Conti Ransomware Accomplice Sentenced to Four Years for Wire Fraud Conspiracy
A Ukrainian national, **Oleksii Oleksiyovych Lytvynenko**, has been sentenced to four years in prison for his involvement in the notorious **Conti** ransomware operation. Lytvynenko, extradited from Ireland, pleaded guilty to conspiracy to commit wire fraud, playing a role in attacks that impacted numerous organizations globally and extorted over $150 million.

A Ukrainian national has received a four-year prison sentence for his direct involvement in **Conti** ransomware attacks spanning from 2021 to 2022.
**Oleksii Oleksiyovych Lytvynenko**, 44, was apprehended by the Irish national police (**An Garda SΓochΓ‘na**) in July 2023 following a request from the United States. He was subsequently extradited last year.
Lytvynenko and his **Conti** co-conspirators deployed ransomware across victim networks in the U.S. and abroad. Their modus operandi involved data exfiltration and device encryption to extort **Bitcoin** ransom payments.
"From 2020 until 2022, **Conti** was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The **FBI** estimates that, as of January 2022, there had been victim payouts associated with **Conti** ransomware exceeding $150,000,000," the **Department of Justice** stated.
Assistant Attorney General **A. Tysen Duva** added, "Lytvynenko joined that conspiracy as both an intruder and a developer β personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools **Conti** used to extort and threaten communities."
Lytvynenko pleaded guilty to conspiracy to commit wire fraud in June 2026, facing a potential maximum sentence of 20 years.
He admitted to joining the **Conti** operation in September 2021, where he managed stolen data from eight U.S. victims and four international victims. He also confessed to sending ransom notes as part of the cybercrime group's double extortion tactics between 2020 and June 2022.
Furthermore, Lytvynenko acknowledged his role in a team led by another **Conti** conspirator, where he developed a "loader" β a type of malware designed to facilitate the deployment of attack software.
## The Conti Ransomware Gang's Legacy
The **Conti** ransomware operation emerged in 2020, evolving from the **Ryuk** cybercrime group and maintaining close ties with the **TrickBot** malware gang. It quickly gained notoriety for its extensive attacks targeting healthcare organizations, government entities, and enterprises.
**Conti** transformed into a sophisticated cybercrime syndicate, controlling multiple malware operations, including **BazarBackdoor** and **TrickBot**. The group ultimately disbanded in 2022, a decision influenced by heightened law enforcement pressure and the public leak of its internal communications.
Following its dissolution, the **Conti** gang fragmented into several other prominent ransomware groups, including **BlackCat** (**ALPHV**), **Black Basta**, **ZEON**, **Hive**, **Quantum**, **BlackByte**, **Karakurt**, and the **Silent Ransom Group**.
In February 2023, seven **TrickBot**/**Conti** members were sanctioned after significant leaks of personal information and internal conversations, known as **ContiLeaks** and **TrickLeaks**.
September 2023 saw the U.S. and the United Kingdom further sanction and charge nine Russian nationals linked to **Conti** and **TrickBot** for attacks affecting over 900 victims globally. The **Federal Criminal Police Office of Germany** (**Bundeskriminalamt** or **BKA**) also unmasked the alleged leader of the **TrickBot** and **Conti** cybercrime gangs in May 2025, identifying him as 36-year-old Russian **Vitaly Nikolaevich Kovalev**, who used the alias "**Stern**."
Court documents reveal that the **Conti** cybercrime gang targeted over 1,000 victims worldwide and amassed more than $150 million in ransom payments during its active period.