Five Years of the Civil Cyber-Fraud Initiative: Sixteen Settlements, Ten Whistleblower Suits and No Judgment
Key Takeaways
- The initiative targets knowingly deficient cybersecurity products or services, knowing misrepresentation of security practices, and knowing violations of incident monitoring and reporting duties
- Sixteen settlements were located in DOJ releases dated March 8, 2022 to September 1, 2026, ranging from $293,771 to $11,300,000
- Ten of the sixteen releases describe qui tam suits; relator shares ran from $201,250 to $2,610,000
- NIST SP 800-171, through DFARS 252.204-7012, and false self-assessment scores recur in the defense cases from 2024 onward
- DOJ's FY2025 fact sheet reports nine cyber-fraud settlements that year; this publication located eight, so the count here is not a complete census
The 2021 Announcement
On October 6, 2021, Deputy Attorney General Lisa Monaco announced the Civil Cyber-Fraud Initiative, to be led by the Civil Division's Commercial Litigation Branch, Fraud Section. The release said the initiative "will utilize the False Claims Act to pursue cybersecurity related fraud by government contractors and grant recipients," and named three kinds of conduct: "knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches."
It was not a new statute, regulation or unit. The same release describes it as a product of a departmental cyber review ordered that May, drawing on existing expertise in "civil fraud enforcement, government procurement and cybersecurity." The legal footing is the False Claims Act, and the initiative's reach is therefore limited to what that statute reaches: requests for federal money.
The False Claims Act Theory
31 U.S.C. § 3729(a)(1) makes liable any person who "knowingly presents, or causes to be presented, a false or fraudulent claim for payment or approval," or who knowingly makes or uses a false record or statement material to one. Liability is three times the government's damages plus a per-claim civil penalty, adjusted for inflation from a statutory base of $5,000 to $10,000. A defendant that reports within 30 days and cooperates fully may have damages reduced to double under § 3729(a)(2).
Two definitions do the work in the cyber cases. "Knowingly" in § 3729(b)(1) covers actual knowledge, deliberate ignorance and reckless disregard, and requires "no proof of specific intent to defraud." A "claim" in § 3729(b)(2) includes a request to a contractor or grantee where the United States provides or reimburses any portion of the money. That second definition is why state-administered programs funded with federal dollars appear in the record: a Florida children's insurance website paid with Medicaid funds, Pennsylvania contact tracing paid with CDC funds, and New York's federally funded rental assistance portal.
The pattern in the releases is an invoice, or a certification or assessment score submitted to win or keep a contract, that is alleged to be false because a contractual security requirement was not being met.
Qui Tam Relators
Section 3730(b) lets a private person sue "for the person and for the United States Government." The complaint is filed under seal for at least 60 days while the government decides whether to intervene. Under § 3730(d)(1) a relator whose case the government takes over receives 15 to 25 per cent of the proceeds; under § 3730(d)(2), where the government does not proceed, 25 to 30 per cent. Section 3730(h) protects employees who are retaliated against.
Ten of the sixteen releases charted below describe a qui tam action. The relators named in them are mostly insiders: a former Aerojet employee, a former Insight Global contact tracing staff member, an entity owned by a former Guidehouse employee, the former chief information officer of Penn State's Applied Research Laboratory, a former Raytheon director of engineering, a former Illumina platform management director, two members of Georgia Tech's cybersecurity team, and a former Honeywell employee. The Aerojet relator "filed and litigated" the case himself and settled on the second day of trial; his $2.61 million share of $9 million is 29 per cent, above the 25 per cent ceiling § 3730(d)(1) sets where the government takes over a case and within the § 3730(d)(2) range where it does not.
The Settlement Record
The table lists each resolved matter this publication found in a DOJ release, fetched on September 21, 2026. It records what each release alleges, not what was proved.
