DOJ Arrests Tech CEO for Hiding Russian Ownership From Feds
The complaint doesn't allege a breach or a defective security control, it alleges the company lied about who owned it and where the code was written, and that's now a criminal matter.
TL;DR
DOJ arrested the CEO of a Virginia software firm and a Russian national for allegedly concealing that the company was owned and controlled by Russian nationals and that its software was developed in Russia. The firm sold software to U.S. government agencies. The complaint (filed in the Eastern District of New York) charges conspiracy to violate the Export Control Reform Act and other offenses tied to procurement of controlled technology for a Russian end user. The case signals DOJ is willing to treat supply-chain deception in federal software procurement as a criminal matter, not just a contractual dispute.

The Justice Department unsealed a criminal complaint charging the CEO of a Virginia-based software company and a Russian national with conspiring to conceal Russian ownership, control, and software-development activity from U.S. government agencies that bought the company's products. The complaint was filed in the Eastern District of New York.
What's notable about this case is what it doesn't allege. There's no data breach. No incident. No failure to implement a NIST SP 800-171 control. The alleged harm is deception in the procurement process itself, misrepresenting who owned the company and where the software was built. DOJ is treating that as a criminal conspiracy.
The charges include conspiracy to violate the Export Control Reform Act (50 U.S.C. § 4819), among other counts. The ECRA charge ties the ownership-concealment and procurement activity to export-control violations involving a Russian entity, Joint Stock Company Research and Development Center ELVEES, which was added to the Entity List in March 2022. The FBI affidavit alleges the defendants routed controlled technology through Hong Kong and other locations to reach a prohibited Russian end user without obtaining the required licenses from the Commerce Department.
The complaint doesn't enumerate which federal procurement certifications or representations the defendants allegedly falsified, the DOJ press release says only that the company sold software to U.S. government agencies while hiding Russian ownership and development. That ambiguity is itself part of the story. Federal contractors now have to consider that representations about beneficial ownership and development location, even if made implicitly or in the ordinary course of procurement, may be scrutinized under criminal export-control statutes rather than through the False Claims Act or contractual remedies.
The case also broadens the visible pattern of DOJ prosecutions targeting supply-chain deception in federal technology procurement. In recent years, similar ECRA-based indictments (including those against Arthur Petrov, Denis Postovoy, and the KanRus defendants) have focused on microelectronics and avionics routed to Russian end users in violation of export controls. This complaint extends that theory to software sold directly to the U.S. government, where the deception was about the vendor's identity rather than the destination of the goods.
For primes and subcontractors, the practical implication is straightforward: if you represent to the government that your software is U.S.-developed or U.S.-controlled, and it isn't, the exposure may now include an FBI arrest warrant, not just a cure notice.
Published ·Deep Fathom