A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which compromised more than 1,000 victims worldwide and generated at least $150 million in ransom payments.
Oleksii Oleksiyovych Lytvynenko, 44, previously living in Cork, Ireland, was sentenced for conspiracy to commit wire fraud. U.S. prosecutors said he worked with other Conti operators to deploy ransomware, steal victim data, and extort organizations affected by the attacks.
Conti was one of the most disruptive ransomware operations from 2020 to 2022. The group targeted corporate networks, healthcare providers, schools, local governments, and other critical infrastructure organizations. Its attacks affected victims in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries.
The FBI estimated in January 2022 that Conti-related victims had paid more than $150 million in ransoms. The actual financial damage was likely much higher because that figure did not include ransom demands, recovery costs, incident-response expenses, business disruption, data theft, or reputational damage.
Conti Ransomware Hacker Sentenced
Court records showed that Lytvynenko possessed data stolen from 12 Conti victims, including eight organizations in the United States and four overseas victims. Investigators recovered evidence from his online accounts linking him to storing and handling exfiltrated victim information.
Lytvynenko also admitted that he joined a technical team managed by another Conti conspirator. His work included coding a malware “loader,” a component used to install or launch additional malicious programs on compromised systems.
In ransomware intrusions, loaders can execute payloads, deploy remote-access tools, establish persistence, or launch ransomware across an enterprise network.
Authorities said forensic artifacts seized when Lytvynenko was arrested in County Cork, Ireland, in July 2023 showed he remained involved in ransomware-related activity even after the original Conti operation ended. He pleaded guilty to conspiracy to commit wire fraud on June 10, 2026.
The Conti group was widely associated with a ransomware-as-a-service model, in which core operators, developers, initial-access brokers, affiliates, and money-laundering participants could each contribute to attacks.
This model made the operation resilient, allowing different participants to support reconnaissance, credential theft, lateral movement, data exfiltration, encryption, and extortion.
The sentencing follows a wider U.S. investigation into the Conti and TrickBot cybercrime ecosystem. In September 2023, U.S. authorities unsealed charges against four additional foreign nationals allegedly connected to the malware and ransomware conspiracy.
FBI field offices in San Diego, Nashville, and El Paso, along with the U.S. Secret Service, investigated the case. Homeland Security Investigations also provided support, while Irish law-enforcement and justice agencies assisted with Lytvynenko’s arrest and extradition.
The conviction highlights continued international action against ransomware operators and developers. U.S. authorities stressed that cybercriminals involved in building, deploying, or profiting from ransomware can face prosecution even when they operate outside the United States.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post Conti Ransomware Hacker Sentenced After Group Attacked Over 1,000 Victims Worldwide appeared first on Cyber Security News.
