{
  "id": "case-aerojet-fca-cyber",
  "slug": "aerojet-rocketdyne-false-claims-act",
  "title": "United States ex rel. Markus v. Aerojet Rocketdyne (Civil Cyber-Fraud Settlement)",
  "summary": "Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.",
  "case_number": "2:15-cv-02245-WBS-AC",
  "court": "U.S. District Court for the Eastern District of California",
  "district": "E.D. Cal.",
  "country": "United States",
  "opened_at": "2015-10-29",
  "status": "settled",
  "victim_sector": "Defense Industrial Base & Aerospace",
  "victim_country": "United States",
  "loss_amount_usd": 9000000,
  "loss_amount_note": "Federal False Claims Act settlement and whistleblower relator award of $2.61 million.",
  "first_seen_at": "2013-09-01T00:00:00Z",
  "last_updated_at": "2026-10-09T10:00:00Z",
  "actor_slug": "defense-procurement-fraud",
  "defendant_slugs": [],
  "cves": [],
  "techniques": [
    {
      "technique_id": "T1078",
      "evidence_excerpt": "Whistleblower former cybersecurity director documented that contractor failed to implement required access controls, encryption, and audit logs required by NIST SP 800-171.",
      "evidence_locator": "Second Amended Qui Tam Complaint \u00b6 35, Page 14",
      "mapping_status": "reviewed",
      "mapped_by": "rule",
      "source_title": "United States ex rel. Markus v. Aerojet Rocketdyne Holdings, Inc.",
      "source_url": "https://www.justice.gov",
      "technique_name": "Valid Accounts",
      "tactic": "Defense Evasion"
    }
  ],
  "events": [
    {
      "event_type": "lawsuit",
      "event_date": "2015-10-29",
      "description": "Former cybersecurity director files qui tam False Claims Act complaint under seal."
    },
    {
      "event_type": "ruling",
      "event_date": "2022-02-01",
      "description": "Federal judge denies contractor motion for summary judgment, establishing that cybersecurity non-compliance is material under the False Claims Act."
    },
    {
      "event_type": "settlement",
      "event_date": "2022-07-08",
      "description": "Aerojet Rocketdyne agrees to pay $9 million settlement on the second day of federal jury trial."
    }
  ],
  "attack_anatomy": {
    "ground_zero": "Unauthorized intrusion originating from targeted infiltration directed against Defense Industrial Base & Aerospace networks. Landmark Department of Justice Civil Cyber-Fraud Initiative settlement under the False Claims Act where defense contractor Aerojet Rocketdyne paid $9 million to resolve a qui tam whistleblower lawsuit alleging it falsely certified compliance with federal cybersecurity regulations (DFARS 252.204-7012 and NIST SP 800-171) on Department of Defense and NASA missile contracts.",
    "blast_radius": "Federal False Claims Act settlement and whistleblower relator award of $2.61 million. Impacted Defense Industrial Base & Aerospace infrastructure and associated victim operations.",
    "kill_chain": [
      {
        "phase": "Phase 1: Defense Evasion",
        "title": "Defense Evasion & Security Blindfolding",
        "description": "Whistleblower former cybersecurity director documented that contractor failed to implement required access controls, encryption, and audit logs required by NIST SP 800-171.",
        "technical_artifacts": [
          "T1078",
          "Valid Accounts"
        ],
        "mitre_technique_id": "T1078"
      }
    ],
    "defensive_takeaways": [
      "Enforce phishing-resistant multifactor authentication (FIDO2) across all external remote access endpoints.",
      "Implement network microsegmentation to prevent unrestricted lateral traversal between internal subnets.",
      "Maintain isolated, immutable backups of critical directory services and transaction databases.",
      "Deploy real-time endpoint detection and response (EDR) agents with automated containment policies."
    ]
  }
}