An access broker for the Ryuk gang draws two years in prison

Karen Vardanyan sold network access to the crew behind some of the worst hospital ransomware attacks of 2020.

MedRisk Staff
By
2 Min Read

An Armenian man who fed corporate networks to the Ryuk ransomware operation will spend two years in federal prison and pay $1.2 million in restitution.

Karen Vardanyan, 35, was extradited from Ukraine after a 2025 arrest and pleaded guilty in July. Prosecutors said he broke into corporate networks between November 2019 and April 2020 and handed the access to accomplices who deployed Ryuk, a strain that became synonymous with hospital shutdowns. He drew 24 months plus three years of supervised release and was ordered to pay $1,219,106 to victims.

Ryuk is best remembered in healthcare for the September 2020 attack on Universal Health Services, which knocked out systems across hundreds of facilities and is estimated to have cost the company around $67 million. The crew also hit dozens of other hospitals and clinics in that period, often crippling electronic health records and forcing staff back onto paper.

The conviction is one of the clearest tied to the group. For security leaders, it is a reminder that the initial-access brokers who open the door are increasingly in prosecutors’ sights, even years after the intrusion. Auditing remote access, patching internet-facing systems, and watching for abnormal credential use remain the controls that break this chain.

Share This Article