Back Technadu Ukrainian National Sentenced to Four Years Over Conti Ransomware Connections
Sentence length: Oleksii Oleksiyovych Lytvynenko, 44, received four years in prison for wire fraud conspiracy connected to Conti ransomware.
Scale of harm: Conti infected more than 1,000 victims worldwide, with FBI-estimated ransom payouts exceeding $150 million as of January 2022.
Defendant's role: Lytvynenko worked as both an intruder and a developer, coding a malware "loader" for a Conti conspirator.
A U.S. federal court sentenced Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national formerly based in Cork, Ireland, to four years in prison on September 10 for conspiracy to commit wire fraud tied to the Conti ransomware operation.
Conti's Reach Spanned Nearly Every U.S. State
Between 2020 and 2022, Conti was deployed against computers and networks across 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries, according to court documents.
Lytvynenko conspired with others to deploy ransomware to extort victims and steal their data, targeting hospitals, schools, businesses, local governments, and critical infrastructure entities.
Guilty Plea Details His Work as Intruder and Coder
Lytvynenko pleaded guilty to wire fraud conspiracy on June 10. Evidence from his online accounts showed he possessed stolen data from eight U.S. victims and four overseas victims – roughly a dozen companies personally harmed, according to prosecutors.
He admitted joining a team run by a Conti conspirator, who directed him to code a loader.
Case Built on Multi-Agency, International Investigation
Authorities arrested the individual in July 2023 in County Cork, Ireland, where forensic evidence pointed to continued ransomware activity even after Conti's operations had wound down. Lytvynenko was extradited from Ireland to the U.S. in October 2025.
A September 2023 indictment in the Middle District of Tennessee had already charged four other Conti conspirators. A massive data leak in June 2025 exposed Conti and Trickbot ransomware operators.
The Conti ransomware operation was one of the most destructive of its time, responsible for attacks on more than 1,000 entities worldwide, with the FBI estimating victim payouts topping $150 million as of January 2022. Victims were located in approximately 47 U.S. states and 31 foreign countries. In 2021, Conti was identified as the most active ransomware variant targeting critical infrastructure.
In May, a Conti and Akira affiliate was sentenced to 102 months in prison for ransomware and extortion operations targeting over 50 organizations.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
