News

Conti ransomware developer gets 4 years in US prison

The Justice Department on 10 September 2026 said Oleksii Lytvynenko, 44, was sentenced to four years for wire fraud conspiracy tied to Conti. Evidence showed he held stolen data from eight U.S. victims and four overseas, and coded a loader.

Conti ransomware developer gets 4 years in US prison

The U.S. Department of Justice, in a 10 September 2026 Office of Public Affairs release, said Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national formerly of Cork, Ireland, was sentenced to four years in prison for conspiracy to commit wire fraud tied to Conti ransomware.

This is an official DOJ sentencing press release. It is not a new Conti campaign, not a CISA Known Exploited Vulnerabilities listing, and not a fresh indictment unsealing.

DOJ said Conti infected computers of more than 1,000 victims worldwide. Attacks spanned 47 U.S. states, 31 foreign countries, the District of Columbia, and Puerto Rico in the 2020 to 2022 window in the department's narrative. The FBI estimated victim payouts associated with Conti exceeded $150,000,000 as of January 2022.

Lytvynenko pleaded guilty to wire fraud conspiracy on 10 June. Evidence showed he possessed data stolen from eight U.S. victims and four overseas victims. He admitted joining a Conti team and being directed to code a "loader" malware component.

He was arrested in July 2023 in County Cork, Ireland. Forensic artifacts, DOJ said, showed ongoing ransomware involvement even after Conti wound down. Irish partners assisted the extradition.

The case was prosecuted in the Middle District of Tennessee by CCIPS and an assistant U.S. attorney. Separately, a September 2023 indictment charging four other Conti conspirators was unsealed there.

CyberScoop (Matt Kapko, 10 September 2026) reported the same sentencing and said prosecutors found him asleep within reach of an open laptop running Cobalt Strike. It said he was extradited to the United States in October 2025. Conti as a brand wound down around 2022. This sentence is four years on the count he pleaded to, not news of a fresh Conti wave.

Ransomware and intrusion context on Cyberpresso includes Anthropic's September 2026 threat report, Mantax Otax Android ransomware-spyware, PaperCut AI agents hitting 395 organizations, and IDScan's 150 million licenses breach.

If you still hold Conti-era logs or paid a Conti ransom, treat this as accountability for one developer's past membership and post-Conti work through arrest. Hunt successor crews rather than a revived Conti brand.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free