A man accused of helping deploy Ryuk ransomware against U.S. victims has pleaded guilty in federal court after being extradited from Ukraine. U.S. prosecutors say Karen Serobovich Vardanyan provided initial access to corporate networks and helped deploy Ryuk between November 2019 and April 2020, encrypting hundreds of servers and workstations. Court records cited attacks including a Michigan company, a technology company in Oregon, and a school in Texas, with the conspirators allegedly receiving about 1,610 bitcoin in ransom payments.
Why it matters: This matters because it ties a named individual to one of the most damaging ransomware operations and shows continued prosecution years after the attacks. Defenders and affected sectors should treat it as a reminder that initial-access brokers and old Ryuk tradecraft still shape current ransomware threats descended from Ryuk and Conti.
Bill Toulas
2026.07.10
100% relevant
This article establishes a distinct law-enforcement story centered on Karen Vardanyan's guilty plea for his role in the Ryuk ransomware operation, not a previously tracked plea or breach event.
2026.07.10
97% relevant
This article directly updates that same Ryuk criminal case with the guilty plea by Karen Serobovich Vardanyan, additional detail on victim organizations in Michigan, Oregon, and Texas, the 200 bitcoin payment, restitution, and sentencing timeline.
← Back to all stories