Key Takeaways
- Karen Vardanyan received 24 months in federal prison, three years of supervised release, and a $1,219,106 restitution order.
- The case connects Ryuk operations to attacks against U.S. companies and a school during 2019 and 2020.
- Ransomware remains a substantial business risk, with attackers changing variants and targeting critical infrastructure.
An Armenian national linked to the Ryuk ransomware gang has been sentenced for participating in attacks that encrypted victim networks and supported extortion demands.
Karen Vardanyan received 24 months in federal prison, followed by three years of supervised release. He was also ordered to pay $1,219,106 in restitution, according to The Record. Vardanyan had pleaded guilty to computer fraud and conspiracy charges connected to attacks against U.S. companies and a school during 2019 and 2020.
The sentence closes one part of a case involving a ransomware operation that became known for targeting organizations where downtime could quickly translate into financial or operational pressure. Ryuk operators encrypted systems and used that disruption to extract payments from victims. Schools, hospitals, companies, and public institutions have all faced versions of this basic playbook.
For business leaders, the age of the underlying attacks does not make the case less relevant. Investigations into cross-border ransomware groups can stretch across years, particularly when operators, infrastructure, victims, and financial transactions are distributed across multiple jurisdictions. Arrests and prosecutions can therefore arrive well after an incident has disappeared from daily security reports.
While law enforcement action can raise the cost of participating in ransomware, it does not remove the operational problem for enterprises. Groups can fragment, rebrand, recruit new affiliates, or shift to another ransomware family. Names such as Ryuk, LockBit, and Qilin may dominate headlines at different times, while the underlying model remains familiar: gain access, expand privileges, steal or encrypt data, and apply pressure.
The FBI Internet Crime Complaint Center recorded 3,611 ransomware complaints and $32.3 million in reported losses during 2025. Those figures do not capture much of the disruption, recovery spending, lost productivity, legal work, or reputational damage that can follow an attack. The FBI also identified 63 new ransomware variants in 2025, with healthcare, critical manufacturing, and government facilities among the critical-infrastructure sectors most frequently affected.
In many cases, attackers do not need an exotic vulnerability to execute these intrusions. Stolen credentials, exposed remote access, delayed patching, weak privilege controls, and gaps in monitoring can provide enough room to establish a foothold. Once inside, an intruder may spend time mapping systems, locating backups, and identifying the assets most likely to create leverage.
Buying another security product is rarely a complete answer. Organizations commonly use technologies from CrowdStrike, Palo Alto Networks, Sophos, and other vendors for endpoint monitoring, network defense, and incident response. The value of those controls depends heavily on configuration, coverage, staffing, and whether alerts lead to timely action. A tool that detects suspicious behavior but sits in an unattended queue offers limited protection.
A more durable approach treats ransomware as an enterprise risk rather than solely an IT issue. The NIST Cybersecurity Framework 2.0 groups security work around governance, identification, protection, detection, response, and recovery. NIST’s 2025 Ransomware Risk Management CSF 2.0 Community Profile applies those functions more specifically to ransomware readiness (source).
In practice, that can include mapping critical systems, limiting administrative privileges, using multifactor authentication, segmenting networks, and maintaining isolated backups that are routinely tested. Response plans should also identify decision-makers across security, legal, finance, communications, insurance, and executive leadership. Tabletop exercises can expose awkward questions before a real incident does, including who can shut down systems, contact law enforcement, or approve recovery spending.
The Vardanyan sentence demonstrates that individual ransomware participants can face prison, supervision, and substantial financial penalties years after attacks occur. For companies, though, deterrence remains only one layer of defense. The more immediate task is reducing opportunities for intrusion and building enough recovery capacity that extortion pressure loses some of its force.
⬇️