Ukrainian National Sentenced to Four Years for Role in Conti Ransomware Attacks

A federal judge in Tennessee has sentenced Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian national and former member of the Conti ransomware gang, to 48 months in prison. The sentencing, which took place on September 10, 2026, follows his guilty plea to conspiracy to commit wire fraud earlier this summer.

Lytvynenko, who previously resided in Cork, Ireland, served as both a developer and an “intruder” for the prolific cybercrime syndicate. His role was instrumental in attacks that paralyzed essential services in the United States, including a significant breach of a Tennessee local government entity. That specific attack impacted a sheriff’s department, police department, and emergency medical services (EMS), eventually resulting in an extortion payment of approximately $634,000 in Bitcoin.

The prosecution of Lytvynenko highlights the critical intersection between cybercrime and public safety infrastructure. While many ransomware affiliates specialize in either coding or the “boots-on-the-ground” infiltration, Lytvynenko’s dual role allowed him to bridge the gap between building malicious tools and deploying them against high-value targets.

Digital icons of emergency services protected by shields.
The attack targeted critical Tennessee infrastructure, including emergency medical services and local police departments.

According to the U.S. Department of Justice, Lytvynenko joined the Conti organization in September 2021. Even after the Conti group officially dissolved in early 2022 following a series of internal leaks, he continued to engage in independent ransomware operations. He remained active in the cybercrime ecosystem until his arrest by An Garda Síochána in Ireland in July 2023. Following a lengthy legal process, he was extradited to the Middle District of Tennessee in 2025 to face charges.

The Conti group was one of the most aggressive ransomware-as-a-service (RaaS) operations in history. Before its collapse, the FBI estimated that the group had extorted more than $150 million from over 1,000 victims worldwide. The gang was known for its “double extortion” tactics, where attackers not only encrypted files but also threatened to leak sensitive data unless a ransom was paid.

Abstract map showing digital connections between Europe and North America.
Lytvynenko was arrested in Ireland and extradited to the United States to face charges related to his work with Conti.

The prosecution of Lytvynenko serves as a signal to international cybercriminals that residency abroad does not offer permanent immunity from U.S. law enforcement.

The case also underscores the persistence of ransomware actors who frequently rebrand or continue their work as “lone wolves” after major syndicates collapse. Despite the formal end of the Conti brand, the technical expertise and infrastructure developed by members like Lytvynenko allowed them to maintain a threat to municipal and emergency services for years after the group’s initial peak.

More From Category

More Stories Today