Ukrainian Conti Ransomware Member Gets 4 Years in US Prison

Ukrainian Conti Ransomware Member Gets Four Years in US Prison

Ukrainian national Oleksii Lytvynenko gets four years in US prison for his role in the Conti ransomware operation, which targeted over 1,000 victims.

Listen to this article

0:00

Press play to start listening

A Ukrainian citizen, Oleksii Oleksiyovych Lytvynenko, 44, has been sentenced to four years in prison by a US federal court for his involvement in the Conti ransomware operation.

Lytvynenko, formerly of Cork, Ireland, had pleaded guilty to conspiracy to commit wire fraud in June. The Department of Justice (DOJ) announced the sentence on September 10.

The operation impacted over 1,000 victims across 47 US states, Washington, D.C., Puerto Rico, and 31 foreign countries between 2020 and 2022. One of the group’s attacks, in December 2021, targeted Nordic Choice Hotels and caused system disruptions that forced guests out of their rooms.

Hotel claims Conti ransomware attack on system as guests locked out
Hotel screens following the Conti ransomware attack

The FBI reports that Conti targeted more critical infrastructure victims than any other ransomware variant in 2021, including healthcare and first-responder networks.

The agency estimated that victim payouts associated with Conti had exceeded $150 million as of January 2022. Lytvynenko, on the other hand, conspired with others to deploy Conti ransomware to extort victims and steal their data. He also helped develop tools used by the operation.

Lytvynenko’s Role and Conti’s Shutdown

Lytvynenko personally harmed at least 12 companies during his involvement with the operation, the DOJ’s press release revealed. Evidence recovered from his online accounts also showed that he possessed stolen data from eight US victims and four overseas victims.

He was also directed to work on coding a ‘loader,’ which the DOJ described as malware used to load programs needed for other malicious attacks.

The DOJ said Lytvynenko’s involvement in the Conti conspiracy continued until about June 2022, when the ransomware operation was winding down. Within a month, the group’s websites used to publish stolen victim data and negotiate ransom payments also went offline.

Forensic evidence recovered when Irish authorities arrested Lytvynenko in County Cork in July 2023 showed that he remained involved in ransomware activity after Conti had shut down. He was later extradited to the United States.

FBI Cyber Division Assistant Director Brett Leatherman said Lytvynenko and his co-conspirators used Conti ransomware to attack computers and networks in nearly every US state, adding that the sentence reflects the “gravity and extent” of their crimes.

Authorities Continue to Pursue Conti Operators

The case brought together investigators in the US and Ireland. FBI offices in San Diego, Nashville, and El Paso investigated the case with the US Secret Service and Homeland Security Investigations. The Garda National Cyber Crime Bureau and other Irish authorities helped with Lytvynenko’s arrest and extradition to the United States.

In September 2023, US prosecutors unsealed an indictment charging four other alleged Conti conspirators. Lytvynenko’s sentencing is the latest US prosecution connected to the ransomware operation, even though Conti itself shut down in 2022.

The court has not yet determined how much restitution Lytvynenko must pay, with a restitution hearing scheduled for November 16, 2026.

Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts