Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison
A United States court sentenced Ukrainian national Oleksii Oleksiyovych Lytvynenko to four years in prison this week for his role in the Conti ransomware operation.
Lytvynenko, 44, was arrested in Ireland in 2023 and extradited to the United States in late 2025.
He pleaded guilty to wire fraud in June 2026, admitting to helping the Conti group develop malware and possessing stolen victim data. He faced up to 20 years in prison.
Authorities initially indicated that the Ukrainian man worked with the Conti group between 2020 and 2022, when the operation was shut down. However, at his guilty plea, Lytvynenko admitted joining the cybercrime gang in September 2021.
Lytvynenko helped the group develop a malware loader, but investigators also found victim data in his possession, suggesting that he may have also participated in the actual ransomware attacks.
Investigators determined that Lytvynenko remained involved in ransomware attacks even after the Conti operation ended, until his arrest.
Advertisement. Scroll to continue reading.
The Conti ransomware gang is estimated to have received at least $150 million in ransom payments after encrypting victims’ files and threatening to leak stolen information unless they paid up.
Authorities said the hackers targeted organizations in more than 30 countries, including most US states.
Lytvynenko’s sentencing comes just months after Latvian national Deniss Zolotarjovs was sentenced to 8.5 years in prison in the US for his role as a Karakurt ransomware negotiator.
Last month, the US also announced that the Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison.
Related: Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
Related: Australia Arrests 2 Alleged TeamPCP Hackers
Related: Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft
Reproduced in full under licence from SecurityWeek. © SecurityWeek. Written by Eduard Kovacs.
At a glance
- Severity
- Mediumfrom category and source signals; no CVSS referenced
- Exploitation
- No vulnerabilities referenced
- Vulnerabilities
- None referenced
- Vendors & products
- None named
- Threat actors & malware
- Conti
- Industries
- Not industry-specific
- Coverage
- 1 outlet· first seen 2026-09-11 11:29 UTC
- Priority
- 43/100Source tier, category, exploitation and corroboration. Not a risk score for your environment.
Coverage
One outlet has carried this so far.
2026-09-11 11:29 UTC
Related stories
- Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
Dark Reading · 2026-09-11
- Microsoft sees some new wrinkles in invoice-scam emails
The Record · 2026-09-11
- Why AI Is So Good at Scamming Humans
Dark Reading · 2026-09-11
- Crypto customers targeted by scammers after email marketing provider breach
Malwarebytes Labs · 2026-09-11
- In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review
SecurityWeek · 2026-09-11