Conti Ransomware Developer Sentenced to Four Years in Prison for Cyberattacks

Lytvynenko pleaded guilty on June 10, 2026, to conspiracy to commit wire fraud; prosecutors said he joined Conti around September 2021 and retained stolen data from 12 victims, including eight in the United States.
U.S. officials said Lytvynenko continued participating in ransomware operations after the Conti conspiracy ended and remained active until his arrest.
When Lytvynenko was arrested in Ireland, authorities said he was asleep within arm’s reach of an open laptop running Cobalt Strike, a penetration-testing tool frequently used by attackers.
Prosecutors said Lytvynenko and his co-conspirators extorted approximately $634,000 in Bitcoin from two Tennessee victims, including an undisclosed government entity whose network compromise affected a sheriff’s department, emergency medical services and a police department.
A Ukrainian developer of the Conti ransomware gang has been sentenced to four years in U.S. prison after pleading guilty to wire fraud conspiracy. SecurityWeek reports that Oleksii Oleksiyovych Lytvynenko joined the operation around September 2021, helping create malicious tools and stealing data from at least 12 victims. The Conti gang targeted over 1,000 victims worldwide and generated an estimated $150 million or more in ransom payments before the operation was shut down.
Lytvynenko was arrested in Ireland in 2023 while asleep next to an open laptop running Cobalt Strike, a tool attackers use to break into computer networks. The Record notes that prosecutors said Lytvynenko and his co-conspirators extorted roughly $634,000 in Bitcoin from two Tennessee victims, including a government entity whose network compromise affected a sheriff's department, emergency medical services, and police department.
Lytvynenko trained as a lawyer before joining the Conti ransomware gang. The Register reports he took on a double life, working as a developer and intruder for the operation. He retained stolen data from at least 12 companies and participated in attacks that disrupted critical infrastructure and public agencies across multiple countries.
Irish authorities arrested Lytvynenko in 2023 while he was asleep at his laptop. He was found with Cobalt Strike already running on his computer, a penetration-testing tool frequently used by hackers to break into networks. Following international legal proceedings, he was extradited to the United States to face federal charges.
The Conti operation affected more than 1,000 victims across the United States and other countries before shutting down. The Record states that the gang generated an estimated $150 million or more in ransom payments through extortion campaigns. Lytvynenko and his conspirators extracted approximately $634,000 in Bitcoin alone from just two Tennessee victims.
The case demonstrates the U.S. government's commitment to pursuing ransomware developers and technical participants across borders. Prosecutors revealed that Lytvynenko continued participating in ransomware operations even after the Conti conspiracy officially ended. His arrest and prosecution underscore efforts to hold accountable the skilled individuals who enable large-scale extortion campaigns targeting businesses and critical infrastructure.
Publishers
14
Articles
9
Reach
23