| Release date | Defendant | Amount | Alleged failure, as the release describes it | Origin |
|---|---|---|---|---|
| Mar. 8, 2022 | Comprehensive Health Services | $930,000 | Scanned medical records of personnel in Iraq left on a network drive rather than the secure EMR system billed for; the settlement also resolved drug-approval allegations | Two qui tam suits |
| July 8, 2022 | Aerojet Rocketdyne | $9,000,000 | Misrepresented compliance with cybersecurity requirements in certain federal government contracts | Qui tam, settled at trial |
| Mar. 14, 2023 | Jelly Bean Communications Design and its manager | $293,771 | Unpatched software on a Medicaid-funded children's insurance site; more than 500,000 applications hacked | Not stated |
| Sept. 5, 2023 | Verizon Business Network Services | $4,091,317 | Trusted Internet Connections service missed three required controls on GSA contracts, 2017 to 2021 | Self-disclosure |
| May 1, 2024 | Insight Global | $2,700,000 | Contact tracing health data sent in unencrypted email, shared passwords, public links | Qui tam |
| June 17, 2024 | Guidehouse and Nan McKay | $11,300,000 | Required pre-production security testing of New York's rental assistance portal not done; site shut 12 hours after launch | Qui tam; admissions |
| Oct. 15, 2024 | ASRC Federal Data Solutions | $306,722, plus waiver of at least $877,578 in breach costs | Medicare beneficiary screenshots stored unencrypted on a subcontractor server later breached | Prompt notice to CMS; cooperation |
| Oct. 22, 2024 | Pennsylvania State University | $1,250,000 | Required controls missing across 15 DoD and NASA contracts; implementation dates in submitted scores misrepresented | Qui tam |
| Feb. 18, 2025 | Health Net Federal Services and Centene | $11,253,400 | Falsely certified TRICARE contract security compliance, 2015 to 2018; ignored audit findings | Not stated |
| Mar. 26, 2025 | MORSECORP | $4,600,000 | Reported a NIST score of 104 after being told the true score was -142; email host not FedRAMP Moderate equivalent | Qui tam; admissions |
| May 1, 2025 | Raytheon, RTX and Nightwing | $8,400,000 | Internal development system used on 29 DoD contracts lacked a system security plan and required controls | Qui tam |
| July 31, 2025 | Illumina | $9,800,000 | Genomic sequencers sold to agencies with software vulnerabilities and no adequate product security program | Qui tam |
| July 31, 2025 | Aero Turbine and Gallant Capital Partners | $1,750,000 | NIST SP 800-171 controls missing; defense files given to an Egypt-based software company | Self-disclosure |
| Sept. 30, 2025 | Georgia Tech Research Corporation | $875,000 | No antivirus in a DoD research lab; campus-wide score of 98 for a system that did not exist | Qui tam; government intervened |
| June 18, 2026 | LOGZONE | $507,144 | NIST SP 800-171 controls missing on two Navy contracts; DCMA assessment scored it -170 | Not stated; DCMA assessment |
| Sept. 1, 2026 | Honeywell Aerospace | $2,042,518 | NIST SP 800-171 requirements not met on one network used for a DoD contract, 2020 to 2023 | Qui tam |
The sixteen amounts total $69,099,872, before ASRC's waived reimbursement. The Comprehensive Health Services figure covers drug-approval allegations as well as the records failure, and the release does not split it. DOJ called that matter its "first resolution of a False Claims Act case involving cyber fraud since the launch" of the initiative.
Most releases from 2022 through October 2024 name the initiative in a closing paragraph. From February 2025 the releases fetched for this account generally do not use the phrase, though the Georgia Tech release is headed "Civil Cyber-Fraud Litigation," and the Department's FY2025 False Claims Act fact sheet reports under "Cybersecurity Fraud" that it "recovered over $52 million in nine cybersecurity fraud settlements" that fiscal year. This publication located eight settlements dated within fiscal year 2025, from ASRC in October 2024 to Georgia Tech in September 2025, totaling about $38.2 million. At least one FY2025 matter is missing from the table, and the count above is the count found, not a census.
Contract Clauses the Settlements Cite
The defense cases converge on one clause. DFARS 252.204-7012 requires "adequate security" on covered contractor information systems and, for systems not operated on the government's behalf, the security requirements of NIST SP 800-171, implemented "not later than December 31, 2017." It defines rapid incident reporting as within 72 hours of discovery. The Raytheon release names the clause alongside FAR 52.204-21, which it describes as requiring "basic safeguarding requirements" for systems that process or store federal contract information.
The self-assessment score is the recurring false statement. The MORSECORP, Georgia Tech, Penn State and LOGZONE releases each turn on a summary assessment score reported to DoD; the MORSECORP and LOGZONE releases give the scale as -203 to 110. MORSECORP reported 104 and, according to the facts it admitted, did not correct it for eleven months after a consultant put the real figure at -142, and then only three months after a subpoena. Georgia Tech's 98 was alleged to rest on a "fictitious" or "virtual" environment. The Georgia Tech release adds that the NIST SP 800-171 obligation has applied to DoD contracts "since 2017" and "will continue" under the Cybersecurity Maturity Model Certification program.
