Skip to content
Conti ransomware gang member sentenced to 4 years in prison

Conti ransomware gang member sentenced to 4 years in prison

Bleepingcomputer September 11, 2026

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.

44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda Síochána) in July 2023 at the request of the United States and was extradited last year.

Lytvynenko and his Conti accomplices deployed ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.

"From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000," the Department of Justice said on Thursday .

"Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities," added Assistant Attorney General A. Tysen Duva.

The defendant pleaded guilty to conspiracy to commit wire fraud in June 2026 and was facing a maximum sentence of 20 years in prison.

He admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight U.S. victims and four overseas victims, and sending ransom notes as part of the cybercrime gang's double extortion attacks between 2020 and June 2022.

Lytvynenko also admitted to joining a team run by another Conti conspirator, where he coded a "loader," which is a type of malware designed to load the software needed to carry out attacks.

Conti ransomware gang

The Conti ransomware operation emerged from the Ryuk cybercrime group in 2020 with close ties to the TrickBot malware gang, and became notorious for large-scale attacks against healthcare organizations, governments, and enterprises.

Conti evolved into a cybercrime syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot, and it shut down two years later, in 2022, after increased law enforcement pressure and leaked internal chats .

The Conti gang later split into other ransomware groups , including BlackCat , Black Basta, ZEON, Hive, Quantum , BlackByte , Karakurt , and the Silent Ransom Group .

Seven TrickBot/Conti members were sanctioned in February 2023, after a massive leak of personal information and internal conversations belonging to Conti and TrickBot members, known as the ContiLeaks and TrickLeaks .

In September 2023, the U.S. and the United Kingdom also sanctioned and charged nine Russian nationals associated with Conti and TrickBot for attacks against over 900 victims worldwide, while the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) doxed the leader of the TrickBot and Conti cybercrime gangs in May 2025, claiming he is a 36-year-old Russian named Vitaly Nikolaevich Kovalev using the alias "Stern."

According to court documents, the Conti cybercrime gang has targeted more than 1,000 victims worldwide and collected over $150 million in ransom payments while active.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.