MONEYLAUNDERING.IE
  • Home
  • Typologies
  • Regulatory Materials

Training Typologies

Money Laundering typologies, case studies and news 

Subscribe to our news service at HERE 

Ukrainian national extradited from Ireland to the U.S. pleads guilty to conspiracy to commit wire fraud for involvement in the Conti ransomware operation

15/6/2026

0 Comments

 
Picture
​This post is written by Peter Oakes, a leading financial services expert who has led the establishment of anti-money laundering enforcement functions at Central Banks (Ireland and Saudi Arabia) and worked as a senior regulator in Australia (ASIC) and UK (FSA/FCA).  These days Peter is non-executive director of, and advisor to, financial services companies in Europe Union and the UK.
Picture
If you would rather listen to an audio summarising this blog and additional detail, you can do so by clicking here.  

​This is a very good money laundering typology for AML training, especially if looking for an international ransomware-as-a-service case involving cryptocurrency, Ireland, the USA and how the High Court of Ireland exercises extradition treaty proceedings. 

Our Peter Oakes is often asked to write more about useful money laundering cases that can be used by MLROs (Money Laundering Reporting Officers) as typologies for AML training.  This typology on Ireland's money laundering website, www.moneylaundering.ie, pulls together:

* ransomware-as-service;
* predicate criminal offence;
* a Ukranian national living in Cork;
* identification of proceeds of crime in bitcoin recorded on the supposedly anonymous promoting blockchain;
* Irish High Court extradition proceedings;
* alleged abuse of human rights; and
* evidence from Google Analytics and Google Drive.

So we am pretty sure it ticks all the "right boxes".

The case when examined from multiple sources (like Money Laundering Ireland has done) provides interesting insights into the Irish extradition regime, identification of supposedly anonymous bitcoin transactions recorded on the blockchain and evidenced obtained from Google Analytics.
Picture
Picture
​On Friday 12 June 2026 Oleksii Oleksiyovych Lytvynenko (44), a Ukrainian national who was extradited from Ireland to the U.S., pleaded guilty in the US to conspiracy to commit wire fraud for his involvement in the Conti ransomware operation.

​Back in 2025, the High Court of Ireland made an order committing Lytvynenko to prison to await his extradition to stand trial for his part in the ransomware conspiracy.

​
Lytvynenko, based in Cork, Ireland, worked with others in the Conti ransomware group to hack victims’ networks, encrypt files, and demand ransom payments in exchange for restoring access and not leaking stolen data.

Mr Justice David Keane (High Court of Ireland) determined that the U.S. DoJ application met all of the proofs prescribed by s.29 of the Extradition Act 1965 (as amended) and that the Lytvynenko’s objections based upon violations of his rights and abuse of process did not warrant the refusal of the order sought.

​Before the High Court evidence from Google analytics data on Lytvynenko’s account showed that he had searched for methods of thwarting Windows authentication and had watched YouTube videos on malware, hacking, Windows administration, building a remote access tool and penetration testing. The High Court also heard that cryptocurrency tracing performed by the FBI on the publicly available blockchain had also indicated that the Lytvynenko received payments in Bitcoin from Conti conspirators during approximately the same period as the attacks on six of the victims whose data was found in the respondent’s Google Drive.

The conspiracy was alleged to have resulted in the payment of a combined ransom of approximately $634,000 in cryptocurrency.

The Irish High Court had to consider both s.10(1) and s.10(1A) of the Extradition Act 1965, noting that extradition can be granted only in respect of an offence punishable both under the laws of the requesting country and of the State. The court was ultimately satisfied on the evidence that the requirements of correspondence and minimum gravity had been met and that the extradition of the respondent was not prohibited by Part II of the 1965 Act or by the relevant extradition provisions.

Next the court had to consider that the “making of an extradition arrangement presupposes that the Government and the Oireachtas are satisfied, amongst other things, that a person being extradited to another State with which Ireland has such an arrangement will not have his constitutional (or ECHR) rights impaired”. Mr Justice Keane considered the Lytvynenko’s objections in turn but was not satisfied that they warranted refusal of the order sought where they did not meet the required thresholds and/or where there was an insufficient evidential basis to support them.

The High Court back in 2025 made an order pursuant to s.29 of the 1965 Act committing the Lytvynenko’ to prison to await the making of an order for his extradition. The Irish judgement is The Attorney General v Oleksi Oleksiyovych Lytvynenko [2025] IEHC 100. See citations at end of this post.
Picture
Picture
Once he was extradited, more fun began.

In the US it was argued that between 2020 and 2022, Conti attacks hit systems across 47 U.S. states, 31 countries, the District of Columbia, and Puerto Rico. The FBI estimates that at least $150 million in ransom payments were made by January 2022.

Lytvynenko admitted to joining the group around September 2021. He acknowledged holding stolen data from multiple victims in the U.S. and abroad. He also worked on developing malware components, including a “loader” used to deliver other malicious tools during attacks.

