct ended in April 2020. The arrest came in April 2025, the extradition in June 2025, the plea in July 2026, and sentencing lands in September 2026. That is six and a half years from last keystroke to guilty plea. Ryuk operators who assumed the 2019 to 2021 era had aged out of prosecutorial interest were wrong, and Daily Security Review makes the sharper version of that point: U.S. prosecutors are working through each layer of the ransomware supply chain, not just the brand names.
The extradition itself is the second signal. Vardanyan was arrested in Kyiv and handed over to U.S. authorities while Ukraine was under active armed conflict. Daily Security Review flags this explicitly as evidence that cybercrime law enforcement cooperation survived those pressures. For threat actors who have historically treated the region as a safe operating base, that assumption is now demonstrably weaker.
Third, this case does not sit alone. The Record reports it alongside a 70-month federal sentence handed to Angelo Martino, 41, of Land O'Lakes, Florida, for helping the Blackcat/AlphV group extort victims beginning in April 2023. Martino had worked as a ransomware negotiator and used that experience to assist the attackers. Two cases, one week, two different ends of the ecosystem.
Finally, the case is unfinished. The Record reports that Armenian national Levon Georgiyovych Avetisyan has been charged with conspiracy, fraud and extortion in a connected case, with Ukrainian nationals also named. Feed the Herd reports that three co-conspirators remain at large with one believed to be in France; that detail appears in only one lower-tier source and should be treated as unconfirmed.
The Attack Technique
Ryuk was first detected in August 2018 and was among the most active ransomware families in the world during the window covered by this indictment. The Record notes that law enforcement and researchers have long tied Ryuk to the Conti and Trickbot operations, which is the relevant context for initial access: this was an ecosystem where commodity loader infections were converted into hands-on-keyboard intrusions and then into full-domain encryption.
The prosecutorial language quoted by multiple outlets says Vardanyan "illegally accessed computer networks of victim companies and deployed ransomware on hundreds of compromised servers and workstations." That describes credentialed lateral movement at scale, not a single opportunistic encryption. Daily Security Review offers a more specific reading, characterizing Vardanyan as an initial access broker who compromised targets and handed footholds to Ryuk operators who handled payload deployment and negotiation, reaching file servers, backup systems and domain controllers. That role split is plausible and matches how Ryuk affiliates are known to have worked, but it is a single OTHER-tier interpretation and sits in tension with the DOJ's own phrasing that Vardanyan deployed the ransomware. On this point, accounts differ.
What all sources agree on: access came first, encryption came second, and Bitcoin plus an email address in the ransom note handled the money.
What Organizations Should Do
- Protect the backup tier as a separate trust domain. Ryuk-era tradecraft explicitly hunted backup systems before encrypting production. Keep at least one immutable or offline copy, and make sure backup infrastructure does not authenticate against the same domain that the attacker will own.
- Treat domain controller access as the crown jewel it is. Tier your administrative accounts, block lateral movement paths with host firewall rules, and alert on any new service or scheduled task created on a DC. Encryption at this scale requires domain-wide privilege; denying that privilege denies the whole outcome.
- Hunt for the precursor, not the payload. Ryuk arrived after loader infections and credential theft. By the time the ransom note appears, the useful detection opportunity is weeks old. Prioritize telemetry on credential dumping, unusual RDP and SMB traffic, and remote admin tooling used outside change windows.
- Rehearse an availability-loss scenario, not just a data-loss one. No leak site was involved here. Victims paid because they could not operate. Time your actual restore from backup and know the number before an incident forces you to discover it.
- Decide the payment question in advance, in writing. The Michigan victim paid 200 BTC under duress. Whether or not your organization would pay, that decision should not be made for the first time at 3 a.m. with encrypted domain controllers, and legal, insurance and executive stakeholders should already be aligned.
- Preserve evidence and report early. This case closed because investigators had enough to arrest, extradite and charge. Contemporaneous logs, ransom note copies, wallet addresses and negotiation transcripts are what makes that possible six years later.
Sources: Armenian Hacker Pleads Guilty: $15 Million Ransomware Attacks in th... | Office of Public Affairs Canadian Man Pleads Guilty to Hacking U.... | Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly... | Up to 15 years in prison for alleged Ryuk ransomware ... | Armenian National Extradited From Ukraine Pleads Guilty in $15M Ryu... | Vardanyan Pleads Guilty in $15M Ryuk Ransomware Case — vpn.social | Foreign National Admits Guilt in $15,000,000 Bitcoin Ransomware Att... | Armenian Man Pleads Guilty to Enabling Ryuk ...