A Ukrainian national has been sentenced to four years in federal prison for his role in the Conti ransomware conspiracy, a cybercrime operation that infected more than 1,000 victims worldwide and generated more than $150 million in ransom payments, according to the Justice Department and FBI.
Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, was sentenced after pleading guilty on June 10 to conspiracy to commit wire fraud in connection with the deployment of Conti ransomware.
Federal investigators said Lytvynenko worked with others to compromise victim networks, steal data, and deploy ransomware designed to extort organizations by disrupting their systems and threatening the exposure of stolen information.
From 2020 through 2022, Conti ransomware was used against computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. By January 2022, the FBI estimated that ransom payments associated with Conti had exceeded $150 million.
The scale of the operation placed Conti among the most damaging ransomware campaigns pursued by U.S. authorities during that period.
Lytvynenko was not limited to a passive role in the organization.
Evidence recovered from his online accounts showed that he possessed information stolen from eight victims in the United States and four victims overseas.
He also admitted joining a team managed by another Conti conspirator and being directed to develop a malware loader.
A loader is malicious software used to place or execute additional programs on a compromised system. In ransomware operations, that capability can help attackers establish the infrastructure needed to deliver other malicious tools, expand access inside a network, and prepare systems for encryption or data theft.
Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said Lytvynenko functioned as both an intruder and a developer and personally harmed at least 12 companies.
Federal prosecutors also said Lytvynenko stored stolen victim data and helped develop malicious tools used by the Conti operation.
His ransomware activity did not stop when the broader Conti conspiracy ended.
Forensic evidence recovered after his arrest in July 2023 in County Cork, Ireland, showed continued involvement in ransomware activity, according to the Justice Department.
Ransomware organizations frequently reorganize, splinter, adopt new names, or move personnel and infrastructure into other cybercrime operations after law-enforcement pressure or public exposure. The disappearance of a ransomware brand therefore does not necessarily mean the people, tools, or criminal relationships behind it have disappeared.
The government’s case against Lytvynenko focused on his proven involvement in the conspiracy and the technical role he performed within it.
Conti operated through a ransomware ecosystem that combined intrusion capability, malware development, data theft, encryption, extortion, payment infrastructure, and coordination among multiple participants.
The operation targeted organizations across multiple sectors, including hospitals, schools, businesses, government entities, and critical infrastructure.
The Justice Department said those attacks caused substantial operational disruption and financial losses beyond the ransom payments themselves.
Ransomware victims can face system outages, lost productivity, incident-response expenses, restoration costs, legal expenses, regulatory consequences, data-exposure risks, and long-term security remediation even when a ransom is not paid.
FBI Cyber Division Assistant Director Brett Leatherman said Lytvynenko and his co-conspirators attacked networks across nearly every state and emphasized that operating overseas does not shield ransomware actors from U.S. law enforcement.
U.S. Secret Service Office of Field Operations Assistant Director Brent Daniels said the Conti operation disrupted organizations across numerous industries and placed victim data, business operations, and livelihoods at risk.
Lytvynenko’s prosecution is part of a wider federal effort targeting individuals connected to the Conti ecosystem.
In September 2023, an indictment charging four additional alleged Conti conspirators was unsealed in the Middle District of Tennessee.
The Justice Department has continued pursuing participants in ransomware groups through indictments, arrests, extraditions, infrastructure seizures, cryptocurrency tracing, international cooperation, and prosecutions aimed at both developers and operators.
Lytvynenko’s arrest in Ireland demonstrates the international component of those investigations.
The Justice Department’s Office of International Affairs worked with the Irish Department of Justice, Home Affairs, and Migration, the Irish Office of the Attorney General, and the Garda National Cyber Crime Bureau to secure his arrest and extradition.
The investigation involved the FBI San Diego, Nashville, and El Paso Field Offices, along with the U.S. Secret Service.
Homeland Security Investigations New York also provided assistance.
Trial Attorney Sonia V. Jimenez of the Justice Department Criminal Division’s Computer Crime and Intellectual Property Section and Assistant U.S. Attorney Taylor Phillips for the Middle District of Tennessee prosecuted the case.
The Computer Crime and Intellectual Property Section, known as CCIPS, handles major cybercrime and intellectual-property investigations in coordination with domestic and international law-enforcement agencies.
The Justice Department reported that since 2020, CCIPS has secured convictions against more than 180 cyber and intellectual-property offenders and obtained court orders directing the return of more than $350 million in victim funds.
Lytvynenko’s four-year sentence represents another completed prosecution tied to a ransomware operation whose reach extended across the United States and dozens of foreign countries.
The case also illustrates a point that has become central to international ransomware enforcement: developers, intruders, data handlers, infrastructure operators, and other technical participants can all become part of the same criminal conspiracy when their work knowingly supports ransomware attacks.
Although the Conti conspiracy ended, federal investigations and prosecutions involving individuals connected to the operation have continued.
For Lytvynenko, that international trail ended in a U.S. federal courtroom with a four-year prison sentence.
🔥 NOW AVAILABLE! 🔥
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 1 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed
🔥 Kindle Edition 👉 https://a.co/d/9EoGKzh
🔥 Paperback 👉 https://a.co/d/9EoGKzh
🔥 Hardcover Edition 👉 https://a.co/d/0ITmDIB
🔥 NOW AVAILABLE! 🔥
📖 INK & FIRE: BOOK 2 📖
A bold and unapologetic collection of poetry that ignites the soul. Ink & Fire dives deep into raw emotions, truth, and the human experience—unfiltered and untamed just like the first one.
🔥 Kindle Edition 👉 https://a.co/d/1xlx7J2
🔥 Paperback 👉 https://a.co/d/a7vFHN6
🔥 Hardcover Edition 👉 https://a.co/d/efhu1ON
Get your copy today and experience poetry like never before. #InkAndFire #PoetryUnleashed #FuelTheFire
🚨 NOW AVAILABLE! 🚨
📖 THE INEVITABLE: THE DAWN OF A NEW ERA 📖
A powerful, eye-opening read that challenges the status quo and explores the future unfolding before us. Dive into a journey of truth, change, and the forces shaping our world.
🔥 Kindle Edition 👉 https://a.co/d/0FzX6MH
🔥 Paperback 👉 https://a.co/d/2IsxLof
🔥 Hardcover Edition 👉 https://a.co/d/bz01raP
Get your copy today and be part of the new era. #TheInevitable #TruthUnveiled #NewEra
🚀 NOW AVAILABLE! 🚀
📖 THE FORGOTTEN OUTPOST 📖
The Cold War Moon Base They Swore Never Existed
What if the moon landing was just the cover story?
Dive into the boldest investigation The Realist Juggernaut has ever published—featuring declassified files, ghost missions, whistleblower testimony, and black-budget secrets buried in lunar dust.
🔥 Kindle Edition 👉 https://a.co/d/2Mu03Iu
🛸 Paperback Coming Soon
Discover the base they never wanted you to find. TheForgottenOutpost #RealistJuggernaut #MoonBaseTruth #ColdWarSecrets #Declassified



