Watch hub·enforcement · qui-tam · civil-cyber-fraud · fca

Enforcement

Civil Cyber-Fraud Initiative settlements, qui tam unsealings, and the turn from voluntary to mandatory.

Updated ·RSS ↗

Cyber-compliance enforcement has accelerated through the Department of Justice's Civil Cyber-Fraud Initiative. This hub tracks settled and pending False Claims Act actions, GAO bid-protest decisions touching cyber clauses, and DCMA/DIBCAC findings as they become public — cross-cutting CMMC, FedRAMP, and state programs.

What changed in the last 30 days

  • procurement/independent

    NDAA Would Make 1260H Listings Automatic Procurement Bans

    The FY 2027 NDAA proposes roughly 200 China-related provisions, but one stands apart: Section 1812 would require DoW to refer every Section 1260H Chinese military company designee to the Federal Acquisition Security Council within 90 days for a government-wide exclusion order. The FASC gets 270 days to review; if it recommends exclusion, the President gets 90 more. The bar covers a listed entity, its subsidiaries, and affiliates, and survives removal from the 1260H list. The definition of "covered article" sweeps in IT, telecom, cloud services, and any hardware or software with embedded IT, reaching deep into the defense supply chain.

  • enforcement/trade-press

    Ex-CISA Employee Billed 33-Hour Days Across Secret Contractor Jobs

    A former CISA employee pleaded guilty to a federal false claims charge for secretly holding multiple federal contractor jobs while employed full-time at the agency, at one point billing 33-hour days across four simultaneous positions. Richeline Anisso Fung must repay nearly $250,000 for the scheme, which ran from 2021 to 2024 and went undetected by both CISA and the contractors who employed her. The case exposes a remote-work oversight gap that flourished during the federal cyber hiring boom, the kind of fact pattern that makes primes and contractors ask who on their own payroll might be doing the same thing.

  • procurement/independent

    CAS Board Doubles Full-Coverage Threshold to $100M

    The CAS Board published two final rules September 1, effective October 1, that double the full-coverage threshold from $50M to $100M, raise the basic coverage threshold from $2.5M to $35M, and eliminate the trigger-contract framework. The Board also rescinded CAS 407, which governed standard-cost accounting for direct material and direct labor. More than 200 entities stand to shed full CAS obligations. But the rules cut both ways: single-award IDCs will now be assessed for CAS applicability at the ceiling value, not the task-order level, meaning some contractors will face full CAS on vehicles they'd structured to stay under the old threshold.

  • enforcement/judicial

    Honeywell Aerospace Pays $2.04M to Settle DFARS Cyber FCA Case

    Honeywell Aerospace Inc. agreed to pay $2,042,518 to resolve False Claims Act allegations that it failed to comply with cybersecurity requirements in a Department of Defense contract. The DOJ press release does not specify which DFARS controls were at issue or what contract was involved. Honeywell Aerospace was a business segment of Honeywell International Inc. until June 29, when it became a standalone public company. The settlement follows a pattern of CCFI enforcement actions against defense contractors, including the $8.4M Raytheon/Nightwing settlement and the $4.6M MORSECORP settlement earlier this year.

  • procurement/independent

    SBA proposal would add 114,541 firms to small-business rolls

    SBA issued a proposed rule August 20 resetting small-business size standards across the economy. The net effect: roughly 114,541 additional firms become eligible for small-business set-asides, including an estimated 37,002 that already hold FY2025 federal contracts. Fewer than 200 firms lose eligibility (SBA blocked every proposed reduction, explicitly citing 2021) 2024 inflation and regulatory burdens. The methodology powering the rule is itself out for notice-and-comment, with both dockets closing September 21. Meanwhile, the old 1,500-employee ceiling disappears for manufacturing and defense-industrial codes, pushing shipbuilding from 1,300 to 2,300 employees and oil-and-gas drilling from 1,000 to 2,650. The expansion doesn't touch SBIR/STTR, where a separate 500-employee cap remains locked.

