Conti ransomware crew member sentenced to four years in prison
Get our latest cybersecurity news first on Google.
A 44-year-old Ukrainian national was sentenced to four years in prison for his long-running participation in Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, the Justice Department said Thursday.
Oleksii Oleksiyovych Lytvynenko, also known as Alexsey Alexseevich Litvinenko, pleaded guilty in June to conspiracy to commit wire fraud as a result of some of those attacks. At that time, he admitted he joined the prolific cybercrime group in September 2021, developed malware and held data on 12 victims, including eight based in the United States.
“For years, the Conti ransomware group executed a sustained and sophisticated campaign that victimized hundreds of organizations across the United States and abroad, including critical infrastructure entities, causing losses in the millions of dollars,” A. Tysen Duva, assistant attorney general of the Justice Department’s criminal division, said in a statement.
“Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,” Duva added. “Even after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest. Cybercriminals who build, deploy, or profit from malware like Conti — no matter where they operate — will face justice and meaningful consequences in U.S. courts.”
When Lytvynenko was arrested in Ireland, where he was living with temporary protective status in July 2023, authorities said he “was asleep but within arms’ reach of an open laptop running Cobalt Strike.” He was extradited to the United States in October 2025.
Prosecutors said Lytvynenko and his co-conspirators extorted about $634,000 in Bitcoin from two victims in Tennessee, including an undisclosed government entity that resulted in the compromise of a sheriff’s department, local emergency medical services and a local police department. According to an indictment that was unsealed last fall, Lytvynenko and his co-conspirators also leaked data they stole from another Tennessee-based victim after it refused to pay a $3 million ransom demand.
Four of Lytvynenko’s alleged co-conspirators — Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev and Andrey Yuryevich Zhuykov — were indicted in 2023 in the same federal court for crimes related to their suspected involvement in Conti attacks from 2020 to 2022.
Conti was among the most active ransomware groups globally, impacting hundreds of critical infrastructure providers, Costa Rica’s government in 2022, and ultimately leading the State Department to offer a $10 million reward for information related to Conti’s leaders. The group was notoriously resilient, bouncing back with new infrastructure and hitting new targets after a massive leak exposed chats between the group’s members in 2022.
Conti disbanded later that year, but members of the Cyrillic-language group rebranded under three subgroups: Zeon, Black Basta and Quantum, which quickly rebranded to Royal, before rebranding again to BlackSuit in 2024.
“Lytvynenko and his co-conspirators used Conti ransomware to attack computers and networks in nearly every state, and today’s sentence reflects the gravity and extent of those crimes,” Brett Leatherman, assistant director of the FBI’s cyber division, said in a statement.
“Ransomware criminals should know they are not anonymous and operating from overseas does not mean operating without consequences,” he added. “The FBI and our partners will use every lawful tool to dismantle their infrastructure and bring them to justice.”
Latest Podcasts
Government
FTC rescinds policy requiring health apps to notify customers after a breach
Lawmakers call on Commerce to sanction hackers-for-hire
FBI cyber chief worries private sector not sharing enough cyber threat information
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Technology
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Pegasus, NoviSpy variant spyware found on devices of Serbian activists
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Attackers exploit zero-days in consistently besieged SonicWall product
Wyden seeks upgraded NSA security guidance on commercial VPN use
FBI raises alarm over deceptive phishing campaign targeting prominent people
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Reproduced in full under licence from CyberScoop. © CyberScoop. Written by Matt Kapko.
At a glance
- Severity
- Mediumfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- None named
- Threat actors & malware
- Conti
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-10 20:31 UTC
- Priority
- 43/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-10 20:31 UTC
Related stories
- Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Dark Reading · 2026-09-11
- Microsoft sees some new wrinkles in invoice-scam emails
The Record · 2026-09-11
- Why AI Is So Good at Scamming Humans
Dark Reading · 2026-09-11
- Crypto customers targeted by scammers after email marketing provider breach
Malwarebytes Labs · 2026-09-11
- In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
SecurityWeek · 2026-09-11