Data Security Rules

Five Years of the Civil Cyber-Fraud Initiative: Sixteen Settlements, Ten Whistleblower Suits and No Judgment

Key Takeaways

  • The initiative targets knowingly deficient cybersecurity products or services, knowing misrepresentation of security practices, and knowing violations of incident monitoring and reporting duties
  • Sixteen settlements were located in DOJ releases dated March 8, 2022 to September 1, 2026, ranging from $293,771 to $11,300,000
  • Ten of the sixteen releases describe qui tam suits; relator shares ran from $201,250 to $2,610,000
  • NIST SP 800-171, through DFARS 252.204-7012, and false self-assessment scores recur in the defense cases from 2024 onward
  • DOJ's FY2025 fact sheet reports nine cyber-fraud settlements that year; this publication located eight, so the count here is not a complete census

The 2021 Announcement

On October 6, 2021, Deputy Attorney General Lisa Monaco announced the Civil Cyber-Fraud Initiative, to be led by the Civil Division's Commercial Litigation Branch, Fraud Section. The release said the initiative "will utilize the False Claims Act to pursue cybersecurity related fraud by government contractors and grant recipients," and named three kinds of conduct: "knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity practices or protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches."

It was not a new statute, regulation or unit. The same release describes it as a product of a departmental cyber review ordered that May, drawing on existing expertise in "civil fraud enforcement, government procurement and cybersecurity." The legal footing is the False Claims Act, and the initiative's reach is therefore limited to what that statute reaches: requests for federal money.

The False Claims Act Theory

31 U.S.C. § 3729(a)(1) makes liable any person who "knowingly presents, or causes to be presented, a false or fraudulent claim for payment or approval," or who knowingly makes or uses a false record or statement material to one. Liability is three times the government's damages plus a per-claim civil penalty, adjusted for inflation from a statutory base of $5,000 to $10,000. A defendant that reports within 30 days and cooperates fully may have damages reduced to double under § 3729(a)(2).

Two definitions do the work in the cyber cases. "Knowingly" in § 3729(b)(1) covers actual knowledge, deliberate ignorance and reckless disregard, and requires "no proof of specific intent to defraud." A "claim" in § 3729(b)(2) includes a request to a contractor or grantee where the United States provides or reimburses any portion of the money. That second definition is why state-administered programs funded with federal dollars appear in the record: a Florida children's insurance website paid with Medicaid funds, Pennsylvania contact tracing paid with CDC funds, and New York's federally funded rental assistance portal.

The pattern in the releases is an invoice, or a certification or assessment score submitted to win or keep a contract, that is alleged to be false because a contractual security requirement was not being met.

Qui Tam Relators

Section 3730(b) lets a private person sue "for the person and for the United States Government." The complaint is filed under seal for at least 60 days while the government decides whether to intervene. Under § 3730(d)(1) a relator whose case the government takes over receives 15 to 25 per cent of the proceeds; under § 3730(d)(2), where the government does not proceed, 25 to 30 per cent. Section 3730(h) protects employees who are retaliated against.

Ten of the sixteen releases charted below describe a qui tam action. The relators named in them are mostly insiders: a former Aerojet employee, a former Insight Global contact tracing staff member, an entity owned by a former Guidehouse employee, the former chief information officer of Penn State's Applied Research Laboratory, a former Raytheon director of engineering, a former Illumina platform management director, two members of Georgia Tech's cybersecurity team, and a former Honeywell employee. The Aerojet relator "filed and litigated" the case himself and settled on the second day of trial; his $2.61 million share of $9 million is 29 per cent, above the 25 per cent ceiling § 3730(d)(1) sets where the government takes over a case and within the § 3730(d)(2) range where it does not.

The Settlement Record

The table lists each resolved matter this publication found in a DOJ release, fetched on September 21, 2026. It records what each release alleges, not what was proved.

