Oleksii Oleksiyovych Lytvynenko, 44, was sentenced on Thursday by a US federal court after pleading guilty in June 2026 to conspiracy to commit wire fraud. He faced a maximum of 20 years.
According to the Department of Justice, Lytvynenko joined the Conti conspiracy as both an intruder and a developer. He personally harmed at least 12 companies, stored stolen data from victims, and helped build malicious tools used by the gang.
Lytvynenko admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight US victims and four overseas victims, and sending ransom notes as part of double extortion attacks. He also admitted to coding a "loader" — a type of malware designed to load software needed to carry out attacks — as part of a team run by another Conti conspirator.
Conti emerged from the Ryuk cybercrime group in 2020 and had close ties to the TrickBot malware gang. It became notorious for large-scale attacks against healthcare organizations, governments, and enterprises. The operation shut down in 2022 after increased law enforcement pressure and leaked internal chats.
Lytvynenko was arrested by Irish national police in July 2023 at the request of the United States and was extradited last year.