The civilian and grant-funded cases cite different requirements. Jelly Bean's contract required a hosting environment meeting HIPAA protections. Verizon's service had to satisfy Trusted Internet Connections controls. Guidehouse's contract required pre-production security testing. ASRC's required protection of Medicare beneficiary data that its subcontractor's disk-level encryption did not provide against credentialed access. Illumina, alone in the record, is a product case: the allegation is that the government bought sequencers whose software was represented as meeting ISO and NIST standards.
What the Record Does Not Show
No matter in the table reached a judgment. Each release states, in some form, that the claims resolved "are allegations only" and that "there has been no determination of liability." Admissions appear in two: Guidehouse and Nan McKay admitted that neither completed the required testing, and MORSECORP admitted a set of facts about its controls and its score. The only case taken to trial, Aerojet, settled on its second day.
The third branch of the 2021 announcement, knowing violations of duties to monitor and report incidents, has no settlement in the table built primarily on it. MORSECORP's admitted facts include a cloud email host that did not meet DoD incident reporting requirements, but the matters that followed an actual breach (Jelly Bean, Guidehouse and ASRC) were resolved on the security failure that preceded it, not on a late or missing report.
Cooperation credit is visible but not quantified. Verizon and Aero Turbine are described as receiving credit for self-disclosure, cooperation and remediation, and ASRC for prompt notice and cooperation. None of the releases states how much the credit reduced the amount. Finally, the table is built only from announced resolutions. Investigations closed without action, declined qui tam suits and sealed complaints do not appear in DOJ releases and are not counted here.
Background
For the underlying law rather than this development: Technology & SaaS privacy law.
Frequently Asked Questions
What is the DOJ Civil Cyber-Fraud Initiative?
How many Civil Cyber-Fraud settlements has DOJ announced?
Why do cybersecurity failures become False Claims Act cases?
What share does a whistleblower receive in a cyber-fraud settlement?
Has any company been found liable at trial under the Civil Cyber-Fraud Initiative?
Sources
Everything above is reported from these documents. Follow them to verify.
- DOJ Office of Public Affairs, Deputy Attorney General Lisa O. Monaco Announces New Civil Cyber-Fraud Initiative (October 6, 2021) agency release
- 31 U.S.C. § 3729, False claims statute
- 31 U.S.C. § 3730, Civil actions for false claims statute
- 48 CFR 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting regulation
- DOJ, Medical Services Contractor Pays $930,000 to Settle False Claims Act Allegations (Comprehensive Health Services) (March 8, 2022) agency release
- DOJ, Aerojet Rocketdyne Agrees to Pay $9 Million to Resolve False Claims Act Allegations of Cybersecurity Violations (July 8, 2022) agency release
- DOJ, Jelly Bean Communications Design and its Manager Settle False Claims Act Liability (March 14, 2023) agency release
- DOJ, Cooperating Federal Contractor Resolves Liability for Alleged False Claims (Verizon Business Network Services) (September 5, 2023) agency release
- DOJ, Staffing Company to Pay $2.7M for Alleged Failure to Provide Adequate Cybersecurity for COVID-19 Contact Tracing Data (Insight Global) (May 1, 2024) agency release
- DOJ, Consulting Companies to Pay $11.3M for Failing to Comply with Cybersecurity Requirements (Guidehouse and Nan McKay) (June 17, 2024) agency release
- DOJ, Virginia Contractor Settles False Claims Act Liability for Failing to Secure Medicare Beneficiary Data (ASRC Federal Data Solutions) (October 15, 2024) agency release
- DOJ, The Pennsylvania State University Agrees to Pay $1.25M to Resolve False Claims Act Allegations (October 22, 2024) agency release
- DOJ, Health Net Federal Services LLC and Centene Corporation Agree to Pay Over $11 Million (February 18, 2025) agency release
- DOJ, Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations (March 26, 2025) agency release
- DOJ, Raytheon Companies and Nightwing Group to Pay $8.4M (May 1, 2025) agency release
- DOJ, Illumina Inc. to Pay $9.8M to Resolve False Claims Act Allegations Arising from Cybersecurity Vulnerabilities (July 31, 2025) agency release
- DOJ, California Defense Contractor and Private Equity Firm Agree to Pay $1.75M (Aero Turbine and Gallant Capital Partners) (July 31, 2025) agency release
- DOJ, Georgia Tech Research Corporation Agrees to Pay $875,000 to Resolve Civil Cyber-Fraud Litigation (September 30, 2025) agency release
- DOJ, Alabama Defense Contractor Agrees to Pay $507,144 (LOGZONE) (June 18, 2026) agency release
- DOJ, Honeywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations (September 1, 2026) agency release
- DOJ, Fact Sheet: False Claims Act Settlements and Judgments FY2025 agency release
Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.