Four years in a US federal prison is the sentence a 44-year-old Ukrainian national received for his role in Conti, the ransomware crew that tore through more than 1,000 victims before it vanished in 2022.
Oleksii Lytvynenko split his time between running intrusions and writing malware for the group, according to the Justice Department, which said he hit at least a dozen companies himself and built tools his partners leaned on. He pleaded guilty in June to conspiracy to commit wire fraud. Agents found files stolen from a dozen victims, eight of them in the United States, inside his online accounts. Between 2020 and 2022 the gang struck organizations in 47 US states, Washington, D.C. and 31 countries.
Hospitals sat squarely in the blast radius. Conti ranked among the most aggressive ransomware operations against healthcare, and its 2021 assault on Ireland’s Health Service Executive knocked out national IT systems and scrubbed appointments for months. Investigators later traced Conti infrastructure and personnel into Royal, Black Basta and other crews that kept landing on hospital networks.
The lesson for healthcare defenders has not changed: the people and tooling behind these attacks outlive the brand on the leak site, and prosecutors keep working the file long after a gang goes quiet.