Conti ransomware operator sentenced to 4 years in jail for playing part in a $150M extortion campaign
The Conti ransomware extortion group may be gone, but justice has finally caught up with one of its members.

Image by Cybernews.
- Oleksii Lytvynenko was sentenced to four years in prison after pleading guilty in a US court.
- Prosecutors said he helped steal victim data and build tools for the Conti extortion group.
- Conti hit hospitals, schools, businesses, and governments in 31 countries between 2020 and 2022.
- The FBI estimates Conti victims paid more than $150 million in ransom demands.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A Ukrainian man has to spend the next four years in prison for participating in a global ransomware operation.
According to the US Department of Justice, 44-year-old Oleksii Lytvynenko joined the ransomware extortion group Conti as a hacker and developer.
The Justice Department alleges that he harmed at least 12 companies by stealing data from victims and helping to build business extortion tools.
Even when the Conti group disassembled in 2022, Lytvynenko continued to participate in ransomware operations until his arrest in July 2023.
At that time, the Ukrainian national lived in Cork, Ireland. There, he spent several years in prison while fighting extradition to the US.
On June 10th, 2026, Lytvynenko pleaded guilty to wire fraud conspiracy and deployment of Conti ransomware. He was sentenced to four years in prison.
“For years, the Conti ransomware group executed a sustained and sophisticated campaign that victimized hundreds of organizations across the United States and abroad, including critical infrastructure entities, causing losses in the millions of dollars,” Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said in a statement.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“Cybercriminals who build, deploy, or profit from malware like Conti will face justice and meaningful consequences in US courts,” he continued.
Conti was once one of the most feared and prolific ransomware extortion operations.
From 2020 to 2022, Conti’s malware was used to attack computers and networks of hospitals, schools, businesses, and local governments worldwide. Security researchers have identified at least 859 victims in 31 countries.
The FBI estimates that Conti victims have paid over $150 million in ransom demands.
It all went south when Conti publicly supported Russia’s invasion of Ukraine, as some members of the extortion group were opposed to it. They moved on to smaller ransomware extortion groups, such as BlackCat/ALPHV and Hive, as Conti began dismantling its infrastructure.
The once-dreaded ransomware empire crumbled when internal documents, Conti’s malware source code, technical manuals and tools, and details about its infrastructure were made public by someone called ContiLeaks.