Extradition Lets Ransomware Cases Outlast the Intrusion

Ransomware liability does not end when the victim restores access. A long-running case can still turn into a guilty plea, restitution, and prison time years later when prosecutors preserve the evidence and keep working across borders. Karen Serobovich Vardanyan pleaded guilty in Oregon to conspiracy and computer fraud tied to Ryuk attacks in 2019 and 2020, after being extradited from Ukraine. Prosecutors say the campaign hit a Michigan company that paid about 200 bitcoin, a technology company in Oregon, and a Texas school, and Vardanyan agreed to pay more than $1.1 million in restitution. Sentencing is set for September 22. The practical point for defenders is not a product fix. It is that ransomware investigations can outlast the incident window by years, and the people who handled deployment or payment can still face criminal liability long after the original compromise has faded from view.

Part of the PlainSec briefing for 2026-07-10

Sources