Ransomware Extortionist Sentenced to Prison

A federal court sentenced a man to 24 months in prison for deploying Ryuk ransomware against various entities.

Updated on Sept. 22, 2026 in Cybersecurity

Bold flat-color editorial illustration of a slightly open steel server door, evoking the consequences of digital extortion.
A federal court sentenced Armenian citizen Karen Vardanyan to 24 months in prison for his role in a global Ryuk ransomware conspiracy. AI Illustration. Upload story photo >

Live Poll

Do you trust that businesses are doing enough to protect your digital data from ransomware attacks?

Karen Vardanyan, a 35-year-old Armenian citizen, received a 24-month prison sentence for his role in a global ransomware conspiracy. The scheme targeted companies and schools, resulting in over $1.2 million in court-ordered restitution.

Why it matters

This sentencing addresses a major digital threat where perpetrators rendered computer networks unusable to extort payments. It highlights the federal crackdown on international cybercriminals who used cryptocurrency to hide their illicit profits.

The defendant, operating under aliases, utilized Ryuk ransomware to paralyze victim networks between March 2019 and June 2020. Victims were forced to facilitate extortion payments primarily through Bitcoin.

The players

Karen Vardanyan

He is a 35-year-old Armenian citizen who operated under the monikers Maneeken and Karl Lagerfeld.

The details

Vardanyan, who was extradited from Ukraine to face charges in the United States, pleaded guilty to conspiracy and computer fraud. The court mandate includes a 3-year term of supervised release following his two-year prison stint.

Timeline

  1. March 2019 to June 2020: Vardanyan participated in the ransomware conspiracy.

  2. February 22, 2024: A federal grand jury returned a superseding indictment.

  3. July 8, 2026: Vardanyan pleaded guilty to conspiracy and computer fraud.

  4. September 22, 2026: Vardanyan was sentenced to federal prison.

The Tech Race

This case illustrates the intensifying global effort to dismantle sophisticated ransomware operations that have historically operated with relative impunity. It highlights the transition toward aggressive international extradition protocols to counter the digital threats posed by anonymous online extortionists.

The use of ransomware against schools and companies can lead to prolonged service outages and data security concerns for local residents. This court action serves as a deterrent that may eventually reduce the frequency of cyberattacks targeting local infrastructure.

The takeaway

Cybersecurity experts recommend that entities regularly back up critical data and implement robust multi-factor authentication to mitigate ransomware risks. Understanding that these schemes often utilize cryptocurrency remains vital for individuals and businesses monitoring their digital footprints.

Further reading

Learn more about the evolving landscape of digital threats in our Cybersecurity section.

Live Poll

Do you trust that businesses are doing enough to protect your digital data from ransomware attacks?