" /> False Claims Act Cybersecurity Settlements: Full List 2022-2026
August 26, 2026

False Claims Act Cybersecurity Settlements: The Complete List (2022–2026)

Threat mitigation and security audits

Enforcement tracker · Updated August 2026 · All figures from DOJ announcements and public reporting

Since the DOJ launched its Civil Cyber-Fraud Initiative in October 2021, cybersecurity has become one of the fastest-growing uses of the False Claims Act — the fraud statute with treble damages, per-invoice penalties and 15–30% whistleblower bounties. Here is every major cybersecurity FCA settlement, what each contractor allegedly did, and the lesson buried in each one.

The complete list (2022–2026)

Year Company Settlement Core allegation
2026 LOGZONE Inc. $507,144 Self-reported compliance; DCMA assessed the real score at −170
2025 Georgia Tech Research Corp. $875,000 False DFARS 7019/7020 scores; missing anti-malware; late SSP
2025 Illumina $9.8M Overstated product security and NIST/ISO alignment
2025 Aero Turbine / Gallant Capital $1.75M NIST 800-171 failures — mitigated by voluntary self-disclosure
2025 Raytheon / RTX / Nightwing $8.5M Years of defense work without a compliant 800-171 SSP
2025 MORSE Corp. $4.6M Unimplemented controls, inflated posture — qui tam case
2024 Guidehouse & Nan McKay $11.3M Skipped mandatory pre-launch security testing
2023 Verizon Business $4.09M Missing required controls on government internet services
2023 Penn State University $1.25M Misrepresented 800-171 self-assessments and POA&M progress
2022 Aerojet Rocketdyne $9M Misrepresented 800-171 compliance while bidding defense work
2022 Comprehensive Health Services $930,000 First cyber-fraud settlement: unsecured medical records

Five patterns in the data

  • Self-assessments are being audited. LOGZONE and Georgia Tech both certified themselves; the government checked. The gap between claimed and actual score is the case.
  • Whistleblowers start most of them. Aerojet’s engineer received $2.61M; the Guidehouse relator $1.95M; MORSE began as a qui tam filing. The people who know your real posture have millions of reasons to talk.
  • No breach required. Almost none of these cases involved a hack. The misrepresentation alone — the score, the SSP, the “we’re compliant” checkbox — is the false claim.
  • Universities and giants alike. Penn State, Georgia Tech, Raytheon: sophistication is no defense, and neither is size in either direction.
  • Honesty is rewarded. Aero Turbine self-disclosed and settled far lighter. The DOJ explicitly credits cooperation and disclosure.

Why this list will grow in 2026–2027

DOJ officials have stated that cybersecurity FCA resolutions will continue and increase. Meanwhile the CMMC Level 2 assessment pause has created a perfect enforcement environment: contractors relaxing into optimistic self-assessments while their DFARS 7012/7019/7020 obligations — and the qui tam bar — remain fully active. Our full briefing on False Claims Act risk during the CMMC pause covers the mechanics, the whistleblower economics, and what a defensible posture looks like.

FAQ

What is the biggest False Claims Act cybersecurity settlement so far?

Guidehouse and Nan McKay’s $11.3 million settlement (June 2024) is the largest pure-cybersecurity FCA resolution to date, followed by Illumina at $9.8 million (2025), Aerojet Rocketdyne at $9 million (2022) and Raytheon/Nightwing at $8.5 million (2025).

How much does a cybersecurity whistleblower get under the False Claims Act?

Qui tam relators receive 15–30% of the government’s recovery. In cybersecurity cases, documented awards include $2.61 million (Aerojet Rocketdyne) and $1.95 million (Guidehouse/Nan McKay).

Can a company be fined without ever being breached?

Yes — most settlements on this list involved no breach at all. The False Claims Act punishes the misrepresentation of compliance (an inflated SPRS score, a fictional SSP), not the incident.

Would your compliance claims survive scrutiny?

Get a free CMMC Level 2 gap assessment: your real SPRS score under the official methodology, the evidence gaps, and a fixed-fee plan to close them — before an assessor or a whistleblower finds them first.

BOOK A FREE CMMC GAP ASSESSMENT