A Ukrainian national has been sentenced to four years in U.S. prison for his role in the Conti ransomware operation, which affected more than 1,000 victims worldwide and generated at least $150 million in ransom payments. Oleksii Oleksiyovych Lytvynenko, 44, previously living in Cork, Ireland, was sentenced for conspiracy to commit wire fraud. U.S.

The group targeted corporate networks, healthcare providers, schools, local governments, and other critical infrastructure organizations. The actual financial damage was likely significantly higher, as the reported figure excluded ransom demands, recovery costs, incident-response expenses, business disruption, data theft, and reputational damage.

Lytvynenko admitted to joining a technical team managed by another Conti conspirator, where he contributed to coding a malware “loader,” a component used to install or launch additional malicious programs on compromised systems. Authorities revealed that forensic artifacts found during the arrest of Lytvynenko in County Cork, Ireland, in July 2023 indicated that he continued to engage in ransomware-related activities even after the original Conti operation concluded. This model made the operation resilient, enabling different participants to support reconnaissance, credential theft, lateral movement, data exfiltration, encryption, and extortion.

U.S. authorities emphasized that cybercriminals involved in building, deploying, or profiting from ransomware can face prosecution, even when operating outside the United States.