Back Securityweek Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
A United States court sentenced Ukrainian national Oleksii Oleksiyovych Lytvynenko to four years in prison this week for his role in the Conti ransomware operation.
Lytvynenko, 44, was arrested in Ireland in 2023 and extradited to the United States in late 2025.
He pleaded guilty to wire fraud in June 2026, admitting to helping the Conti group develop malware and possessing stolen victim data. He faced up to 20 years in prison.
Authorities initially indicated that the Ukrainian man worked with the Conti group between 2020 and 2022, when the operation was shut down . However, at his guilty plea, Lytvynenko admitted joining the cybercrime gang in September 2021.
Lytvynenko helped the group develop a malware loader, but investigators also found victim data in his possession, suggesting that he may have also participated in the actual ransomware attacks.
Investigators determined that Lytvynenko remained involved in ransomware attacks even after the Conti operation ended, until his arrest.
The Conti ransomware gang is estimated to have received at least $150 million in ransom payments after encrypting victims’ files and threatening to leak stolen information unless they paid up.
Authorities said the hackers targeted organizations in more than 30 countries, including most US states.
Lytvynenko’s sentencing comes just months after Latvian national Deniss Zolotarjovs was sentenced to 8.5 years in prison in the US for his role as a Karakurt ransomware negotiator.
Last month, the US also announced that the Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison .
Related : Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
Related : Australia Arrests 2 Alleged TeamPCP Hackers
Related : Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
Organizations Warned of Cisco Secure FMC Exploitation
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars
In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Check Point Patches Critical VPN Vulnerabilities
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Surfshark Systems Targeted by Hackers
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
PaperCut Flaws Exploited in AI-Powered Attacks
Mandiant Founder Kevin Mandia Joins Amazon Board
Virtual Event: Attack Surface Management Summit 2026
Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.
Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover?
In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.
Flipboard Whatsapp Whatsapp Email
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