“He admitted to possessing data from eight U.S. and four overseas victims which had been stolen by Conti conspirators. Lytvynenko further admitted to joining a team run by a Conti conspirator during which time Lytvynenko was directed to work on coding a “loader,” which is typically a type of malware, or malicious software, that is used to load programs necessary to execute other malicious attacks.” reads the press release published by DoJ.

Lytvynenko pleaded guilty on Friday 12 June 2026 to conspiracy to commit wire fraud for his role in the Conti ransomware operation. 

He is scheduled to be sentenced on September 10, 2026, and faces up to 20 years in prison. The final sentence will be determined by a federal judge after considering U.S. sentencing guidelines and other statutory factors.

In September 2023, four other Conti conspirators were indicted in Tennessee. The FBI and U.S. Secret Service are investigating, with DOJ prosecutors handling the case.

“Lytvynenko’s guilty plea is a significant step toward holding cyber criminals accountable for the damage they inflict on victims worldwide,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division. “Lytvynenko profited from fear and coercion, conspiring to use Conti ransomware to extort victims and steal their data. This case demonstrates that the FBI and our partners will relentlessly pursue those responsible for cybercrimes, regardless of where they operate, and bring them to justice.”  See citations at end of this post.

The FBI informs that Conti emerged from the Ryuk gang and was closely linked to the TrickBot malware operation. The group became known for attacks on healthcare organizations, governments, and businesses before shutting down operations in 2022 after internal chats were leaked and law enforcement pressure increased.
Sources:
  • The Attorney General v Oleksi Oleksiyovych Lytvynenko [2025] IEHC 100. See https://www.irishlegal.com/articles/high-court-man-committed-to-prison-pending-his-extradition-to-usa-to-stand-trial-for-ransomware-conspiracy-charges / https://www.iisf.ie/Oleksii-Lytvynenko-extradited-conti  /https://ie.vlex.com/vid/the-attorney-general-v-1094149608
  • US Case.  https://www.justice.gov/opa/pr/ukrainian-national-pleads-guilty-wire-fraud-conspiracy-connection-conti-ransomware / https://securityaffairs.com/193590/uncategorized/ukrainian-extradited-from-ireland-pleads-guilty-over-role-in-conti-ransomware-scheme.html
0 Comments

20240226 - US lawyer who laundered $297million through Irish bank accounts jailed for role in 'Crypto Queen' scam

26/2/2024

1 Comment

 
​Subscribe to our news service at HERE
Mark Scott was convicted in November 2019 of laundering a total of almost $400m in his role within One Coin pyramid scheme run by notorious 'Cryto Queen' Ruja Ignatova.

  • An American lawyer who laundered $297million through Bank of Ireland accounts as part of a $3.35 billion cryptocurrency scam has been jailed for 10 years in the US.
  • Mark Scott was convicted in November 2019 of laundering a total of almost $400 million in his role within One Coin pyramid scheme run by notorious 'Cryto Queen' Ruja Ignatova.
  • Authorities said he had set up a number of bogus private equity investment funds called the Fenero Funds in the British Virgin Islands in 2015 because legitimate banks were unwilling to take Ignatova’s money.
  • ​Scott then transferred money from OneCoin victims from the Fenero Funds via Ireland and the Cayman Islands.
  • Court documents from the US state: “Between approximately May 2016 and July 2018, the Fenero Fund Accounts funded approximately €282,000,000 ($304,000,000) in wire transfers to a series of Fenero Fund bank accounts held at the Bank of Ireland in the Republic of Ireland.
  • “At Ignatova’s direction, Scott subsequently transferred approximately €185,000,000 ($200,000,000) from the Bank of Ireland to the accounts of one of Ignatova’s other money launderers.
  • “Through the use of the Fenero Funds, and the ensuing transfers, Scott successfully cleaned the funds, removing anyconnection to Ignatova or OneCoin and enabling Ignatova to move the funds where she pleased.”
  • Bulgarian national Ignatova, who was the subject of BBC podcast The Missing Cryptoqueen, was sast seen in Dubai. She is currently one of the FBI’s Top Ten wanted fugitives, with a $250,000 reward for information leading to her capture.
  • US Attorney for the Southern District of New York said: “Mark Scott, previously convicted at trial of laundering over $400 million of OneCoin proceeds for ‘Crypto Queen,’ Ruja Ignatova, used his law license as a means to participate in a massive money laundering scheme for a cryptocurrency that had no value since its inception.
  • "Scott, an equity partner at a prominent international law firm, had boasted of earning ‘50 by 50.’ Indeed, Scott accomplished his goal, but by fraud and deception, and will now spend a decade in prison and has been ordered to forfeit all of his illegal proceeds.”
  • Bank of Ireland employees were requested to testify as part of Scott’s trial, but declined. US authorities do not believe the Irish bank were aware of the nature of the scam and do not suspect them of any wrongdoing.
 
  • www.irishstar.com/news/us-news/us-lawyer-launders-irish-bank-32020071

​
1 Comment

20230701 - Man accused of unlawful use of computer in crypto fraud

1/7/2023

6 Comments

 
​Subscribe to our news service at HERE
Interesting #financialcrime typology for training purposes around 'easy money to be had' and the corruption of a younger 'technically savvy' generation.

