A Conti ransomware developer has been sentenced to four years in a US prison for his role in attacks against organisations in the United States and elsewhere. Ukrainian national Oleksii Oleksiyovych Lytvynenko admitted developing malware, participating in intrusions and holding data stolen from multiple victims.
Conti ransomware developer receives four-year sentence
Lytvynenko, 44, was sentenced on 10 September 2026 following his extradition from Ireland to the United States. He was convicted of conspiracy to commit wire fraud in connection with his participation in Conti ransomware operations.
Also known as Alexsey Alexseevich Litvinenko, he pleaded guilty in June 2026. As part of that plea, Lytvynenko admitted joining the cybercrime group in September 2021 and personally harming at least 12 companies.
Eight of those victims were based in the United States. His admitted activities included developing malicious software and storing data stolen from victim networks, giving the wider operation material it could use to support ransom demands and threaten disclosure.
The US Department of Justice described Lytvynenko as both an intruder and a developer. This meant his role extended beyond writing software: he also participated directly in unauthorised access to victim environments and retained information obtained during those compromises.
Tennessee victims paid approximately $634,000
Prosecutors said Lytvynenko and his co-conspirators extorted approximately $634,000 in Bitcoin from two victims in Tennessee. One was an undisclosed government entity, where the intrusion resulted in the compromise of a sheriff’s department, local emergency medical services and a local police department.
The case also involved another Tennessee-based organisation that refused to meet a $3 million ransom demand. In response, the conspirators leaked data stolen from that victim, demonstrating the combination of encryption or disruption with data theft and public exposure that made Conti ransomware attacks particularly damaging.
The available court reporting does not identify the affected organisations or provide details about the specific malware versions used against them. It does, however, establish the main elements of the operation: network intrusion, malicious tool development, theft and storage of data, cryptocurrency demands and publication of information when a victim would not pay.
Arrest, extradition and prosecution timeline
Lytvynenko was arrested in Ireland in July 2023 while living there under temporary protective status. Authorities said he was asleep when officers arrived, but was within arm’s reach of an open laptop running Cobalt Strike.
Cobalt Strike is a security testing platform that can also be misused during criminal intrusions. The source reporting does not identify its version or establish every activity being performed through the laptop, but its presence was specifically recorded by the authorities at the time of arrest.
Lytvynenko remained in Ireland until his extradition to the United States in October 2025. An indictment connected to his case was unsealed in 2025, exposing further details about the Tennessee incidents and the alleged actions of the wider conspiracy.
The central stages of the case were:
- Lytvynenko joined the Conti ransomware operation in September 2021.
- Conti formally disbanded during 2022, although Lytvynenko continued active ransomware activity until his arrest.
- Irish authorities arrested him in July 2023.
- He was extradited to the United States in October 2025.
- He pleaded guilty to conspiracy to commit wire fraud in June 2026.
- A US court sentenced him to four years in prison on 10 September 2026.
The Justice Department stressed that his ransomware activity continued after the Conti conspiracy had ended. This is significant because the closure of a named operation does not necessarily mean that its developers, intruders and affiliates have stopped working. Individuals can continue using their expertise and tools through other ransomware operations.
How the Conti ransomware operation caused harm
Conti attacked more than 1,000 organisations around the world before disbanding in 2022. Its victims included critical infrastructure providers and government bodies, with the government of Costa Rica among the prominent organisations affected during that year.
The group operated a sustained extortion model. Participants gained access to networks, deployed malicious tools, removed valuable data and used the threat of operational disruption or data publication to pressure victims into paying cryptocurrency ransoms.
Lytvynenko’s possession of information from 12 victims illustrates the role that stolen data played in this process. Retaining copies allowed the conspirators to maintain leverage even where an organisation restored systems or refused to negotiate. The Tennessee data leak shows that publication threats could be carried out when a demand was rejected.
Conti remained resilient even after internal communications between its members were leaked in 2022. The operation rebuilt infrastructure and continued selecting targets before eventually abandoning the Conti name later that year.
The scale and impact of its campaigns prompted the US State Department to offer a reward of up to $10 million for information concerning the group’s leaders. Four other alleged co-conspirators, Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev and Andrey Yuryevich Zhuykov, were indicted in 2023 for suspected involvement in Conti attacks conducted from 2020 to 2022.
Current exploitation status
Conti ransomware is no longer presented as an active branded group in the source reporting. However, US prosecutors said Lytvynenko remained involved in active ransomware operations until his July 2023 arrest, after Conti itself had disbanded.
The sentence therefore reflects both historic Conti activity and the persistence of personnel after a criminal brand disappears. The public information does not attribute a current ransomware operation to Lytvynenko, who is now in US custody, or establish that the original Conti organisation has resumed operations.
What organisations should take from the case
Organisations should avoid treating the retirement of a ransomware name as confirmation that the underlying threat has ended. Security teams should continue monitoring for techniques associated with data theft, unauthorised remote access and extortion, even when attackers adopt different identities.
This case also highlights the need to investigate legitimate administration and security tools when their use is unexpected. Cobalt Strike should be tightly controlled, with its execution and network activity reviewed where it has no authorised business purpose.
Incident response plans should account for stolen information as well as system recovery. The Tennessee victim that rejected the $3 million demand still faced disclosure of its data, showing why organisations need to determine what was accessed, preserve evidence and prepare for regulatory and stakeholder communications.
Originally reported by cyberscoop.com.