  • supply-chain/trade-press

    Australia arrests two TeamPCP members after months of supply-chain attacks

    Australian Federal Police arrested two Western Australia men Wednesday for their alleged roles in TeamPCP, the cybercrime group whose supply-chain attacks on open-source software compromised more than 1,000 organizations including the European Commission and GitHub. The coordinated arrests, involving the FBI and Western Australia Police, mark the first time active software supply-chain operators have faced prosecution, breaking a pattern of near-total impunity outside US jurisdiction.

  • enforcement/trade-press

    Contractor may have used Grok to falsify VA financial records, CBCA finds

    The Civilian Board of Contract Appeals found that Venergy, a VA construction contractor, may have used Grok AI to alter audited financial statements during discovery, concealing contract data behind electronic white boxes on three years of filings. The board dismissed Venergy's $4.23 million claim against the VA as a sanction, while a VA OIG criminal investigation proceeds in parallel. The case is the first time a procurement tribunal has found generative AI used to manipulate discovery documents, and it lands just as GSA announced $13 billion in suspected procurement fraud, underscoring how far detection capabilities trail the tools available to bad actors.

  • enforcement/judicial

    DOJ Disrupts QScan, QTRouter Platforms Used by Chinese State Hackers

    DOJ and FBI announced court-authorized domain seizures to deny Chinese state-sponsored hackers access to QScan and QTRouter, two complementary hacking platforms used to target U.S. critical infrastructure and other sensitive networks. The operation follows the January 2024 Volt Typhoon botnet takedown and last September's Flax Typhoon disruption, the third major court-authorized action against PRC-state hacking infrastructure in 18 months. The pace suggests infrastructure disruption has moved from exceptional remedy to standard operating procedure.

  • enforcement/trade-press

    DOJ expands Mabna hacking case to 17 defendants

    Federal prosecutors unsealed a superseding indictment Tuesday adding eight defendants to the 2018 Mabna Institute case, bringing the total to 17 Iranian nationals. The group allegedly stole at least 31.5 terabytes of research and intellectual property from 144 U.S. universities, 42 U.S. companies (including unnamed defense contractors) and at least five federal and state government agencies over roughly a decade. The expanded charges tie the operation directly to Iran's Islamic Revolutionary Guard Corps. The defendants remain in Iran; the State Department is offering up to $10 million for information on five of them.

  • fca/trade-press

    FCA whistleblower recoveries hit record $6.8B as cybersecurity fraud enters spotlight

    The Justice Department secured a record $6.8 billion in False Claims Act settlements and judgments in FY2025, driven by 1,297 qui tam whistleblower suits, also an all-time high. Relators collect 15% to 30% of any recovery under the FCA, and the statute's first-to-file rule bars everyone except the first whistleblower to file on a given fraud scheme, regardless of who holds better evidence. Cybersecurity fraud, including knowing misrepresentation of NIST SP 800-171 or CMMC compliance status, is explicitly within FCA scope. The arithmetic for defense contractors is unforgiving: an insider who documents a compliance gap before the company self-discloses stands to capture a significant share of what DOJ recovers.

  • enforcement/trade-press

    Moucka pleads guilty in 165-firm Snowflake breach campaign

    Connor Riley Moucka pleaded guilty Wednesday in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy for his role in the 2024 Snowflake breach campaign. The 26-year-old Canadian faces up to 32 years at sentencing on October 27. Moucka and co-conspirators used stolen credentials, some valid since 2020, to access Snowflake accounts at 165 companies including AT&T, Ticketmaster, and Santander, netting about $2.5 million in ransoms. Prosecutors said Moucka re-extorted at least one victim using stolen data from a government officer's family. He's the third ring member to face accountability after former U.S. soldier Cameron Wagenius's guilty plea last July and John Binns's detention in Turkey.

