US Court Sentences Conti Ransomware Coder to Four Years
Security / news
US Court Sentences Conti Ransomware Coder to Four Years
Oleksii Lytvynenko said he coded a loader for Conti, which the FBI says had drawn more than $150 million in ransom payouts by January 2022.
A federal court in the Middle District of Tennessee sentenced Oleksii Lytvynenko, a 44-year-old Ukrainian national, to four years in prison on Sept. 10 for conspiracy to commit wire fraud tied to the Conti ransomware operation, the Justice Department said.
Lytvynenko pleaded guilty on June 10 to a single count of conspiracy to commit wire fraud, a charge that carries a statutory maximum of 20 years, according to SecurityWeek. He received a fifth of that.
Conti operated from 2020 to 2022, attacking computers and networks in 47 U.S. states, the District of Columbia, Puerto Rico and 31 other countries, the department said. The FBI estimated in January 2022 that ransom payouts tied to Conti had already exceeded $150 million; the group is believed to have infected more than 1,000 victims in total.
Lytvynenko joined the conspiracy in September 2021, according to SecurityWeek. In his plea, he said he had been directed to code a "loader," a piece of malware used to launch other attacks once a network was compromised. Prosecutors said he personally harmed at least 12 companies and held stolen data from eight victims in the United States and four overseas. Forensic evidence showed he stayed involved in ransomware attacks after Conti's core operation wound down in 2022, continuing until his arrest in County Cork, Ireland, in July 2023.
The department's account does not say whether Lytvynenko's loader was used in every one of the 12 intrusions attributed to him, only that he built the tool the group relied on to get a second stage of malware running once initial access was gained.
What the department said about the sentence
"Today's sentence reflects the seriousness of ransomware and the Department's commitment to protecting America's hospitals, schools, businesses, and local governments," said Assistant Attorney General A. Tysen Duva. Assistant Director Brett Leatherman of the FBI's Cyber Division said ransomware operators "should know they are not anonymous" regardless of where they are based.
Getting Lytvynenko into a U.S. courtroom took two years. He was extradited from Ireland in late 2025, more than two years after his arrest, with help the department credited to Ireland's Garda National Cyber Crime Bureau, the Irish Office of the Attorney General and the department's own Office of International Affairs.
A slower clock than the exploitation itself
The case is a reminder of how far behind an indictment trails an intrusion. Ransomware crews still move fast on freshly disclosed flaws, including Adobe's actively exploited Commerce zero-day and the batch of bugs CISA logged in its September Patch Tuesday roundup; Lytvynenko's case took roughly four years to move from Conti's peak activity to a courtroom sentence.
| Conti, by the numbers | Figure |
|---|---|
| Victims worldwide | More than 1,000 |
| U.S. states affected | 47 |
| Foreign countries affected | 31 |
| Ransom payouts (as of Jan. 2022) | Over $150 million |
| Lytvynenko's sentence vs. statutory maximum | 4 years of 20 |
The Justice Department did not say whether other members of the conspiracy Lytvynenko named in his plea remain at large. No further hearings were listed in Thursday's release.
Sources
More in Security
- 01Cisco and Acronis Share a CISA Deadline, Not a Severity ScoreOne flaw needs no password and no user interaction, the other needs an attacker already logged in, and CISA gave federal agencies the same three days to fix both.
- 02Bransys ELD App Shipped With Hardcoded Login CredentialsCISA disclosed three flaws Sept. 17 in the trucking compliance app, including a hardcoded password a researcher says exposed live location and engine data from every connected truck on a subset of fleets.
- 03MikroTik Patches RouterOS Flaws Attackers Exploited FirstPoland's national CERT says attackers began exploiting the chained flaws on Sept. 2, a day before MikroTik shipped a fix, and more than 122,500 routers were still reachable a week later.
- 04Attackers Exploit a JFrog Artifactory Bug in Four DayswatchTowr says attackers began minting administrator tokens by abusing a default empty join key, CVE-2026-82329, within days of JFrog's own patch shipping.