In this case, Adam Gray, just 20 years old has been charged with 21 counts of unlawful use of a computer and attempted theft following an alleged #cryptocurrency fraud.

Readers might recall that a few years ago Conor Freeman (21) was jailed for role in $2 million cryptocurrency theft
identified by US Homeland Security as part of online group.  Freeman, jailed in Ireland, pleaded guilty to knowingly engaging in the possession of the proceeds of crime — namely 142.75682712 Bitcoin. Today (01 July 2023) that amount of bitcoin would be worth a hefty $4.35mn.

Not often is there media about dishonestly operating a computer “with the intention of making gain for yourself or another or causing loss to another”.  There is clearly more to the facts of this story than is currently in the public domain.  Mr Freeman was also charged with three counts of dishonestly operating a computer to make a gain.
Adam Gray, just 20 years old has been charged with 21 counts of unlawful use of a computer and attempted theft following an alleged cryptocurrency fraud. It is alleged that at a place unknown within the Ireland the accused dishonestly operated a computer, or caused it to be operated “with the intention of making gain for yourself or another or causing loss to another”.

Mr. Gray is also charged with five counts of attempted theft from different people, at locations in Dublin. The attempted theft charges related to a total of €1,249 while the amount of money alleged to have gone through the account was €8,136, the court heard.
​
Conor Freeman case (November 2020)

This is a very interesting case.  Freeman was jailed in November 2020. In addition to pleading guilty to knowingly engaging in the possession of the proceeds of crime — namely 142.75682712 Bitcoin, he also pleaded guilty to stealing $100,000 in cryptocurrency from Darran Marble on May 15th 2018, stealing cryptocurrencies with an approximate value of $1,921,335, from Seth Sharpiro on May 16th, 2018, and stealing cryptocurrencies with an approximate value of $167,622.22 from Micheal Templeman on May 18th, 2018.  He also entered guilty pleas to three counts of dishonestly operating a computer to make a gain on dates between May 15th and May 18th, 2018. He has no previous convictions.

  •  Freeman was identified by the United States Department of Homeland Security as being the person behind certain internet handles connected to the offences.
  • Freeman was part of a group of people who had met online. This group identified people on social media who they believed might have access to some amount of cryptocurrency.
  • ​The group was able to gain access to the email addresses and phone numbers of these people via social media, which was information needed to commit the crimes.
  • Freeman’s co-conspirators knew people who worked in telecommunications who would transfer the phone numbers of potential victims onto SIM cards purchased by the group.
  • The co-conspirators would then initiate protocols that are in place in the event of people forgetting their passwords in order to gain access to the online accounts of potential victims.
  • After his co-conspirators gained access to the email exchanges of these people, Freeman would go through these exchanges and identify sources of cryptocurrencies they possessed.
  • The proceeds of the thefts would be split evenly between all parties who were involved. The court heard that there are five co-accused of Freeman who are before the courts in the United States.
  • Freeman's lawyer said his client was “very much a loner” as a teenager who reverted to an online world. He said his client started out “hacking” other persons accounts during online games and that he did so not for monetary gain, but rather for the “thrill”.

Adam Gray links:
  • https://www.independent.ie/irish-news/courts/man-accused-of-unlawful-use-of-computer-in-crypto-fraud/a235542840.html
  • https://www.linkedin.com/posts/peteroakes_financialcrime-cryptocurrency-activity-7080843579216027648-qXyS
​
Conor Freeman link
  • https://www.irishtimes.com/news/crime-and-law/courts/circuit-court/man-jailed-for-role-in-2-million-cryptocurrency-theft-1.4411641
6 Comments

    Author

    On this page you will find a selection of links to articles useful for AFC training.

    Archives

    June 2026
    September 2025
    August 2025
    July 2025
    June 2025
    May 2025
    January 2025
    December 2024
    November 2024
    October 2024
    September 2024
    August 2024
    July 2024
    April 2024
    March 2024
    February 2024
    January 2024
    November 2023
    July 2023
    June 2023
    May 2023
    April 2023
    March 2023
    September 2022
    July 2021
    February 2021
    May 2017
    April 2017
    November 2016
    June 2012

    Categories

    All
    AIB
    Bank Of Ireland
    Bitcoin
    CAB
    Cash Intensive Businesses
    Catriona Carey
    Central Bank Of Ireland
    Crypto
    Danske Bank
    DNB
    Drug Trafficking
    Employee Theft
    Enforcement
    European Banking Authority
    EuroPol
    Fake Identities
    FBI
    Financial Conduct Authority
    Gambling
    Garda
    Gold Bullion
    Guest Contributor
    INTERPOL
    Money Mules
    NCA
    Payments
    PEPs
    Permanent TSB
    Professional Enablers
    Professionals
    Ransomware
    Regulatory Fines
    Revolut
    Romance Fraud
    RTE
    Sandbox
    SARs
    Statistics
    Student Money Mules
    Trade Based Money Laundering
    UBS
    Ulster Bank
    US Law Enforcement
    Waterford Football Club

    RSS Feed

Site powered by Weebly. Managed by Bluehost
  • Home
  • Typologies
  • Regulatory Materials