  • enforcement/trade-press

    DOJ expands Mabna Institute cybertheft charges to 17

    The Justice Department unsealed a superseding indictment Tuesday against 17 Iranian nationals affiliated with the Tehran-based Mabna Institute, expanding the 2018 case that charged nine. The indictment alleges a state-directed campaign that compromised more than 100,000 professor email accounts across 144 U.S. universities and 178 institutions abroad, exfiltrating 31.5 terabytes of academic research and intellectual property. U.S. universities spent approximately $3.4 billion to procure the type of data targeted. The State Department's Rewards for Justice program offers up to $10 million for information on four defendants. None of the 17 are in U.S. custody, and Iran doesn't extradite, the practical effect is unchanged from 2018.

  • procurement/independent

    SBA Drops Race Presumption from 8(a) Disadvantage Rules

    On August 11, SBA issued a final rule formally removing the race-based rebuttable presumption of social disadvantage from the 8(a) Business Development Program, codifying the framework that's been in place since the 2023 Ultima Services ruling. New individually-owned applicants must now provide evidence that their racial, ethnic, or cultural group faced discrimination and self-certify they suffered "material harm", defined as lost access to or diminished economic opportunity. Current 8(a) participants are grandfathered; the rule takes effect September 10.

  • procurement/independent

    COFC Finds Jurisdiction Over SBIR Phase III Protests

    The Court of Federal Claims ruled in Strategi Consulting v. United States that it has jurisdiction to hear protests over SBIR Phase III awards, rejecting the Air Force's three arguments for dismissal: that no "procurement" occurred under the Tucker Act, that the FASA task order bar applied, and that the claim lacked redressability. The court applied a preponderance-of-evidence standard and found the Air Force had reviewed Strategi's Phase III proposal, declined to award the contract but requested its codebase, then routed similar TacSRT work to other contractors under existing task orders. For SBIR Phase II performers who watch their follow-on work get handed to someone else, the decision clears a path to COFC that the government argued didn't exist.

  • dfars/independent

    TINA Threshold Hits $10M; FAR Still Shows $2.5M

    The Truthful Cost or Pricing Data threshold for DoD contracts rose from $2.5 million to $10 million on July 1, 2026, per FY 2026 NDAA Section 1804(c). The statute is operative on its own terms, but FAR 15.403-4 still recites $2.5 million and implementing DFARS rules haven't caught up. Because the change keys to contract date and is not retroactive, the two thresholds coexist for years. Primes and subs must segregate pre- and post-July 1 actions immediately: a modification to a legacy contract still triggers certification at $2.5 million, and misapplying the threshold on a $2.5 million to $10 million deal exposes contractors to downward price adjustment plus interest and potential False Claims Act risk.

  • procurement/trade-press

    GSA Uncovers $13B in Suspected Procurement Fraud Since March

    GSA announced Tuesday it has flagged $13 billion in suspected procurement fraud since March 2026, the largest figure in agency history. The estimate draws on contracting data, public reporting, and IG enforcement information, produced in collaboration with the White House Task Force to Eliminate Fraud. Cases are being referred to the OIG and DOJ. But fraud.gov tells a quieter story: just $29.5 million recovered and $202.2 million prevented through administrative action since January 2025. GSA provided no examples of specific fraud cases in its release, and the agency didn't respond to requests for comment on the fraud.gov listing.

  • enforcement/trade-press

    DOJ and SBA target 8(a) pass-throughs that lack genuine control

    DOJ and SBA are coordinating enforcement against 8(a) contractors who function as pass-throughs: entities holding set-aside contracts without performing substantive work or exercising genuine managerial control. Recent settlements, including a $21.3M SDVOSB case, show investigators examining operational reality. They're asking who makes decisions and who does the work, and whether the 8(a) firm controls its own billing. The burden is shifting onto contractors to prove genuine control, and SBA hasn't defined what that requires.

Open questions

  • 01How many CCFI cases reference NIST 800-171 compliance representations as the predicate?
  • 02Are settlements moving toward higher dollar figures over time?
  • 03When does the first criminal referral connected to CMMC or FedRAMP misrepresentation appear?

Sources we watch

Earlier coverage