GOVERNMENT CONTRACTING & WHISTLEBLOWER ENFORCEMENT

DOJ False Claims Act Cyber Fraud Hub

A comprehensive legal tracker of federal contractor prosecutions and whistleblower settlements under the DOJ Civil Cyber-Fraud Initiative for misrepresenting cybersecurity standards or concealing data breaches.

Key Facts

  • DOJ Civil Cyber-Fraud Initiative uses the False Claims Act (31 U.S.C. § 3729) to prosecute federal contractors for lax cybersecurity.
  • Whistleblowers receive between 15% and 30% of recovered settlement funds under qui tam provisions.
  • Misrepresenting compliance with NIST SP 800-171 or submitting inflated SPRS scores constitutes actionable fraud.
  • Contractors face treble damages (three times actual government loss) plus mandatory statutory penalties per false claim.

The DOJ Civil Cyber-Fraud Initiative Framework

Launched in October 2021 by Deputy Attorney General Lisa Monaco, the Civil Cyber-Fraud Initiative utilizes the False Claims Act to pursue government contractors and grant recipients that knowingly:

1. False Certification Fail to monitor or follow required cybersecurity standards (e.g. NIST SP 800-171, CMMC).
2. Defective Products Provide deficient cybersecurity products or services to federal agencies.
3. Failure to Report Fail to timely report suspected cyber incidents and breaches within mandatory SLA windows (e.g. DFARS 72-hour notice).

Aerojet Rocketdyne Holdings, Inc.

$9,000,000 Settlement
Agency: Department of Defense (DOD) & NASA | Relator Bounty: $2,610,000 to Whistleblower Relator

A former Senior Director of Cybersecurity filed a qui tam action alleging the rocket propulsion manufacturer knowingly failed to comply with mandatory federal cybersecurity regulations while certifying compliance to obtain multi-million dollar missile contracts. The court denied the contractor motion for summary judgment, establishing that cybersecurity compliance is material to the government decision to pay.

Violated Standard: DFARS 252.204-7012 & NIST SP 800-171 Safeguards
Associated Case Record: View Case Dossier →

Comprehensive Health Services LLC (CHS)

$930,000 Settlement
Agency: Department of State & Air Force | Relator Bounty: $167,400 to Whistleblower Relators

CHS submitted claims for medical services provided to federal personnel in Iraq and Afghanistan. CHS failed to disclose that it stored confidential medical records of military service members on an unencrypted internal network drive accessible by non-cleared staff, violating contractual cybersecurity requirements.

Violated Standard: Contractual Data Privacy & Electronic Medical Record Isolation
Associated Case Record: View Case Dossier →

The Pennsylvania State University (Penn State)

$1,250,000 Settlement
Agency: Department of Defense (DOD) & NASA Research Grants | Relator Bounty: $250,000 to Whistleblower Relator

Penn State agreed to pay $1.25 million to resolve False Claims Act allegations that it failed to implement required NIST SP 800-171 cybersecurity controls across university research laboratories handling defense research data and submitted inaccurate Assessment Scores to the DOD Supplier Performance Risk System (SPRS).

Violated Standard: NIST SP 800-171 Security Controls & SPRS Scoring
Associated Case Record: View Case Dossier →