Ukrainian national Oleksii Oleksiyovych Lytvynenko pleaded guilty in U.S. federal court to conspiracy to commit wire fraud for his role in the Conti ransomware operation, one of the most prolific cybercrime campaigns tracked by U.S. authorities. Prosecutors said Lytvynenko joined Conti by September 2021, helped develop a malware loader used to gain initial access to victim networks, and possessed data stolen from 12 victims, including eight in the United States. He was arrested in Ireland in July 2023, extradited to the United States in October 2025, and now faces up to 20 years in prison, with sentencing scheduled for September 2026.
The Justice Department said Conti targeted more than 1,000 victims across 47 U.S. states, Puerto Rico, Washington, D.C., and about 31 countries, extorting more than $150 million in ransom payments. In one part of the case, prosecutors said Lytvynenko and co-conspirators collected about $634,000 in Bitcoin from two Tennessee victims and leaked stolen data from another Tennessee organization after a $3 million ransom demand was rejected. The plea comes as U.S. authorities continue pursuing other alleged Conti members; earlier indictments also tied the group’s breakup to successor operations including Black Basta, Quantum, Royal, and BlackSuit.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
The court scheduled Lytvynenko's sentencing for September 10, 2026, following his guilty plea in the Conti case.
Lytvynenko pleaded guilty to conspiracy to commit wire fraud for his role in Conti ransomware attacks, admitting involvement in the criminal operation and facing up to 20 years in prison.
After his arrest in Ireland, Lytvynenko was extradited to the United States in October 2025 to face federal charges tied to Conti ransomware operations.
Lytvynenko was arrested in Ireland in July 2023 in connection with his alleged role in Conti ransomware attacks.
Authorities said an indictment against four additional alleged Conti conspirators was unsealed in September 2023, expanding the public U.S. case against the ransomware network.
According to the Justice Department description cited in the references, Conti conducted ransomware operations from 2020 to 2022, targeting organizations across 47 U.S. states and 31 foreign countries and extorting at least $150 million.
The Conti ransomware operation shut down in May 2022 after the group backed the Russian government, a move that triggered internal leaks. The article presents this as the end of Conti's active run following its 2020–2022 campaign.
Authorities said Oleksii Oleksiyovych Lytvynenko had joined Conti by at least September 2021 and helped develop a malware loader used to enable initial intrusions in some attacks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcehelpnetsecurity.com
Open sourcesecurityaffairs.com
Open sourcecyberscoop.com
Open sourcesecurityonline.info
Open sourcejustice.gov
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.