An Armenian individual has been sentenced in the United States for his involvement in orchestrating Ryuk ransomware attacks across various global organizations, including one in Oregon. Karen Vardanyan, aged 35, was extradited from Ukraine to face charges in the U.S. and has now been sentenced to 24 months in federal prison, followed by three years of supervised release. Additionally, he is required to pay restitution amounting to $1,219,106 to the victims affected by his actions, as reported by the U.S. Attorney’s Office for the District of Oregon.
Details of the Ransomware Scheme
Vardanyan was a part of a conspiracy that deployed Ryuk ransomware on networks between March 2019 and June 2020. Operating under the aliases “Maneeken” and “Karl Lagerfeld,” he played a key role in the cyber extortion operation. Ryuk ransomware was used to encrypt files within targeted organizations, severely disrupting their computer systems. Attackers demanded payments, primarily in Bitcoin, to restore access or provide decryption keys to the victims.
Court documents revealed that the conspiracy targeted a wide range of entities, including companies and educational institutions worldwide, extorting over $1 million from various victims. Among the affected was a company based in Wilsonville, Oregon. This case underscores the global reach and complexity of major ransomware operations, often involving multiple countries while targeting international victims.
Legal Proceedings and Sentencing
A federal grand jury in Portland charged Vardanyan with conspiracy, computer fraud, and computer extortion on February 22, 2024. Following his extradition from Ukraine, Vardanyan appeared in a U.S. federal court on June 20, 2025, where he was ordered detained. He later pleaded guilty to charges of conspiracy and computer fraud on July 8, 2026. Ryuk ransomware is notorious for being one of the most disruptive tools used against enterprise networks, targeting high-value entities where operational disruptions can exert significant pressure.
This type of ransomware campaign can impact business operations, customer services, data availability, backup systems, and incident-response capabilities. To mitigate such threats, organizations are advised to maintain offline, tested backups, deploy multi-factor authentication, promptly patch systems, restrict privileged access, and monitor networks for suspicious activity.
International Cooperation in Cybercrime Investigations
The FBI conducted the investigation, while Assistant U.S. Attorney Katherine Rykken prosecuted the case. The Justice Department’s Office of International Affairs played a crucial role in securing Vardanyan’s extradition, with significant cooperation from Ukrainian authorities. This case highlights the importance of international collaboration in combating cybercrime and bringing perpetrators to justice.
Security professionals recommend that organizations also investigate unauthorized remote access, unusual credential usage, disabled security controls, and rapid file-renaming activities as part of their cybersecurity measures.
