A Ukrainian national was sentenced to four years in prison for his role in a conspiracy to deploy the Conti ransomware variant, which infected the computers of more than 1,000 victims worldwide, the Justice Department announced.
Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, was sentenced for conspiracy to commit wire fraud in connection with the scheme, according to court documents. Prosecutors said Lytvynenko conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 to 2022, the ransomware was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia and Puerto Rico. The FBI estimated that victim payouts associated with Conti exceeded $150 million as of January 2022.
Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said the sentence reflects the seriousness of ransomware and the department’s commitment to protecting hospitals, schools, businesses and local governments. Duva said Lytvynenko joined the conspiracy as both an intruder and a developer, personally harming at least 12 companies, storing stolen victim data and helping build tools used in the extortion scheme. Duva added that Lytvynenko continued engaging in ransomware operations after the Conti conspiracy ended and until his arrest.
U.S. Attorney Braden H. Boucek for the Middle District of Tennessee said the sentence shows cybercriminals cannot hide behind borders or a keyboard to escape justice, crediting law enforcement and international partners. FBI Cyber Division Assistant Director Brett Leatherman said ransomware criminals operating overseas are not beyond the reach of consequences. U.S. Secret Service Assistant Director Brent Daniels said the sentence provides a measure of justice for victims whose data, operations and livelihoods were put at risk.
Lytvynenko pleaded guilty to wire fraud conspiracy on June 10. Evidence recovered from his online accounts showed that he possessed data stolen from eight U.S. victims and four overseas victims. He admitted joining a team run by a Conti conspirator, where he was directed to code a “loader,” a type of malware typically used to load programs needed to carry out other malicious attacks. Forensic artifacts recovered at the time of his arrest in County Cork in July 2023 further demonstrated his ongoing involvement in ransomware activity.
In September 2023, an indictment charging four other Conti conspirators was unsealed in the Middle District of Tennessee, according to the Justice Department.
The FBI’s San Diego, Nashville and El Paso field offices and the U.S. Secret Service are investigating the case, with assistance from Homeland Security Investigations’ New York field office. The case is being prosecuted by the Justice Department’s Computer Crime and Intellectual Property Section and the U.S. Attorney’s Office for the Middle District of Tennessee. The Justice Department’s Office of International Affairs and Irish law enforcement and government authorities assisted in securing Lytvynenko’s arrest and extradition.
This article was constructed with the assistance of artificial intelligence and published by a member of The Washington Times' AI News Desk team. The contents of this report are based solely on The Washington Times' original reporting, wire services, and/or other sources cited within the report. For more information, please read our AI policy or contact Steve Fink, Director of Artificial Intelligence, at sfink@washingtontimes.com
The Washington Times AI Ethics Newsroom Committee can be reached at aispotlight@washingtontimes.com.

Please read our comment policy before commenting.