A U.S. court has sentenced an Armenian man to 24 months in prison and three years of supervised release for his role in Ryuk ransomware attacks against American companies. The defendant admitted to hacking corporate networks and deploying encryption that disrupted operations, according to the BleepingComputer report. The sentence reflects a broader trend of law enforcement pursuing individual affiliates rather than only the core developers or leaders of ransomware cartels.
The case is notable because Ryuk is one of the most damaging ransomware strains of recent years, responsible for costly outages across hospitals, municipalities, and businesses. While many such prosecutions target high-level administrators, this defendant appears to have been a mid-level operator who performed the technical intrusion work. The relatively short sentence — two years — may signal that courts weigh the defendant's role and cooperation when punishing lower-tier participants.
The verdict also serves as a warning to other would-be affiliates: even if you are not the mastermind, you can still face federal prison time and extended supervision. However, the sentence is far lighter than those handed to top Ryuk leaders, who have received decades in other jurisdictions. That disparity suggests the justice system reserves its harshest penalties for those who organize the schemes rather than those who carry them out.