Conti ransomware member sentenced to four years in prison

A Ukrainian national has been sentenced to four years in prison for his role in the Conti ransomware operation, which extorted over $150 million from victims globally.
Oleksii Lytvynenko, a 44-year-old Ukrainian national, has received a four-year prison sentence for his involvement in the Conti ransomware gang. He was arrested by Irish police in 2023 at the request of the United States and later extradited to face charges. His conviction marks a significant legal milestone in the ongoing dismantling of one of the most prolific cybercrime syndicates of the early 2020s.
The Department of Justice stated that Conti targeted computers in 47 U.S. states, 31 foreign countries, and Puerto Rico. The FBI estimates that victim payouts associated with the group exceeded $150 million by January 2022. Lytvynenko admitted to joining the conspiracy in September 2021, where he acted as both an intruder and a developer, directly harming at least 12 companies and helping build the malicious tools used for extortion.
Dual role in cyber extortion
Lytvynenko’s specific duties involved a combination of direct intrusion and software development. He controlled stolen data from eight U.S. victims and four overseas entities, using this information to send ransom notes. This practice, known as double extortion, pressures victims to pay not only to decrypt their files but also to prevent the public release of sensitive data.
In addition to data theft, Lytvynenko contributed to the technical infrastructure of the gang. He coded a loader, a type of malware designed to install other malicious software onto victim networks. This component was essential for deploying the ransomware that encrypted devices, effectively holding the victims' operations hostage. His guilty plea in June 2026 avoided a maximum potential sentence of 20 years.
Origins of the Conti syndicate
Conti emerged from the Ryuk cybercrime group in 2020, maintaining close ties to the TrickBot malware gang. It evolved into a large-scale syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot. The group became notorious for targeting healthcare organizations, government entities, and large enterprises, amassing over $150 million in ransom payments from more than 1,000 victims worldwide.
The syndicate’s operations faced increasing pressure from law enforcement, leading to its shutdown in 2022. This collapse was accelerated by the leak of internal communications, known as ContiLeaks, which exposed the identities and strategies of its members. Following the disbandment, many members fragmented into new ransomware groups such as BlackCat, Black Basta, and Hive, continuing their criminal activities under different banners.
Global law enforcement response
The dismantling of Conti has been a coordinated international effort. BleepingComputer reported that sanctions were imposed on TrickBot and Conti members in 2023, following the massive data leaks. In September of the same year, the U.S. and U.K. sanctioned nine Russian nationals for attacks on over 900 victims. Additionally, German authorities identified the alleged leader of the gang in 2025, highlighting the persistent global threat posed by these organized cybercrime groups.






