A federal court sentenced Oleksii Lytvynenko, a 44-year-old Ukrainian national and member of the Conti ransomware group, to four years in prison for his role in attacks on at least 12 organizations, including US healthcare and emergency services providers.

 

What happened

The Department of Justice announced the sentencing on Thursday, September 10, 2026. Lytvynenko, who also went by Alexsey Alexseevich Litvinenko, pleaded guilty in June to conspiracy to commit wire fraud. He joined Conti in September 2021, where he developed malware and stored stolen data from 12 victims, eight of them based in the United States. Authorities arrested him in Ireland in July 2023, where he was living with temporary protective status. The US extradited him in October 2025. Prosecutors say Lytvynenko and his co-conspirators extorted roughly $634,000 in Bitcoin from two victims in Tennessee, one of which was a government entity whose compromise affected a sheriff's department, local emergency medical services, and a local police department.

 

Going deeper

An unsealed indictment detailed additional conduct, after a separate Tennessee-based victim refused to pay a $3 million ransom demand, Lytvynenko and his co-conspirators leaked the data they had stolen from that organization. The Justice Department also states that Lytvynenko kept working in active ransomware operations even after the original Conti conspiracy ended, continuing until his arrest in 2023.

 

What was said

A. Tysen Duva, assistant attorney general of the Justice Department's criminal division, said Conti "executed a sustained and sophisticated campaign that victimized hundreds of organizations across the United States and abroad, including critical infrastructure entities, causing losses in the millions of dollars." Duva added that Lytvynenko "joined that conspiracy as both an intruder and a developer - personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities," and that he "continued engaging in active ransomware operations" after Conti ended.

Brett Leatherman, assistant director of the FBI's cyber division, said Lytvynenko and his co-conspirators "used Conti ransomware to attack computers and networks in nearly every state, and today's sentence reflects the gravity and extent of those crimes." He added that "ransomware criminals should know they are not anonymous and operating from overseas does not mean operating without consequences."

 

In the know

Conti operated as a ransomware-as-a-service group that used double extortion, attackers first stole a victim's data, then encrypted its systems, pressuring the victim to pay to both regain access and prevent the stolen data from being published. Cobalt Strike, the tool found running on Lytvynenko's laptop at his arrest, is a legitimate penetration-testing platform that ransomware operators frequently misuse to move through a compromised network after gaining initial access.

 

Why it matters

One of the Tennessee attacks tied to Lytvynenko compromised a sheriff's department, local EMS, and a local police department at the same time, the kind of attack that can disrupt 911 dispatch and emergency response alongside records systems. Conti's US healthcare targeting wasn't limited to back-office systems, the group was also tied to the 2021 ransomware attack on Scripps Health, a San Diego-based system operating five hospitals. The FBI's San Diego, Nashville, and El Paso field offices, along with the US Secret Service, investigated the Lytvynenko case, which included that 2021 Scripps Health attack. Even though Conti disbanded in 2022, this sentencing shows US prosecutors are still pursuing individual members years later, and that rebranded successor groups inherited Conti's tactics.

 

The bottom line

A four-year sentence for one Conti developer won't undo the damage the group caused, but it shows that extradition and prosecution remain risks for ransomware operators, no matter where they're based. For healthcare organizations, the case is a reminder that ransomware crews don't need to be active today to still be relevant, former Conti members and their rebranded successor groups continue to pose a threat, and HIPAA-covered entities should keep treating ransomware readiness, from backups to incident response plans, as a priority.

Related: HIPAA Compliant Email: The Definitive Guide

 

FAQs

What is ransomware-as-a-service?

It's a business model where ransomware developers lease or sell their malware and infrastructure to other criminals in exchange for a cut of the ransom proceeds.

 

Why do ransomware groups rebrand instead of disappearing?

Rebranding lets members dodge law enforcement pressure tied to the old brand, and keep operating under a new identity with much of the same infrastructure and tactics.

 

How does extradition work when a suspect is arrested outside the US?

Extradition depends on treaties and cooperation between the country holding the suspect and the country requesting them, and it can take months or years to complete.