Conti member pleads guilty in ransomware scheme linked to hospital attacks

Advertisement

A Ukrainian national who helped deploy Conti ransomware against more than 1,000 victims worldwide has pleaded guilty to conspiracy to commit wire fraud and faces up to 20 years in prison.

According to a June 12 Justice Department news release, Oleksii Oleksiyovych Lytvynenko, 44, of Cork, Ireland, admitted to joining the Conti ransomware operation by September 2021 and developing a “loader,” malware designed to deliver additional malicious software to compromised systems.

Mr. Lytvynenko was extradited from Ireland before entering his plea. He is scheduled to be sentenced Sept. 10, 2026.

Federal authorities said Conti infected more than 1,000 computers and networks worldwide between 2020 and 2022, targeting organizations in 47 states, the District of Columbia, Puerto Rico and 31 countries. The FBI estimates the group collected at least $150 million in ransom payments.

Healthcare organizations were among Conti’s most frequent targets. A separate 2023 Justice Department indictment linked the group to attacks on about 300 U.S. organizations, including hospitals. One of the defendants named in that case, Maksim Galochkin, was charged in connection with a 2021 ransomware attack on Scripps Health in San Diego that forced portions of the health system’s IT network offline for weeks and disrupted patient care at Scripps and neighboring UC San Diego Health.

Although Conti disbanded in 2022, cybersecurity officials have said its members and infrastructure have resurfaced in other ransomware operations. In early 2024, the Health Sector Cybersecurity Coordination Center warned that the Akira ransomware group, which had claimed more than 80 victims, shared ties to the former Conti operation and used similar double-extortion tactics against healthcare organizations.

Mr. Lytvynenko also admitted possessing stolen data belonging to eight U.S. victims and four victims outside the country.

The FBI’s San Diego, Nashville and El Paso field offices investigated the case alongside the U.S. Secret Service. The Justice Department’s Office of International Affairs, the Irish Department of Justice and the Garda National Cyber Crime Bureau assisted with the arrest and extradition.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Register to Attend Webinar

The hidden cost of lost clinical time and how leading health systems are responding

Friday, August 7
12:00 PM - 1:00 PM CDT

Presenters: Kassaundra McKnight-Young, Zebra TechnologiesGregory Carras, Zebra TechnologiesJennifer Gene, Levata

Advertisement

Next Up in Cybersecurity

Advertisement