Enforcement tracker · Updated August 2026 · All figures from DOJ announcements and public reporting
Since the DOJ launched its Civil Cyber-Fraud Initiative in October 2021, cybersecurity has become one of the fastest-growing uses of the False Claims Act — the fraud statute with treble damages, per-invoice penalties and 15–30% whistleblower bounties. Here is every major cybersecurity FCA settlement, what each contractor allegedly did, and the lesson buried in each one.
The complete list (2022–2026)
| Year | Company | Settlement | Core allegation |
|---|---|---|---|
| 2026 | LOGZONE Inc. | $507,144 | Self-reported compliance; DCMA assessed the real score at −170 |
| 2025 | Georgia Tech Research Corp. | $875,000 | False DFARS 7019/7020 scores; missing anti-malware; late SSP |
| 2025 | Illumina | $9.8M | Overstated product security and NIST/ISO alignment |
| 2025 | Aero Turbine / Gallant Capital | $1.75M | NIST 800-171 failures — mitigated by voluntary self-disclosure |
| 2025 | Raytheon / RTX / Nightwing | $8.5M | Years of defense work without a compliant 800-171 SSP |
| 2025 | MORSE Corp. | $4.6M | Unimplemented controls, inflated posture — qui tam case |
| 2024 | Guidehouse & Nan McKay | $11.3M | Skipped mandatory pre-launch security testing |
| 2023 | Verizon Business | $4.09M | Missing required controls on government internet services |
| 2023 | Penn State University | $1.25M | Misrepresented 800-171 self-assessments and POA&M progress |
| 2022 | Aerojet Rocketdyne | $9M | Misrepresented 800-171 compliance while bidding defense work |
| 2022 | Comprehensive Health Services | $930,000 | First cyber-fraud settlement: unsecured medical records |
Five patterns in the data
- Self-assessments are being audited. LOGZONE and Georgia Tech both certified themselves; the government checked. The gap between claimed and actual score is the case.
- Whistleblowers start most of them. Aerojet’s engineer received $2.61M; the Guidehouse relator $1.95M; MORSE began as a qui tam filing. The people who know your real posture have millions of reasons to talk.
- No breach required. Almost none of these cases involved a hack. The misrepresentation alone — the score, the SSP, the “we’re compliant” checkbox — is the false claim.
- Universities and giants alike. Penn State, Georgia Tech, Raytheon: sophistication is no defense, and neither is size in either direction.
- Honesty is rewarded. Aero Turbine self-disclosed and settled far lighter. The DOJ explicitly credits cooperation and disclosure.
Why this list will grow in 2026–2027
DOJ officials have stated that cybersecurity FCA resolutions will continue and increase. Meanwhile the CMMC Level 2 assessment pause has created a perfect enforcement environment: contractors relaxing into optimistic self-assessments while their DFARS 7012/7019/7020 obligations — and the qui tam bar — remain fully active. Our full briefing on False Claims Act risk during the CMMC pause covers the mechanics, the whistleblower economics, and what a defensible posture looks like.
FAQ
What is the biggest False Claims Act cybersecurity settlement so far?
Guidehouse and Nan McKay’s $11.3 million settlement (June 2024) is the largest pure-cybersecurity FCA resolution to date, followed by Illumina at $9.8 million (2025), Aerojet Rocketdyne at $9 million (2022) and Raytheon/Nightwing at $8.5 million (2025).
How much does a cybersecurity whistleblower get under the False Claims Act?
Qui tam relators receive 15–30% of the government’s recovery. In cybersecurity cases, documented awards include $2.61 million (Aerojet Rocketdyne) and $1.95 million (Guidehouse/Nan McKay).
Can a company be fined without ever being breached?
Yes — most settlements on this list involved no breach at all. The False Claims Act punishes the misrepresentation of compliance (an inflated SPRS score, a fictional SSP), not the incident.
Next: why the CMMC pause makes this list more dangerous, not less · the full False Claims Act briefing · check your real SPRS score
Would your compliance claims survive scrutiny?
Get a free CMMC Level 2 gap assessment: your real SPRS score under the official methodology, the evidence gaps, and a fixed-fee plan to close them — before an assessor or a whistleblower finds them first.