San Diego/ Crime & Emergencies

Ukrainian Coder Gets 4 Years for Conti Hack That Cost Scripps Health $113M

AI Assisted Icon
Published on September 16, 2026
Ukrainian Coder Gets 4 Years for Conti Hack That Cost Scripps Health $113M10385 Vista Sorrento Pkwy — Tennessee Conti Prosecution Venue
Google Street View

A 44-year-old Ukrainian national who once lived in Cork, Ireland, was sentenced to four years in U.S. federal prison after admitting he helped build and deploy the Conti ransomware that crippled San Diego-based Scripps Health in 2021. Oleksii Oleksiyovych Lytvynenko pleaded guilty in June to conspiracy to commit wire fraud, and a judge handed down the sentence on Thursday.

The case was investigated by FBI San Diego

alongside the FBI's Nashville and El Paso field offices and the U.S. Secret Service, according to the agency's own case update. Prosecutors say Lytvynenko worked as both an intruder and a malware developer for Conti starting in September 2021, coding malicious loaders used to deliver payloads onto victim networks and storing stolen data lifted from 12 victim companies, eight of them American, according to

CyberScoop

.

For San Diego, the case reaches back to a painful local memory. Scripps Health suffered a major cyberattack in May 2021 that forced clinical IT networks offline, diverted emergency patients, and ultimately cost the health system nearly $113 million in recovery costs and lost revenue, according to Becker's Hospital Review.

A Years-Long Path From Cork to Federal Custody

Lytvynenko's road to a U.S. courtroom began in July 2023, when Irish national police arrested him in County Cork at the request of American authorities. The U.S. Department of Justice's Middle District of Tennessee office says his detention in Ireland stretched on until his extradition to the United States was finally completed in October 2025 — more than two years after his arrest.

Court documents filed by federal prosecutors show Lytvynenko stayed actively engaged in cybercrime operations right up until days before that July 2023 arrest, even though Conti had disbanded in 2022. The same filings, reported by the Justice Department and by cybersecurity outlet The Record, describe a defendant who kept working the angles long after the syndicate he helped build had officially gone dark.

The Scale of Conti's Global Damage

Between 2020 and 2022, Conti compromised networks across 47 U.S. states, Washington D.C., Puerto Rico, and 31 foreign countries, infecting more than 1,000 organizations and extorting over $150 million in total victim payouts by January 2022, per the Justice Department. FBI assessments cited by The HIPAA Journal found that Conti targeted more U.S. critical infrastructure organizations in 2021 than any other ransomware variant.

Locally in Tennessee, where the case was prosecuted, Conti conspirators extorted more than $500,000 in cryptocurrency from two victims and publicly published sensitive data stolen from a third victim that refused to pay a $3 million ransom, according to Justice Department filings.

Other Alleged Members Remain at Large

Lytvynenko is not the only person the government has tied to Conti. In September 2023, a federal grand jury in the Middle District of Tennessee unsealed an indictment charging four Russian co-conspirators — Maksim Galochkin, Maksim Rudenskiy, Mikhail Tsarev, and Andrey Zhuykov — with participating in the Conti enterprise alongside Lytvynenko. The Justice Department notes that Galochkin was also separately charged in federal court in San Diego over the Scripps Health breach specifically.

While Lytvynenko served as a developer coding loaders and maintaining stolen data, the 2023 indictments also named several alleged co-conspirators.

Conti's Code Lives On in New Threats

Even though the Conti brand shut down in 2022, its leaked source code didn't disappear with it. Becker's Hospital Review reports that the code was repurposed to launch Gunra, which emerged in 2025.

Hoodline on federal warnings that Gunra targets government and critical infrastructure and was built on Conti code. That same month, the broader pattern of double-extortion ransomware operations hitting U.S. institutions remained a concern. Ransomware-driven outages remain a reminder that the operational risks Conti pioneered haven't gone away even as its original network sits in the past.