Ryuk Ransomware Operative Pleads Guilty in $15M Bitcoin Case
Karen Serobovich Vardanyan pleaded guilty to conspiracy and computer fraud in a Ryuk campaign authorities say extorted about 1,610 bitcoin-over $15 million-from U.S. victims.
Karen Serobovich Vardanyan, 34, an Armenian national, pleaded guilty July 8 to conspiracy and computer fraud for his role in a Ryuk ransomware campaign that authorities say extracted about 1,610 bitcoin from U.S. organizations.
The attacks occurred from November 2019 through April 2020. Intruders encrypted files, disabled workstations and left corporate data inaccessible across hundreds of servers and computers.
Attackers placed ransom notes demanding payment in bitcoin and provided an email address for victims to communicate. A Justice Department statement described the scheme: “As part of the scheme, ransom payments were extorted from victim companies in exchange for decryption keys to regain access to their data.” Federal prosecutors say the operation collected roughly 1,610 bitcoin, valued at more than $15 million at the time. One Michigan company transferred 200 bitcoin-more than $1.1 million-to regain control of its network. Other identified victims included a technology company in Wilsonville, Oregon, and a Texas school hit in February 2020.
A federal grand jury in Portland indicted Vardanyan on Feb. 22, 2024, on counts of conspiracy, computer fraud and extortion. He was extradited from Ukraine and entered guilty pleas to the conspiracy and computer fraud counts. Investigators from the FBI, the Justice Department and Ukrainian authorities coordinated on the case.
Under the plea agreement Vardanyan must pay more than $1.1 million in restitution. He faces statutory maximum penalties of five years in prison, a $250,000 fine and three years of supervised release for the conspiracy conviction, and up to 10 years in prison, a $250,000 fine and three years of supervised release for the computer fraud conviction. A U.S. district court judge will determine his sentence on Sept. 22, 2026, after reviewing the plea agreement, restitution terms and federal sentencing guidelines.
Ryuk is a family of ransomware that encrypts data and demands cryptocurrency for decryption tools. In the incidents tied to Vardanyan, authorities say attackers used the disruption from encryption to pressure companies into purchasing decryption tools and supplied keys after funds reached wallets controlled by the conspirators.
The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.







