Oleksii Oleksiyovych Lytvynenko, a Ukrainian national alleged to be a key member of the Conti ransomware group, was extradited from Ireland to the United States to face charges related to his involvement in global ransomware attacks. U.S. authorities accuse Lytvynenko of participating in Conti's double extortion operations between 2020 and June 2022, controlling stolen data, sending ransom notes, and extorting millions in cryptocurrency from victims worldwide, including specific incidents in Tennessee. He was arrested in Cork, Ireland, in July 2023 by Irish police at the request of the U.S., and after lengthy extradition proceedings, appeared in a Tennessee court facing charges of computer fraud conspiracy and wire fraud conspiracy, with a potential sentence of up to 25 years if convicted.
The Conti ransomware group, which replaced the Ryuk operation in 2020, became one of the most prolific and aggressive ransomware syndicates, responsible for over 1,000 attacks in the U.S. and more than 30 countries, collecting approximately $150 million in ransom payments. The group targeted critical infrastructure and high-profile organizations, exploiting vulnerabilities such as Log4j and ProxyShell. After the group disbanded in 2022, its members, including Lytvynenko, allegedly continued cybercriminal activities. The U.S. Department of Justice and FBI have highlighted Conti's significant impact on global cybersecurity, with Lytvynenko's prosecution marking a major step in international law enforcement efforts against ransomware operators.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The U.S. Department of Justice announced that Lytvynenko was extradited from Ireland and made an initial appearance in the Middle District of Tennessee on the 2023 indictment. Prosecutors said he faces federal charges carrying a potential sentence of up to 25 years in prison.
The extradition process in Ireland concluded in October 2025, clearing the way for Lytvynenko to be transferred to U.S. custody. This ended his detention in Ireland pending the U.S. case.
In July 2023, An Garda Síochána arrested Lytvynenko in Ireland at the request of the United States. An Irish court then detained him pending extradition proceedings.
A 2023 U.S. indictment charged Oleksii Oleksiyovych Lytvynenko with conspiracy to commit computer fraud and conspiracy to commit wire fraud in connection with the Conti ransomware conspiracy. The indictment later formed the basis for his extradition and initial court appearance in Tennessee.
Court documents allege Lytvynenko conspired to deploy Conti ransomware, steal data, and extort victims from around 2020 through about June 2022. Prosecutors say this included more than $500,000 in cryptocurrency extorted from two victims in Tennessee.
As of January 2022, the FBI estimated Conti had attacked more than 1,000 victims worldwide and collected at least $150 million in ransom payments. The DOJ cited this as evidence of the operation's scale and impact.
By 2021, the FBI assessed Conti was used in more critical infrastructure attacks than any other ransomware variant. The group also exploited widely abused vulnerabilities such as Log4j and ProxyShell during its campaigns.
U.S. authorities say the Russian-based Conti ransomware operation began in 2020 and carried out intrusions, data theft, encryption, and double-extortion attacks against organizations globally. Prosecutors allege Oleksii Oleksiyovych Lytvynenko participated in this activity from around 2020.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcedatabreaches.net
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcehackread.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.