trade-press
FCA whistleblower recoveries hit record $6.8B as cybersecurity fraud enters spotlight
A record 1,297 qui tam filings and explicit inclusion of cybersecurity fraud in FCA enforcement mean defense contractors' DFARS and CMMC compliance gaps now carry whistleblower exposure, and the first-to-file rule punishes delay.
The Justice Department secured a record $6.8 billion in False Claims Act settlements and judgments in FY2025, driven by 1,297 qui tam whistleblower suits, also an all-time high. Relators collect 15% to 30% of any recovery under the FCA, and the statute's first-to-file rule bars everyone except the first whistleblower to file on a given fraud scheme, regardless of who holds better evidence. Cybersecurity fraud, including knowing misrepresentation of NIST SP 800-171 or CMMC compliance status, is explicitly within FCA scope. The arithmetic for defense contractors is unforgiving: an insider who documents a compliance gap before the company self-discloses stands to capture a significant share of what DOJ recovers.