TTO-2026-0912-120 · September 12, 2026 Law EnforcementSentencing

Conti Ransomware Developer Sentenced to Four Years — Operation Struck 1,000 Victims, Extracted $150 Million

DOJ confirmedOleksii Lytvynenko4 years prisonWire fraud conspiracy1,000+ victims$150M+ in ransoms47 US states and 31 countries

Summary

Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national previously residing in Cork, Ireland, was sentenced on September 10, 2026 to four years in federal prison for conspiracy to commit wire fraud in connection with the Conti ransomware operation. The Department of Justice confirmed the sentencing, citing Conti's record of attacking more than 1,000 victim organizations in 47 U.S. states, the District of Columbia, Puerto Rico, and 31 foreign countries between 2020 and 2022, generating at least $150 million in ransom payments. Lytvynenko was arrested in Ireland in July 2023 and extradited to the United States in October 2025. He pleaded guilty in June 2026.

Timeline

DateEvent
2020-2022Conti ransomware operation active; Lytvynenko joins in September 2021 as loader developer and intruder
May 2022Conti operation effectively shuts down following internal leak of chat logs and source code
July 2023Lytvynenko arrested in County Cork, Ireland; forensic artifacts link him to ransomware activity continuing after Conti's shutdown
October 2025Lytvynenko extradited to the United States
June 15, 2026Lytvynenko pleads guilty to wire fraud conspiracy in U.S. District Court
Sep 10, 2026Lytvynenko sentenced to four years in federal prison

What He Did

Lytvynenko joined the Conti operation as both an intruder and a developer. He coded a malware loader — a component that installs or launches additional malicious programs on compromised systems, enabling ransomware deployment, remote-access tool staging, persistence, and lateral movement across enterprise networks. He personally compromised at least 12 victim organizations, including eight in the United States, and possessed data stolen from those victims.

Conti operated as a ransomware-as-a-service syndicate with distinct functional teams: core operators and developers, initial-access brokers, affiliates conducting intrusions, and money-laundering participants. The structure made the operation resilient. U.S. investigators estimated at least $150 million in ransoms paid to the group by early 2022; the true financial damage including recovery costs, business disruption, and data theft is believed to be substantially higher. Conti targeted hospitals, schools, local governments, and critical infrastructure, including an attack that disrupted the Costa Rican government in 2022.

Lytvynenko's sentencing is the latest in a series of Conti-linked prosecutions. A separate Latvian national linked to former Conti members was sentenced to 102 months in May 2026 for attacks on more than 54 organizations. Both cases reflect continued DOJ pursuit of Conti participants through international extradition more than four years after the group's shutdown.

Note on Domain Intelligence

This bulletin documents a law enforcement outcome rather than an active breach or vulnerability. No domain intelligence score is published in this bulletin. The Conti operation did not operate a public domain; its victims spanned thousands of organizations across dozens of sectors. WarmBadge domain intelligence for specific victim organizations is available at warmbadge.com.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 12, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026