Ukrainian national linked to Conti ransomware attacks on U.S. hospitals gets 4-year sentence

One of the developers of the Conti ransomware, which is used in cyberattacks on critical infrastructure in industries including healthcare, has been sentenced to four years in prison on a charge of conspiracy to commit wire fraud in relation to its deployment.

According to the U.S. Department of Justice (DOJ), Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian man who formerly lived in Ireland, was part of a cybercrime ring that attacked schools, local governments and hospitals worldwide, including in 47 states and Puerto Rico.

For his part, Lytvynenko was responsible for coding the ransomware, including its delivery system. Authorities said the Conti ransomware was prolific between 2020 and 2022, claiming over 1,000 victims.

Those victims paid over $150 million in ransom payments, the DOJ added.

“For years, the Conti ransomware group executed a sustained and sophisticated campaign that victimized hundreds of organizations across the U.S. and abroad, including critical infrastructure entities, causing losses in the millions of dollars. Lytvynenko joined that conspiracy as both an intruder and a developer—personally harming at least 12 companies, storing stolen data from victims, and helping build the malicious tools Conti used to extort and threaten communities,” Assistant Attorney General A. Tysen Duva of the Justice Department’s Criminal Division said in a statement.

“Even after the Conti conspiracy ended, he continued engaging in active ransomware operations until his arrest. Cybercriminals who build, deploy, or profit from malware like Conti—no matter where they operate, will face justice and meaningful consequences in U.S. courts,” he added.

Authorities said evidence from his online accounts showed that Lytvynenko was in possession of stolen data from the 12 entities, eight of which were located in the U.S.

Subscribe to Health Exec News

The agency did not say for how long Lytvynenko was involved in the proliferation of Conti. Given the associated ransomware gang is responsible for hundreds of attacks in 32 countries, his relationship to his conspirators is not entirely clear.

Four others have been indicted, all currently facing federal criminal charges in Tennessee.

Conti was very successful in attacking stateside hospitals and holding them for ransom, including an infamous 2021 attack on Scripps Health, based in San Diego. The cyberattacks would encrypt data on servers, including sensitive patient data, holding it hostage.

The group has not been active since 2022.

It was in Ireland, back in July 2023, where Lytvynenko was arrested. He was later extradited to the U.S. to face charges in 2025, before pleading guilty in June 2026. Multiple federal agencies participated in the investigation and arrest of the Conti ransomware crime syndicate.

Lytvynenko will serve his sentence in a federal prison.

Chad Van Alstin Health Imaging Health Exec

Chad is an award-winning writer and editor with over 15 years of experience working in media. He has a decade-long professional background in healthcare, working as a writer and in public relations.

Subscribe to Health Exec News

Subscribe to Health Exec News