Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000 victims worldwide.
According to court documents, Lytvynenko, formerly of Cork, Ireland, conspired with others to deploy Conti ransomware to extort victims and steal their data. From 2020 until 2022, Conti was used to attack computers and networks in 47 states, 31 foreign countries, the District of Columbia, and Puerto Rico. The FBI estimates that, as of January 2022, there had been victim payouts associated with Conti ransomware exceeding $150,000,000.
“Today’s sentence reflects the seriousness of ransomware and the Department’s commitment to protecting America’s hospitals, schools, businesses, and local governments,” said Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division. “For years, the Conti ransomware group executed a sustained and sophisticated campaign that victimized hundreds of organizations across the United States and abroad, including critical infrastructure entities, causing losses in the millions of dollars. Lytvynenko joined that conspiracy as both an intruder and a developer – personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities. Even after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest. Cybercriminals who build, deploy, or profit from malware like Conti – no matter where they operate – will face justice and meaningful consequences in U.S. courts.”
“Ransomware attacks like Conti cause real harm to businesses, institutions, and families here at home and around the world,” said U.S. Attorney Braden H. Boucek for the Middle District of Tennessee. “Today’s sentence demonstrates that cybercriminals cannot hide behind borders or a keyboard to escape justice. We are grateful to our law enforcement and international partners whose work made this result possible.”
“Lytvynenko and his co-conspirators used Conti ransomware to attack computers and networks in nearly every state, and today’s sentence reflects the gravity and extent of those crimes,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Ransomware criminals should know they are not anonymous and operating from overseas does not mean operating without consequences. The FBI and our partners will use every lawful tool to dismantle their infrastructure and bring them to justice.”
“Conti ransomware caused extraordinary harm, targeting victims across nearly every state and dozens of countries and disrupting critical operations for organizations across multiple industries,” said Assistant Director Brent Daniels of the U.S. Secret Service’s Office of Field Operations. “Today’s sentence is a measure of justice for the victims whose data, operations, and livelihoods were put at risk. It underscores the Secret Service’s commitment to pursuing ransomware actors and their networks wherever they operate and protecting the American people.”
Lytvynenko pleaded guilty to wire fraud conspiracy on June 10. Evidence recovered from Lytvynenko’s online accounts showed he possessed data stolen from eight U.S. victims and four overseas victims. Lytvynenko further admitted to joining a team run by a Conti conspirator during which time Lytvynenko was directed to work on coding a “loader,” which is typically a type of malware, or malicious software, that is used to load programs necessary to execute other malicious attacks. Forensic artifacts recovered at the time of his arrest in July 2023 in County Cork, Ireland, further demonstrated ongoing involvement in ransomware activity.
In September 2023, an indictment charging four other Conti conspirators was unsealed in the Middle District of Tennessee.
The FBI’s San Diego, Nashville, and El Paso Field Offices and the U.S. Secret Service are investigating the case. The Department of Homeland Security’s Homeland Security Investigations New York field office provided valuable assistance.
Trial Attorney Sonia V. Jimenez of the Criminal Division’s Computer Crime and Intellectual Property Section (CCIPS) and Assistant U.S. Attorney Taylor Phillips for the Middle District of Tennessee are prosecuting the case. The Justice Department’s Office of International Affairs, and the Irish Department of Justice, Home Affairs, and Migration, the Irish Office of the Attorney General and the Garda National Cyber Crime Bureau provided valuable assistance to secure the arrest and extradition of Lytvynenko.
CCIPS investigates and prosecutes cybercrime and intellectual property (IP) crime in coordination with domestic and international law enforcement agencies, often with assistance from the private sector. Since 2020, CCIPS has secured the conviction of over 180 cyber and IP criminals, and court orders for the return of over $350 million in victim funds.