CiberLATAMbywhalemate

Ryuk Case Ties Vardanyan to U.S. Hospitals

Karen Vardanyan pleaded guilty in Ryuk attacks on U.S. hospitals, bringing renewed scrutiny to ransomware's impact on healthcare.

Whalemate Labs · AI-assisted researchJul 11, 20262 min read

Karen Vardanyan pleaded guilty to Ryuk ransomware attacks targeting hospitals in the United States, in an extortion chain that, according to Moncloa.com, even shut down operating rooms during the pandemic.

Karen Vardanyan pleaded guilty to Ryuk ransomware attacks targeting hospitals in the United States, in the context of an extortion chain that, according to Moncloa.com, even shut down operating rooms during the pandemic.

The Ryuk case

The material published by the Spanish outlet makes an explicit link between Ryuk and U.S. hospital institutions. The key point is legal, since Vardanyan is now tied to an admission of responsibility for those attacks in a case that puts the healthcare sector squarely in the crosshairs of extortion.

The information provided at this stage does not specify which hospitals were affected, how many facilities were involved, or the exact scope of the disruptions beyond the reference to operating rooms being brought to a halt during the pandemic. It also does not include figures for payments, ransom demands, or quantified damage.

Other reports on health care and ransomware

In parallel, a news item circulated by TN23NOTICIAS on Facebook says that two hospitals in the United States were hit with ransomware malware. However, that post offers no verifiable details about the medical centers, the dates, or the scope of the incident, so it should be treated only as a general reference, not as additional confirmation of the case.

The material also includes Spanish-language reports about a ransomware attack on hospitals in Romania that, around the same dates, mention Change Healthcare in the United States suffering a cyberattack that caused severe disruptions to health service delivery. Those texts add that the company paid the attackers, although the available excerpts do not clarify whether the incident was legally classified as ransomware, nor do they include amounts, payment terms, or the exact impact on patients and other providers.

The syndicated Yahoo Noticias version repeats the same line: Change Healthcare faced a cyberattack with major operational disruption and paid the attackers, but the available excerpt does not add further detail. BBC Mundo offers a similar account in its Romania coverage, also without opening the excerpt to additional technical or financial specifics.

The result is a fragmented picture. On one side, there is a guilty plea linked to Ryuk and hospitals in the United States. On the other, there are references to incidents in the U.S. health system with public information that remains incomplete, especially when it comes to measuring the real impact on patients, providers, and operations.

Sources

View all