Release dateDefendantAmountAlleged failure, as the release describes itOrigin
Mar. 8, 2022Comprehensive Health Services$930,000Scanned medical records of personnel in Iraq left on a network drive rather than the secure EMR system billed for; the settlement also resolved drug-approval allegationsTwo qui tam suits
July 8, 2022Aerojet Rocketdyne$9,000,000Misrepresented compliance with cybersecurity requirements in certain federal government contractsQui tam, settled at trial
Mar. 14, 2023Jelly Bean Communications Design and its manager$293,771Unpatched software on a Medicaid-funded children's insurance site; more than 500,000 applications hackedNot stated
Sept. 5, 2023Verizon Business Network Services$4,091,317Trusted Internet Connections service missed three required controls on GSA contracts, 2017 to 2021Self-disclosure
May 1, 2024Insight Global$2,700,000Contact tracing health data sent in unencrypted email, shared passwords, public linksQui tam
June 17, 2024Guidehouse and Nan McKay$11,300,000Required pre-production security testing of New York's rental assistance portal not done; site shut 12 hours after launchQui tam; admissions
Oct. 15, 2024ASRC Federal Data Solutions$306,722, plus waiver of at least $877,578 in breach costsMedicare beneficiary screenshots stored unencrypted on a subcontractor server later breachedPrompt notice to CMS; cooperation
Oct. 22, 2024Pennsylvania State University$1,250,000Required controls missing across 15 DoD and NASA contracts; implementation dates in submitted scores misrepresentedQui tam
Feb. 18, 2025Health Net Federal Services and Centene$11,253,400Falsely certified TRICARE contract security compliance, 2015 to 2018; ignored audit findingsNot stated
Mar. 26, 2025MORSECORP$4,600,000Reported a NIST score of 104 after being told the true score was -142; email host not FedRAMP Moderate equivalentQui tam; admissions
May 1, 2025Raytheon, RTX and Nightwing$8,400,000Internal development system used on 29 DoD contracts lacked a system security plan and required controlsQui tam
July 31, 2025Illumina$9,800,000Genomic sequencers sold to agencies with software vulnerabilities and no adequate product security programQui tam
July 31, 2025Aero Turbine and Gallant Capital Partners$1,750,000NIST SP 800-171 controls missing; defense files given to an Egypt-based software companySelf-disclosure
Sept. 30, 2025Georgia Tech Research Corporation$875,000No antivirus in a DoD research lab; campus-wide score of 98 for a system that did not existQui tam; government intervened
June 18, 2026LOGZONE$507,144NIST SP 800-171 controls missing on two Navy contracts; DCMA assessment scored it -170Not stated; DCMA assessment
Sept. 1, 2026Honeywell Aerospace$2,042,518NIST SP 800-171 requirements not met on one network used for a DoD contract, 2020 to 2023Qui tam

The sixteen amounts total $69,099,872, before ASRC's waived reimbursement. The Comprehensive Health Services figure covers drug-approval allegations as well as the records failure, and the release does not split it. DOJ called that matter its "first resolution of a False Claims Act case involving cyber fraud since the launch" of the initiative.

Most releases from 2022 through October 2024 name the initiative in a closing paragraph. From February 2025 the releases fetched for this account generally do not use the phrase, though the Georgia Tech release is headed "Civil Cyber-Fraud Litigation," and the Department's FY2025 False Claims Act fact sheet reports under "Cybersecurity Fraud" that it "recovered over $52 million in nine cybersecurity fraud settlements" that fiscal year. This publication located eight settlements dated within fiscal year 2025, from ASRC in October 2024 to Georgia Tech in September 2025, totaling about $38.2 million. At least one FY2025 matter is missing from the table, and the count above is the count found, not a census.

Contract Clauses the Settlements Cite

The defense cases converge on one clause. DFARS 252.204-7012 requires "adequate security" on covered contractor information systems and, for systems not operated on the government's behalf, the security requirements of NIST SP 800-171, implemented "not later than December 31, 2017." It defines rapid incident reporting as within 72 hours of discovery. The Raytheon release names the clause alongside FAR 52.204-21, which it describes as requiring "basic safeguarding requirements" for systems that process or store federal contract information.

The self-assessment score is the recurring false statement. The MORSECORP, Georgia Tech, Penn State and LOGZONE releases each turn on a summary assessment score reported to DoD; the MORSECORP and LOGZONE releases give the scale as -203 to 110. MORSECORP reported 104 and, according to the facts it admitted, did not correct it for eleven months after a consultant put the real figure at -142, and then only three months after a subpoena. Georgia Tech's 98 was alleged to rest on a "fictitious" or "virtual" environment. The Georgia Tech release adds that the NIST SP 800-171 obligation has applied to DoD contracts "since 2017" and "will continue" under the Cybersecurity Maturity Model Certification program.

The civilian and grant-funded cases cite different requirements. Jelly Bean's contract required a hosting environment meeting HIPAA protections. Verizon's service had to satisfy Trusted Internet Connections controls. Guidehouse's contract required pre-production security testing. ASRC's required protection of Medicare beneficiary data that its subcontractor's disk-level encryption did not provide against credentialed access. Illumina, alone in the record, is a product case: the allegation is that the government bought sequencers whose software was represented as meeting ISO and NIST standards.

What the Record Does Not Show

No matter in the table reached a judgment. Each release states, in some form, that the claims resolved "are allegations only" and that "there has been no determination of liability." Admissions appear in two: Guidehouse and Nan McKay admitted that neither completed the required testing, and MORSECORP admitted a set of facts about its controls and its score. The only case taken to trial, Aerojet, settled on its second day.

The third branch of the 2021 announcement, knowing violations of duties to monitor and report incidents, has no settlement in the table built primarily on it. MORSECORP's admitted facts include a cloud email host that did not meet DoD incident reporting requirements, but the matters that followed an actual breach (Jelly Bean, Guidehouse and ASRC) were resolved on the security failure that preceded it, not on a late or missing report.

Cooperation credit is visible but not quantified. Verizon and Aero Turbine are described as receiving credit for self-disclosure, cooperation and remediation, and ASRC for prompt notice and cooperation. None of the releases states how much the credit reduced the amount. Finally, the table is built only from announced resolutions. Investigations closed without action, declined qui tam suits and sealed complaints do not appear in DOJ releases and are not counted here.

