FCA whistleblower recoveries hit record $6.8B as cybersecurity fraud enters spotlight
A record 1,297 qui tam filings and explicit inclusion of cybersecurity fraud in FCA enforcement mean defense contractors' DFARS and CMMC compliance gaps now carry whistleblower exposure, and the first-to-file rule punishes delay.
TL;DR
The Justice Department secured a record $6.8 billion in False Claims Act settlements and judgments in FY2025, driven by 1,297 qui tam whistleblower suits, also an all-time high. Relators collect 15% to 30% of any recovery under the FCA, and the statute's first-to-file rule bars everyone except the first whistleblower to file on a given fraud scheme, regardless of who holds better evidence. Cybersecurity fraud, including knowing misrepresentation of NIST SP 800-171 or CMMC compliance status, is explicitly within FCA scope. The arithmetic for defense contractors is unforgiving: an insider who documents a compliance gap before the company self-discloses stands to capture a significant share of what DOJ recovers.
The False Claims Act has never been more dangerous for defense contractors with cybersecurity compliance gaps. DOJ's FY2025 numbers tell the story: $6.8 billion in settlements and judgments, 1,297 qui tam filings, and 401 new investigations opened. The statute awards whistleblowers between 15% and 30% of whatever the government recovers, a relator share that, on a large procurement-fraud case, can run into eight figures. And the Civil Division's April 2026 launch of the FOCUS initiative signals that DOJ isn't just fielding insider tips anymore; it's actively courting data miners who can cross-reference public datasets to flag anomalies in federal contract performance and billing.
Cybersecurity fraud isn't a hypothetical FCA theory. A contractor that attests to NIST SP 800-171 compliance in a DFARS 252.204-7012 contract clause, or represents CMMC Level 2 certification status in a proposal, while knowing those controls aren't fully implemented, has made a false claim to the government. The same logic applies to FedRAMP authorizations, CJIS attestations, and state-level frameworks that condition payment on security posture. The FCA's scienter standard ("knowingly") covers actual knowledge, deliberate ignorance, and reckless disregard. An auditor's finding that a company "should have known" its SSP was materially inaccurate can satisfy the standard.
The first-to-file rule is what turns a compliance gap into a race. It doesn't matter that a second whistleblower has better documentation or identifies more claims. Only the first to file collects. That means the disgruntled engineer sitting on a year's worth of internal emails about unmet controls has an incentive to move before the company's own disclosure catches up. Internal hotlines and compliance-reporting channels are valuable, but they don't stop the clock: the FCA rewards the person who files in federal court, not the person who notifies the CISO. For contractors operating under CMMC or DFARS obligations, the question isn't whether compliance gaps exist, it's who documents them first and what they do with the evidence.
Published ·Updated ·Deep Fathom