Ukrainian Conti Ransomware Member Gets Four Years for Extorting 12 Companies
Oleksii Lytvynenko admitted joining the gang in 2021, coding a malware loader, and holding stolen data from a dozen victims for ransom.

Key points
- Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced this week to four years in a US federal prison for his role in the Conti ransomware gang.
- He admitted joining Conti in September 2021 and personally harming at least 12 companies, eight in the US and four abroad.
- The FBI estimates Conti victims paid out more than $150 million by January 2022, hitting targets in 47 US states and 31 countries.
- Lytvynenko was arrested in Ireland by An Garda Síochána in July 2023 and extradited to the US last year.
- Conti shut down in 2022 after its internal chats leaked, but its members regrouped into gangs including Black Basta, BlackCat, and Karakurt.
A US federal court has sentenced a Ukrainian man to four years in prison for helping run one of the most damaging ransomware operations of the last decade.
Oleksii Oleksiyovych Lytvynenko, 44, admitted joining the Conti gang in September 2021. Ransomware is malicious software that locks a company's files until a payment is made, usually in Bitcoin. Conti went a step further and stole the files first, then threatened to publish them if the victim refused to pay. Security researchers call that tactic double extortion.
Lytvynenko pleaded guilty to conspiracy to commit wire fraud earlier this year. He faced up to 20 years.
What did he actually do?
He worked as both a break-in specialist and a developer inside Conti, according to the US Department of Justice. Prosecutors say he personally harmed at least 12 companies, held onto stolen files from eight US victims and four foreign ones, and sent the ransom notes demanding payment.
He also wrote code for a "loader", a small piece of malware whose only job is to quietly pull down the bigger attack tools onto a victim's computer once the criminals are inside.
Assistant Attorney General A. Tysen Duva said Lytvynenko joined the conspiracy "as both an intruder and a developer," helping build the tools Conti used to "extort and threaten communities."
How big was Conti?
Enormous. The FBI estimates Conti victims had paid more than $150 million in ransoms by January 2022. Court documents put the total victim count above 1,000 worldwide.
| Fact | Figure |
|---|---|
| US states hit | 47 |
| Foreign countries hit | 31 |
| Total victims worldwide | 1,000+ |
| Ransom payments collected | $150 million+ |
| Lytvynenko's prison term | 4 years |
Conti grew out of the Ryuk crew in 2020 and worked closely with the TrickBot malware gang. It became notorious for attacks on hospitals, government agencies, and large companies. The group publicly backed Russia's invasion of Ukraine in early 2022, a decision that pushed an insider to leak the gang's internal chats. Those leaks, dubbed ContiLeaks, helped investigators put names to aliases.
Conti formally shut down later that year. Its members did not retire. They scattered into other ransomware brands including Black Basta, BlackCat, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group. Several of those gangs are still active.
Is anyone else being prosecuted?
Yes. In February 2023, the US and UK sanctioned seven TrickBot and Conti members. Another nine Russian nationals were sanctioned and charged in September 2023 over attacks on more than 900 victims. Germany's federal police, the Bundeskriminalamt, publicly named the alleged leader of TrickBot and Conti in May 2025 as 36-year-old Russian Vitaly Nikolaevich Kovalev, who used the alias "Stern."
The arrest was first reported in detail by BleepingComputer at the time of Lytvynenko's extradition.
What should affected businesses do?
If your organisation was hit by Conti between 2020 and 2022, assume the stolen files are still circulating. Notify affected staff and customers if you have not already. Regulators including the FTC in the US and the ICO in the UK still expect breach notifications for historical incidents where new evidence emerges. Rotate any credentials that were stored on compromised systems, even years later. Criminals sell old data sets for a long time.



