Sun 13 Sep 2026 / 13:38 ET
Kernel
Security 3 min read

Oleksii Lytvynenko gets four-year U.S. sentence over Conti role

A Ukrainian national received four years for wire-fraud conspiracy after admitting he held stolen Conti data and coded malware.

Mara Chen-Doyle

By Mara Chen-Doyle / Staff Writer

Oleksii Lytvynenko gets four-year U.S. sentence over Conti role
img: The Record

Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national formerly of Cork, Ireland, received a four-year U.S. prison sentence on Sept. 10 for wire-fraud conspiracy tied to the Conti ransomware operation. The Justice Department announced the oleksii lytvynenko conti sentence after he pleaded guilty in June.

The case puts a specific individual conviction beside the far broader damage attributed to Conti. Lytvynenko was sentenced for conspiracy to commit wire fraud, rather than for every attack associated with the ransomware group.

According to the Justice Department, Lytvynenko admitted possessing data stolen from eight U.S. victims and four victims overseas. He also admitted joining a team run by a Conti conspirator and being directed to code a malware loader.

A loader is malicious software used to load programs needed to carry out other attacks, the department said. The evidence cited by prosecutors also included forensic artifacts recovered when Lytvynenko was arrested that indicated ongoing ransomware activity.

What did Oleksii Lytvynenko admit to doing for Conti?

In his June 10 guilty plea, Lytvynenko admitted to the wire-fraud conspiracy, possession of stolen victim data and work on the loader. Assistant Attorney General A. Tysen Duva said the Justice Department viewed him as both an intruder and a developer who personally harmed at least 12 companies, though that characterization is the department's account of his role.

Lytvynenko had faced computer-fraud conspiracy and wire-fraud conspiracy charges after arriving in the United States. The final conviction was for wire-fraud conspiracy. BankInfoSecurity reported that prosecutors dismissed the separate computer-fraud conspiracy charge under the plea agreement.

How large was the Conti ransomware campaign?

From 2020 through 2022, Conti was used against computers and networks in 47 U.S. states, Washington, D.C., Puerto Rico and 31 countries, according to the Justice Department. The FBI estimated that associated victim payments had exceeded $150 million by January 2022.

Court filings summarized by the department said Conti conspirators broke into systems, encrypted data and sought ransom payments to restore file access and prevent disclosure of stolen material. The Justice Department said the campaign affected more than 1,000 victims worldwide, figures that describe Conti as a whole and not losses assigned to Lytvynenko alone.

How did Lytvynenko reach a U.S. court?

Irish national police arrested Lytvynenko in County Cork in July 2023 at the request of U.S. authorities. An Irish court detained him during extradition proceedings, which concluded in October 2025, the Justice Department said. He then made an initial appearance in the Middle District of Tennessee, pleaded guilty in June 2026 and was sentenced three months later.

The FBI field offices in San Diego, Nashville and El Paso, along with the U.S. Secret Service, investigated the case. Homeland Security Investigations' New York field office assisted, while Irish justice agencies, the Office of the Attorney General and the Garda National Cyber Crime Bureau helped secure the arrest and extradition, according to the Justice Department.

This story draws on original reporting from The Record.

More Security/

view all ↗