
AN Armenian national extradited from Ukraine has pleaded guilty in a US federal court to conspiracy and computer fraud linked to the Ryuk ransomware scheme, admitting his role in attacks that extracted more than $1.1 million in restitution from victims. The plea was entered after his transfer to the United States following arrest in 2025, and it covers illegal intrusions carried out between November 2019 and April 2020. The Justice Department announced the agreement, highlighting the financial toll on affected organisations.
During the period of activity Vardanyan and his co‑conspirants gained unauthorized access to corporate networks, deployed Ryuk ransomware and demanded payment in Bitcoin for decryption keys. One Michigan firm reportedly handed over 200 Bitcoin, while a school in Texas also met ransom demands, contributing to a total haul of roughly 1,610 Bitcoin valued at over $15 million at the time. Details of the extortion were outlined by Infosecurity Magazine, underscoring the scale of the operation.
The guilty plea carries a maximum sentence of fifteen years in prison, with sentencing scheduled for 22 September 2026, and the defendant must pay restitution exceeding $1.1 million. Prosecutors from the US Attorney’s Office, assisted by the FBI and Ukrainian authorities, pursued the case as part of a broader effort to dismantle ransomware networks. Security Affairs reported on the forthcoming court date and the financial penalties involved.
Ryuk operated from 2018 to 2020, focusing on sectors such as healthcare, defence and education, and this conviction demonstrates that even after the group’s apparent disbandment, individuals can still be held accountable. The case also illustrates the value of international cooperation, with Ukrainian law‑enforcement playing a key role in the suspect’s extradition. DataBreaches.net noted the cross‑border nature of the investigation and the collaborative effort that led to the plea.
Defenders should review remote‑access mechanisms, enforce multi‑factor authentication on all privileged accounts and ensure that offline, immutable backups are maintained and tested regularly. Network segmentation can limit lateral movement, while continuous monitoring for anomalous authentication or unusual file encryption activity helps detect ransomware early. Patching known vulnerabilities and conducting phishing simulations reduce the likelihood of initial compromise.
Organisations are advised to test incident‑response plans against ransomware scenarios, subscribe to threat‑intelligence feeds that publish Ryuk indicators of compromise and maintain clear communication channels with law‑enforcement for rapid reporting. By combining strong preventive controls with effective detection and response capabilities, the risk of falling victim to similar extortion campaigns can be substantially lowered.