NEW: A Better Approach to HIPAA Training
View HIPAA Courses
NEW: A Better Approach to HIPAA Training
View HIPAA Courses

The HIPAA Journal is the leading provider of HIPAA training, news, regulatory updates, and independent compliance advice.

Conti Ransomware Member Sentenced to 4 Years in Jail

A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and other countries has been sentenced to four years in jail for his role in the attacks. The Conti ransomware group was a major ransomware operation that engaged in double extortion tactics, breaching victims’ networks, stealing sensitive data, and encrypting devices for financial gain. The Conti ransomware operation emerged after the shutdown of the Ryuk ransomware group in 2020 and was active until 2022. During that time, the group conducted ransomware attacks on an estimated 1,000 entities in 31 foreign countries, 47 U.S. states, the District of Columbia, and Puerto Rico.

While some ransomware groups prohibited attacks on healthcare providers, Conti had no such restrictions and actively targeted healthcare organizations. The group reached peak activity in 2021, when many critical infrastructure entities were attacked, including the Health Service Executive in Ireland and many U.S. hospitals, such as Scripps Health in San Diego. According to the U.S. Department of Justice (DoJ), the Conti ransomware group collected an estimated $150 million in ransom payments as of January 2022.

Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, was arrested in Ireland in July 2023 by the Irish national police and was extradited to the United States last year to face trial. Lytvynenko was accused of being a developer of malicious tools used by the Conti ransomware operation, breaching the networks of at least 12 companies, and exfiltrating and storing stolen data.

Lytvynenko admitted to being a member of the Conti ransomware operation since September 2021, controlling stolen data from eight victims in the United States and four victims in foreign countries, and issuing ransom demands. Lytvynenko was a member of a team run by a co-conspirator and developed loader malware, which was used by the group to load malicious software on victims’ networks. In June 2026, Lytvynenko pleaded guilty to one count of conspiracy to commit wire fraud and has been awaiting sentencing, which could have been a maximum of 20 years in jail. On September 10, 2026, Lytvynenko was sentenced to four years in federal prison.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

“Ransomware attacks like Conti cause real harm to businesses, institutions, and families here at home and around the world,” said U.S. Attorney Braden H. Boucek for the Middle District of Tennessee. “Today’s sentence demonstrates that cybercriminals cannot hide behind borders or a keyboard to escape justice. We are grateful to our law enforcement and international partners whose work made this result possible.”

Four other Conti co-conspirators – Russian nationals Maksim Galochkin, Maksim Rudenskiy, Mikhail Mikhailovich Tsarev, and Andrey Yuryevich Zhuykov – have also been indicted for their role in Conti ransomware attacks and have criminal charges pending in the Middle District of Tennessee.

Author: Steve Alder is the editor-in-chief of The HIPAA Journal. Steve is responsible for editorial policy regarding the topics covered in The HIPAA Journal. He is a specialist on healthcare industry legal and regulatory affairs, and has 10 years of experience writing about HIPAA and other related legal topics. Steve has developed a deep understanding of regulatory issues surrounding the use of information technology in the healthcare industry and has written hundreds of articles on HIPAA-related topics. Steve shapes the editorial policy of The HIPAA Journal, ensuring its comprehensive coverage of critical topics. Steve Alder is considered an authority in the healthcare industry on HIPAA. The HIPAA Journal has evolved into the leading independent authority on HIPAA under Steve’s editorial leadership. Steve manages a team of writers and is responsible for the factual and legal accuracy of all content published on The HIPAA Journal. Steve holds a Bachelor’s of Science degree from the University of Liverpool. You can connect with Steve via LinkedIn or email via stevealder(at)hipaajournal.com

x

Is Your Organization HIPAA Compliant?

Find Out With Our Free HIPAA Compliance Checklist

Get Free Checklist