BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Sep 11, 2026 · 2 min read · Original story

Conti ransomware gang member sentenced to 4 years in prison

Conti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.

44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda Síochána) in July 2023 at the request of the United States and was extradited last year.

Lytvynenko and his Conti accomplices deployed ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.

"From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000," the Department of Justice said on Thursday.

"Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities," added Assistant Attorney General A. Tysen Duva.

The defendant pleaded guilty to conspiracy to commit wire fraud in June 2026 and was facing a maximum sentence of 20 years in prison.

He admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight U.S. victims and four overseas victims, and sending ransom notes as part of the cybercrime gang's double extortion attacks between 2020 and June 2022.

Lytvynenko also admitted to joining a team run by another Conti conspirator, where he coded a "loader," which is a type of malware designed to load the software needed to carry out attacks.

Conti ransomware gang

The Conti ransomware operation emerged from the Ryuk cybercrime group in 2020 with close ties to the TrickBot malware gang, and became notorious for large-scale attacks against healthcare organizations, governments, and enterprises.

Conti evolved into a cybercrime syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot, and it shut down two years later, in 2022, after increased law enforcement pressure and leaked internal chats.

The Conti gang later split into other ransomware groups, including BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.

Seven TrickBot/Conti members were sanctioned in February 2023, after a massive leak of personal information and internal conversations belonging to Conti and TrickBot members, known as the ContiLeaks and TrickLeaks.

In September 2023, the U.S. and the United Kingdom also sanctioned and charged nine Russian nationals associated with Conti and TrickBot for attacks against over 900 victims worldwide, while the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) doxed the leader of the TrickBot and Conti cybercrime gangs in May 2025, claiming he is a 36-year-old Russian named Vitaly Nikolaevich Kovalev using the alias "Stern."

According to court documents, the Conti cybercrime gang has targeted more than 1,000 victims worldwide and collected over $150 million in ransom payments while active.

References in this story

  1. Ukrainian extradited from Ireland on Conti ransomware charges www.bleepingcomputer.com A Ukrainian national believed to be a member of the Conti ransomware operation has been extradited to the United States and faces charges that could get him 25 years in prison.
  2. Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware www.justice.gov Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that…
  3. Ukrainian national pleads guilty to role in Conti ransomware operation www.bleepingcomputer.com A Ukrainian national extradited from Ireland to the United States last year has pleaded guilty to conspiracy charges tied to the Conti ransomware operation.
  4. Conti ransomware shows signs of being Ryuk's successor www.bleepingcomputer.com The Conti Ransomware is an upcoming threat targeting corporate networks with new features that allow it to perform quicker and more targeted attacks. There are also indications that this ransomware shares the same…
  5. Conti ransomware gang takes over TrickBot malware operation www.bleepingcomputer.com After four years of activity and numerous takedown attempts, the death knell of TrickBot has sounded as its top members move under new management, the Conti ransomware syndicate, who plan to replace it with the…
  6. Conti ransomware's internal chats leaked after siding with Russia www.bleepingcomputer.com An angry member of the Conti ransomware operation has leaked over 60,000 private messages after the gang sided with Russia over the invasion of Ukraine.
  7. Conti ransomware shuts down operation, rebrands into smaller units www.bleepingcomputer.com The notorious Conti ransomware gang has officially shut down their operation, with infrastructure taken offline and team leaders told that the brand is no more.
  8. BlackCat (ALPHV) ransomware linked to BlackMatter, DarkSide gangs www.bleepingcomputer.com The Black Cat ransomware gang, also known as ALPHV, has confirmed they are former members of the notorious BlackMatter/DarkSide ransomware operation.
  9. Quantum ransomware seen deployed in rapid network attacks www.bleepingcomputer.com The Quantum ransomware, a strain first discovered in August 2021, were seen carrying out speedy attacks that escalate quickly, leaving defenders little time to react.
  10. BlackByte ransomware decryptor released to recover files for free www.bleepingcomputer.com A free decryptor for the BlackByte ransomware has been released, allowing past victims to recover their files for free.
  11. Karakurt revealed as data extortion arm of Conti cybercrime syndicate www.bleepingcomputer.com After breaching servers managed by the cybercriminals, security researchers found a connection between Conti ransomware and the recently emerged Karakurt data extortion group, showing that the two gangs are part of the…
  12. Silent Ransom Group targets law firms with fake IT support calls www.bleepingcomputer.com The Silent Ransom Group extortion gang is actively targeting U.S. law firms and professional services organizations in social engineering attacks that often lead to data theft within hours of initial contact, according…
  13. U.S. and U.K. sanction TrickBot and Conti ransomware operation members www.bleepingcomputer.com The United States and the United Kingdom have sanctioned seven Russian individuals for their involvement in the TrickBot cybercrime group, whose malware was used to support attacks by the Conti and Ryuk ransomware…
  14. Unmasking Trickbot, One of the World’s Top Cybercrime Gangs www.wired.com A WIRED investigation into a cache of documents posted by an unknown figure lays bare the Trickbot ransomware gang’s secrets, including the identity of a central member.
  15. US and UK sanction 11 TrickBot and Conti cybercrime gang members www.bleepingcomputer.com The USA and the United Kingdom have sanctioned eleven Russian nationals associated with the TrickBot and Conti ransomware cybercrime operations.
  16. www.justice.gov
  17. Germany doxxes Conti ransomware and TrickBot ring leader www.bleepingcomputer.com The Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) claims that Stern, the leader of the Trickbot and Conti cybercrime gangs, is a 36-year-old Russian named Vitaly Nikolaevich Kovalev.

Guides related to this story

← Back to all news