LmCast :: Stay tuned in

Conti ransomware gang member sentenced to 4 years in prison

Recorded: Sept. 11, 2026, 7 a.m.

Original Summarized

Conti ransomware gang member sentenced to 4 years in prison

News

Featured
Latest

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Over 36,000 exposed Plex servers vulnerable to recent flaws

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Conti ransomware gang member sentenced to 4 years in prison

New Android malware encrypts files, steals data, and harasses victims

September Windows Server updates break Remote Desktop Services

Surfshark VPN says hackers breached internal testing, proxy servers

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecurityConti ransomware gang member sentenced to 4 years in prison

Conti ransomware gang member sentenced to 4 years in prison

By Sergiu Gatlan

September 11, 2026
02:48 AM
0

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.
44-year-old Oleksii Oleksiyovych Lytvynenko was arrested by the Irish national police (An Garda Síochána) in July 2023 at the request of the United States and was extradited last year.
Lytvynenko and his Conti accomplices deployed ransomware on victim networks in the United States and abroad, stealing data and encrypting devices to extort Bitcoin ransom payments.
"From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000," the Department of Justice said on Thursday.
"Lytvynenko joined that conspiracy as both an intruder and a developer — personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities," added Assistant Attorney General A. Tysen Duva.
The defendant pleaded guilty to conspiracy to commit wire fraud in June 2026 and was facing a maximum sentence of 20 years in prison.
He admitted to joining the Conti ransomware operation in September 2021, controlling the stolen data of eight U.S. victims and four overseas victims, and sending ransom notes as part of the cybercrime gang's double extortion attacks between 2020 and June 2022.
Lytvynenko also admitted to joining a team run by another Conti conspirator, where he coded a "loader," which is a type of malware designed to load the software needed to carry out attacks.
Conti ransomware gang
The Conti ransomware operation emerged from the Ryuk cybercrime group in 2020 with close ties to the TrickBot malware gang, and became notorious for large-scale attacks against healthcare organizations, governments, and enterprises.
Conti evolved into a cybercrime syndicate that controlled multiple malware operations, including BazarBackdoor and TrickBot, and it shut down two years later, in 2022, after increased law enforcement pressure and leaked internal chats.
The Conti gang later split into other ransomware groups, including BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.
Seven TrickBot/Conti members were sanctioned in February 2023, after a massive leak of personal information and internal conversations belonging to Conti and TrickBot members, known as the ContiLeaks and TrickLeaks.
In September 2023, the U.S. and the United Kingdom also sanctioned and charged nine Russian nationals associated with Conti and TrickBot for attacks against over 900 victims worldwide, while the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) doxed the leader of the TrickBot and Conti cybercrime gangs in May 2025, claiming he is a 36-year-old Russian named Vitaly Nikolaevich Kovalev using the alias "Stern."
According to court documents, the Conti cybercrime gang has targeted more than 1,000 victims worldwide and collected over $150 million in ransom payments while active.

Build your security blueprint for AI-powered attacks

Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.
Save your seat

Related Articles:
Man gets six years for hacking 750 women's Snapchat accountsBerlin confirms data theft after Rhysida ransomware attack claimsATF confirms “major incident” after recent Qilin breach claimsCISA: Medusa ransomware hit over 500 critical infrastructure orgsData analyst sent to prison for stealing data, extorting employer

Conti
Data Theft
Ransomware
Ukraine
USA

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

Over 36,000 exposed Plex servers vulnerable to recent flaws

Sponsor Posts

Overdue a password health-check? Audit your Active Directory for free

EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain

Find your gaps before an auditor does. Check your EU CRA readiness in 5 questions. 

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

A Ukrainian national, Oleksii Oleksiyovych Lytvynenko, has been sentenced to four years in prison for his involvement in the Conti ransomware attacks spanning the period from 2021 to 2022. Lytvynenko was arrested by the Irish national police in July 2023 at the request of the United States and subsequently extradited. His actions as part of the Conti conspiracy involved deploying ransomware against victim networks in the United States and abroad, which included stealing data and encrypting devices to extort Bitcoin ransom payments. The Department of Justice estimated that during this period, Conti ransomware operations attacked computers and networks across 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. Furthermore, the Department of Justice reported that victim payouts associated with Conti ransomware exceeded $150,000,000 as of January 2022.

Lytvynenko admitted to joining the Conti ransomware operation in September 2021. In this capacity, he was involved both as an intruder and a developer, personally causing harm to at least twelve companies by storing stolen victim data and assisting in the development of malicious tools utilized by Conti for extortion and threats. He confessed to participating in double extortion attacks between 2020 and June 2022, specifically admitting to controlling the stolen data of eight U.S. victims and four overseas victims while sending ransom notes. He also admitted to joining a team led by another Conti conspirator where he coded a loader, a type of malware designed to facilitate attacks by loading necessary software.

The Conti ransomware operation itself originated from the Ryuk cybercrime group in 2020 and developed close ties with the TrickBot malware gang. It became infamous for conducting large-scale attacks targeting healthcare organizations, governments, and enterprises. Over time, Conti evolved into a broader cybercrime syndicate that managed multiple malware operations, including BazarBackdoor and TrickBot. Following increased law enforcement pressure and the public release of internal communications, the Conti group dismantled itself in 2022, subsequently splintering into various ransomware groups such as BlackCat, Black Basta, ZEON, Hive, Quantum, BlackByte, Karakurt, and the Silent Ransom Group.

The notoriety of the Conti and TrickBot operations became part of a larger international effort against cybercrime. In February 2023, seven members associated with both TrickBot and Conti were sanctioned following a significant leak of personal information and internal conversations known as the ContiLeaks and TrickLeaks. Additionally, in September 2023, the United States and the United Kingdom placed sanctions and charges against nine Russian nationals linked to Conti and TrickBot for attacks against over 900 global victims. Further evidence of the operation's leadership emerged in May 2025 when the Federal Criminal Police Office of Germany (Bundeskriminalamt or BKA) publicly doxed the leader of the TrickBot and Conti cybercrime gangs, identifying him as a 36-year-old Russian named Vitaly Nikolaevich Kovalev under the alias "Stern." Overall, court documents indicate that the Conti cybercrime gang targeted more than one thousand victims worldwide and successfully collected over $150 million in ransom payments while operational.