Conti ransomware gang member sentenced to 4 years in prison
US court sentences Ukrainian Conti ransomware member Oleksii Lytvynenko to four years; the gang extorted over $150M from 1,000+ victims.
Ukrainian national Oleksii Oleksiyovych Lytvynenko, 44, was sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022, after being arrested by Irish police in July 2023 and extradited to the US. He pleaded guilty in June 2026 to conspiracy to commit wire fraud, admitting he controlled stolen data from 12 victims and helped develop a loader used in the gang's double extortion attacks. Per the DOJ, Conti attacked more than 1,000 victims across 47 US states and 31 foreign countries, with victim payouts exceeding $150 million as of January 2022. Conti shut down in 2022 and later split into groups including BlackCat, Black Basta, Hive and Quantum.
- Lytvynenko admitted controlling stolen data of 8 US and 4 overseas victims, harming at least 12 companies.
- Conti attacked 1,000+ victims in 47 US states and 31 countries, collecting over $150 million in ransoms.
- He joined in September 2021 as intruder and developer, coding a loader for double extortion attacks.
- Conti shut down in 2022 and split into BlackCat, Black Basta, Hive, Quantum and other groups.
- Seven TrickBot/Conti members were sanctioned in 2023 after the ContiLeaks and TrickLeaks chat leaks.
Full article538 words · extracted from bleepingcomputer.com · click to collapse

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.
44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda Síochána) in July 2023 at the request of the United States and was extradited last year.
Lytvynenko and his Conti accomplices deployed ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.
"From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000," the Department of Justice said on Thursday.
"Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities," added Assistant Attorney General A. Tysen Duva.
The defendant pleaded guilty to conspiracy to commit wire fraud in June 2026 and was facing a maximum sentence of 20 years in prison.
He admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight U.S. victims and four overseas victims, and sending ransom notes as part of the cybercrime gang's double extortion attacks between 2020 and June 2022.
Lytvynenko also admitted to joining a team run by another Conti conspirator, where he coded a "loader," which is a type of malware designed to load the software needed to carry out attacks.
Conti ransomware gang
The Conti ransomware operation emerged from the Ryuk cybercrime group in 2020 with close ties to the TrickBot malware gang, and became notorious for large-scale attacks against healthcare organizations, governments, and enterprises.
Conti evolved into a cybercrime syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot, and it shut down two years later, in 2022, after increased law enforcement pressure and leaked internal chats.
The Conti gang later split into other ransomware groups, including BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.
Seven TrickBot/Conti members were sanctioned in February 2023, after a massive leak of personal information and internal conversations belonging to Conti and TrickBot members, known as the ContiLeaks and TrickLeaks.
In September 2023, the U.S. and the United Kingdom also sanctioned and charged nine Russian nationals associated with Conti and TrickBot for attacks against over 900 victims worldwide, while the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) doxed the leader of the TrickBot and Conti cybercrime gangs in May 2025, claiming he is a 36-year-old Russian named Vitaly Nikolaevich Kovalev using the alias "Stern."
According to court documents, the Conti cybercrime gang has targeted more than 1,000 victims worldwide and collected over $150 million in ransom payments while active.
Build your security blueprint for AI-powered attacks
Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/