Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationenforcement-actioncritical-infrastructure-threatunderground-data-leak

Extradition and Prosecution of Conti Ransomware Operator Oleksii Lytvynenko

Updated 3mo agoFirst seen Oct 31, 20259 sources

Oleksii Oleksiyovych Lytvynenko, a Ukrainian national alleged to be a key member of the Conti ransomware group, was extradited from Ireland to the United States to face charges related to his involvement in global ransomware attacks. U.S. authorities accuse Lytvynenko of participating in Conti's double extortion operations between 2020 and June 2022, controlling stolen data, sending ransom notes, and extorting millions in cryptocurrency from victims worldwide, including specific incidents in Tennessee. He was arrested in Cork, Ireland, in July 2023 by Irish police at the request of the U.S., and after lengthy extradition proceedings, appeared in a Tennessee court facing charges of computer fraud conspiracy and wire fraud conspiracy, with a potential sentence of up to 25 years if convicted.

The Conti ransomware group, which replaced the Ryuk operation in 2020, became one of the most prolific and aggressive ransomware syndicates, responsible for over 1,000 attacks in the U.S. and more than 30 countries, collecting approximately $150 million in ransom payments. The group targeted critical infrastructure and high-profile organizations, exploiting vulnerabilities such as Log4j and ProxyShell. After the group disbanded in 2022, its members, including Lytvynenko, allegedly continued cybercriminal activities. The U.S. Department of Justice and FBI have highlighted Conti's significant impact on global cybersecurity, with Lytvynenko's prosecution marking a major step in international law enforcement efforts against ransomware operators.

Share:
Extradition and Prosecution of Conti Ransomware Operator Oleksii Lytvynenko
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
Oct 30, 20258mo ago

Lytvynenko is extradited to the U.S. and appears in Tennessee court

The U.S. Department of Justice announced that Lytvynenko was extradited from Ireland and made an initial appearance in the Middle District of Tennessee on the 2023 indictment. Prosecutors said he faces federal charges carrying a potential sentence of up to 25 years in prison.

Oct 1, 20259mo ago

Irish extradition proceedings against Lytvynenko conclude

The extradition process in Ireland concluded in October 2025, clearing the way for Lytvynenko to be transferred to U.S. custody. This ended his detention in Ireland pending the U.S. case.

Jul 1, 20233y ago

Irish police arrest Lytvynenko at U.S. request

In July 2023, An Garda Síochána arrested Lytvynenko in Ireland at the request of the United States. An Irish court then detained him pending extradition proceedings.

Jan 1, 20233y ago

United States indicts Lytvynenko on Conti-related charges

A 2023 U.S. indictment charged Oleksii Oleksiyovych Lytvynenko with conspiracy to commit computer fraud and conspiracy to commit wire fraud in connection with the Conti ransomware conspiracy. The indictment later formed the basis for his extradition and initial court appearance in Tennessee.

Jun 30, 20224y ago

Lytvynenko's alleged participation in Conti activity ends

Court documents allege Lytvynenko conspired to deploy Conti ransomware, steal data, and extort victims from around 2020 through about June 2022. Prosecutors say this included more than $500,000 in cryptocurrency extorted from two victims in Tennessee.

Jan 1, 20224y ago

FBI estimates Conti had extorted at least $150 million

As of January 2022, the FBI estimated Conti had attacked more than 1,000 victims worldwide and collected at least $150 million in ransom payments. The DOJ cited this as evidence of the operation's scale and impact.

Jan 1, 20215y ago

Conti becomes a major critical infrastructure ransomware threat

By 2021, the FBI assessed Conti was used in more critical infrastructure attacks than any other ransomware variant. The group also exploited widely abused vulnerabilities such as Log4j and ProxyShell during its campaigns.

Jan 1, 20206y ago

Conti ransomware operation begins targeting victims worldwide

U.S. authorities say the Russian-based Conti ransomware operation began in 2020 and carried out intrusions, data theft, encryption, and double-extortion attacks against organizations globally. Prosecutors allege Oleksii Oleksiyovych Lytvynenko participated in this activity from around 2020.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

33 LINKEDOpen in app
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.