CASE DOSSIER settled

United States ex rel. Markus v. Aerojet Rocketdyne (Civil Cyber-Fraud Settlement)

Docket: 2:15-cv-02245-WBS-AC Court: U.S. District Court for the Eastern District of California Opened: 2015-10-29 Sector: Defense Industrial Base & Aerospace

Key Facts

Status
SETTLED
Legal disposition
Loss Amount
$9.0 million
Federal False Claims Act settlement and whistleblower relator award of $2.61 million.
Techniques
1
Verified mappings
Defendants
0
Named in charges
  • Legal Status: SETTLED in U.S. District Court for the Eastern District of California.
  • Primary Target Sector: Defense Industrial Base & Aerospace.
  • Documented Financial Loss: $9.0 million.
  • 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Export structured case data and MITRE ATT&CK Navigator layer:

Case Summary

Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.
BOARDROOM EXECUTIVE BRIEF

Executive Summary for Board Members & Leadership

Plain-English Root Cause

Unauthorized intrusion originating from targeted infiltration directed against Defense Industrial Base & Aerospace networks. Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.

Operational & Financial Fallout

Federal False Claims Act settlement and whistleblower relator award of $2.61 million. Impacted Defense Industrial Base & Aerospace infrastructure and associated victim operations.

3 Critical Boardroom Questions

  • 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
  • 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
  • 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Disposition: SETTLED
Technical Threat Intelligence

Attack Anatomy & Incident Execution

Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.

Ground Zero / Infiltration Vector

Unauthorized intrusion originating from targeted infiltration directed against Defense Industrial Base & Aerospace networks. Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.

Adversary Kill Chain Flow

1 Documented Phases
1
Phase 1: Defense Evasion Defense Evasion & Security Blindfolding
MITRE ATT&CK T1078 →

Whistleblower former cybersecurity director documented that contractor failed to implement required access controls, encryption, and audit logs required by NIST SP 800-171.

Artifacts & Tooling: T1078 Valid Accounts
Real-World Blast Radius & Operational Fallout

Federal False Claims Act settlement and whistleblower relator award of $2.61 million. Impacted Defense Industrial Base & Aerospace infrastructure and associated victim operations.

Defensive Engineering Takeaways
Recommended Hardening Controls
✓ Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.
✓ Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.
✓ Maintain isolated, immutable backups of critical directory services and transaction databases.
✓ Deploy real-time endpoint detection and response (EDR) agents with automated containment policies.

Procedural & Incident Timeline

2015-10-29 lawsuit

Former cybersecurity director files qui tam False Claims Act complaint under seal.

2022-02-01 ruling

Federal judge denies contractor motion for summary judgment, establishing that cybersecurity non-compliance is material under the False Claims Act.

2022-07-08 settlement

Aerojet Rocketdyne agrees to pay $9 million settlement on the second day of federal jury trial.

Substantiated MITRE ATT&CK Techniques

Technique ID Technique Name & Tactic Primary Source Evidence Excerpt Locator Verification
T1078 Valid Accounts
Defense Evasion
"Whistleblower former cybersecurity director documented that contractor failed to implement required access controls, encryption, and audit logs required by NIST SP 800-171." Second Amended Qui Tam Complaint ¶ 35, Page 14 reviewed

Cite & Embed This Case Record

Public Domain / CC0
Bluebook Legal Citation:
Cyberattack Case Library, United States ex rel. Markus v. Aerojet Rocketdyne (Civil Cyber-Fraud Settlement), No. 2:15-cv-02245-WBS-AC (U.S. District Court for the Eastern District of California 2015), https://cybercaselibrary.com/cases/aerojet-rocketdyne-false-claims-act/
Embeddable Incident Card (HTML):
<iframe src="https://cybercaselibrary.com/embed/case/aerojet-rocketdyne-false-claims-act" width="100%" height="220" style="border:none; border-radius:6px;" loading="lazy"></iframe>