Background

For the underlying law rather than this development: Technology & SaaS privacy law.

Frequently Asked Questions

What is the DOJ Civil Cyber-Fraud Initiative?
A Justice Department initiative announced on October 6, 2021 and led by the Civil Division's Fraud Section. It uses the False Claims Act against government contractors and grant recipients that knowingly provide deficient cybersecurity products or services, misrepresent their security practices, or violate incident monitoring and reporting obligations.
How many Civil Cyber-Fraud settlements has DOJ announced?
This publication located sixteen resolved matters in DOJ releases from March 2022 through September 1, 2026, totaling $69,099,872. DOJ's own FY2025 fact sheet reports nine settlements that year where this publication found eight, so the true total is at least that and may be higher.
Why do cybersecurity failures become False Claims Act cases?
Because the contractor asked for federal money while a contractual security requirement was allegedly unmet, or submitted a false certification or assessment score. The Act's knowledge standard includes reckless disregard and needs no proof of specific intent to defraud, and its definition of a claim reaches state programs paid partly with federal funds.
What share does a whistleblower receive in a cyber-fraud settlement?
Under 31 U.S.C. § 3730(d), 15 to 25 per cent where the government takes over the case and 25 to 30 per cent where it does not. In the releases charted here, relator awards ran from $201,250 in the Georgia Tech matter to $2.61 million in the Aerojet case, which the relator litigated himself.
Has any company been found liable at trial under the Civil Cyber-Fraud Initiative?
Not in the record charted here. Every matter located was resolved by settlement, and each release states the claims are allegations with no determination of liability. Aerojet Rocketdyne settled on the second day of trial.

Sources

Everything above is reported from these documents. Follow them to verify.

  1. DOJ Office of Public Affairs, Deputy Attorney General Lisa O. Monaco Announces New Civil Cyber-Fraud Initiative (October 6, 2021) agency release
  2. 31 U.S.C. § 3729, False claims statute
  3. 31 U.S.C. § 3730, Civil actions for false claims statute
  4. 48 CFR 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting regulation
  5. DOJ, Medical Services Contractor Pays $930,000 to Settle False Claims Act Allegations (Comprehensive Health Services) (March 8, 2022) agency release
  6. DOJ, Aerojet Rocketdyne Agrees to Pay $9 Million to Resolve False Claims Act Allegations of Cybersecurity Violations (July 8, 2022) agency release
  7. DOJ, Jelly Bean Communications Design and its Manager Settle False Claims Act Liability (March 14, 2023) agency release
  8. DOJ, Cooperating Federal Contractor Resolves Liability for Alleged False Claims (Verizon Business Network Services) (September 5, 2023) agency release
  9. DOJ, Staffing Company to Pay $2.7M for Alleged Failure to Provide Adequate Cybersecurity for COVID-19 Contact Tracing Data (Insight Global) (May 1, 2024) agency release
  10. DOJ, Consulting Companies to Pay $11.3M for Failing to Comply with Cybersecurity Requirements (Guidehouse and Nan McKay) (June 17, 2024) agency release
  11. DOJ, Virginia Contractor Settles False Claims Act Liability for Failing to Secure Medicare Beneficiary Data (ASRC Federal Data Solutions) (October 15, 2024) agency release
  12. DOJ, The Pennsylvania State University Agrees to Pay $1.25M to Resolve False Claims Act Allegations (October 22, 2024) agency release
  13. DOJ, Health Net Federal Services LLC and Centene Corporation Agree to Pay Over $11 Million (February 18, 2025) agency release
  14. DOJ, Defense Contractor MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud Allegations (March 26, 2025) agency release
  15. DOJ, Raytheon Companies and Nightwing Group to Pay $8.4M (May 1, 2025) agency release
  16. DOJ, Illumina Inc. to Pay $9.8M to Resolve False Claims Act Allegations Arising from Cybersecurity Vulnerabilities (July 31, 2025) agency release
  17. DOJ, California Defense Contractor and Private Equity Firm Agree to Pay $1.75M (Aero Turbine and Gallant Capital Partners) (July 31, 2025) agency release
  18. DOJ, Georgia Tech Research Corporation Agrees to Pay $875,000 to Resolve Civil Cyber-Fraud Litigation (September 30, 2025) agency release
  19. DOJ, Alabama Defense Contractor Agrees to Pay $507,144 (LOGZONE) (June 18, 2026) agency release
  20. DOJ, Honeywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations (September 1, 2026) agency release
  21. DOJ, Fact Sheet: False Claims Act Settlements and Judgments FY2025 agency release

Reporting, not legal advice. This article reports on developments in privacy law using publicly available primary sources, which are linked throughout and listed at the end. It is not legal advice, it is not written or reviewed by an attorney, and it does not assess how any law applies to your situation. Privacy law changes frequently and differs by jurisdiction. Reading this does not create an attorney-client relationship. To find out where you or your business stands, consult a licensed attorney. How we report.