United States ex rel. Markus v. Aerojet Rocketdyne (Civil Cyber-Fraud Settlement)
Key Facts
- Legal Status: SETTLED in U.S. District Court for the Eastern District of California.
- Primary Target Sector: Defense Industrial Base & Aerospace.
- Documented Financial Loss: $9.0 million.
- 1 verified MITRE ATT&CK techniques substantiated with verbatim court excerpts.
Case Summary
Executive Summary for Board Members & Leadership
Plain-English Root Cause
Unauthorized intrusion originating from targeted infiltration directed against Defense Industrial Base & Aerospace networks. Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.
Operational & Financial Fallout
Federal False Claims Act settlement and whistleblower relator award of $2.61 million. Impacted Defense Industrial Base & Aerospace infrastructure and associated victim operations.
3 Critical Boardroom Questions
- 1. Do 100% of our external portals enforce phishing-resistant hardware MFA?
- 2. Can compromised endpoint credentials traverse laterally to domain controllers or cloud storage?
- 3. Have our air-gapped immutable recovery backups been restored and tested within the last 90 days?
Attack Anatomy & Incident Execution
Forensic analysis of initial intrusion vector, step-by-step kill chain, operational blast radius, and defensive controls.
Unauthorized intrusion originating from targeted infiltration directed against Defense Industrial Base & Aerospace networks. Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.
Adversary Kill Chain Flow
1 Documented PhasesWhistleblower former cybersecurity director documented that contractor failed to implement required access controls, encryption, and audit logs required by NIST SP 800-171.
Federal False Claims Act settlement and whistleblower relator award of $2.61 million. Impacted Defense Industrial Base & Aerospace infrastructure and associated victim operations.
Procedural & Incident Timeline
Former cybersecurity director files qui tam False Claims Act complaint under seal.
Federal judge denies contractor motion for summary judgment, establishing that cybersecurity non-compliance is material under the False Claims Act.
Aerojet Rocketdyne agrees to pay $9 million settlement on the second day of federal jury trial.
Substantiated MITRE ATT&CK Techniques
| Technique ID | Technique Name & Tactic | Primary Source Evidence Excerpt | Locator | Verification |
|---|---|---|---|---|
| T1078 | Valid Accounts Defense Evasion | "Whistleblower former cybersecurity director documented that contractor failed to implement required access controls, encryption, and audit logs required by NIST SP 800-171." | Second Amended Qui Tam Complaint ¶ 35, Page 14 | reviewed |