Watch hub·enforcement · qui-tam · civil-cyber-fraud · fca

Enforcement

Civil Cyber-Fraud Initiative settlements, qui tam unsealings, and the turn from voluntary to mandatory.

Updated ·RSS ↗

Cyber-compliance enforcement has accelerated through the Department of Justice's Civil Cyber-Fraud Initiative. This hub tracks settled and pending False Claims Act actions, GAO bid-protest decisions touching cyber clauses, and DCMA/DIBCAC findings as they become public — cross-cutting CMMC, FedRAMP, and state programs.

What changed in the last 30 days

  • dfars/independent

    DFARS Consultant-Lobbyist Ban Takes Effect With Rules Unresolved

    The Section 851 prohibition on defense contractors using consultants who lobby for covered foreign entities took effect June 30 via a DFARS class deviation, not formal rulemaking, after DoD abandoned DFARS Case 2025-D0007. The deviation tracks the statutory text and provides no guidance on the safe harbor for legal, audit, and tax compliance services. Contractors must now self-certify under 252.209-7012 without knowing which consultant arrangements qualify.

  • procurement/independent

    ASBCA blocks Army Corps bid to suppress KiewitPhelps ruling

    The Armed Services Board of Contract Appeals (ASBCA) on June 25 rejected the U.S. Army Corps of Engineers’ request to keep unpublished a May 4 merits decision in KiewitPhelps’ Offutt Air Force Base construction delay appeal; the ruling became public July 16. Contractors and agencies litigating under ASBCA protective orders still get a redaction process tied to FOIA exemptions. They do not get to trade publication away as part of a global settlement.

  • far/independent

    FAR Council squeezes termination settlements to 90 days

    The FAR Council proposed cutting the deadline for termination settlement proposals from one year to 90 days while leaving the underlying support burden intact. Primes, subcontractors and counsel would have to collect cost data, address inventory, develop profit positions and resolve subcontractor claims on a compressed clock. The efficiency case is obvious. So is the litigation risk if contractors pad estimates or file before the record is ready.

  • dfars/independent

    War Department pushes FOCI onto CUI contractors over $5M

    The Department of War’s proposed Defense Federal Acquisition Regulation Supplement (DFARS) rule on foreign ownership, control, or influence (FOCI) closed for comment July 6. It would require primes and subs on covered unclassified sensitive work, including controlled unclassified information (CUI), over $5 million to disclose and mitigate FOCI, with award blocked for noncompliance and nearly 40,000 entities affected by DoW’s estimate. Congress is moving in parallel: the Senate Fiscal Year 2027 National Defense Authorization Act would drop the threshold to $500,000, while an undefined commercial-contract national-security override stays loose enough to slow deals.

  • far/independent

    FAR Council consolidates supply-chain, CUI rules in Part 40 proposal

    The FAR Council's June 23, 2026 Part 40 proposal would pull supply-chain security restrictions from FAR Parts 4, 25 and 40 into one structure, add FAR-wide Controlled Unclassified Information obligations, impose a uniform reasonable-inquiry standard, and set a 72-hour reporting window for supply-chain violations. Primes, subs and counsel get a central hub, but not yet a settled answer on how agency-specific CUI clauses will run alongside it.

  • fca/regulator

    DOE lifts AFCA false-claim cap to $1 million

    The Department of Energy issued a final rule updating its Administrative False Claims Act regulations, raising the maximum claim amount from $150,000 to $1 million and extending DOE’s enforcement lookback. Primes, subs and counsel now have materially higher exposure for false claims, reverse false claims and written misrepresentations involving federal funds. The rule does not specify whether the higher cap reaches pre-rule conduct.

  • enforcement/trade-press

    Vardanyan pleads guilty in $1.2M Ryuk ransomware case

    Karen Serobovich Vardanyan, an Armenian national extradited from Ukraine last year, pleaded guilty to computer fraud and conspiracy to commit fraud and extortion for 2019 and 2020 Ryuk ransomware attacks, CyberScoop reported, citing DOJ. He agreed to nearly $1.2 million in restitution and faces up to 15 years. The admitted victims included U.S. companies and a Texas school; prosecutors said the broader crew received about 1,160 bitcoin, then worth more than $15 million.

  • enforcement/judicial

    Canadian-owned firms settle SBIR FCA claims for $223,618

    Advanced Global Services, Paradigm Shift Technologies and Gennady Yumshtyk agreed to pay $223,618 to settle False Claims Act allegations tied to Small Business Innovation Research awards funded by the Air Force and Navy. Contractors and counsel should treat SBIR eligibility representations as FCA-sensitive contract records. The settlement is modest and SBIR-specific, so it signals continued DOJ attention rather than a broader Civil Cyber-Fraud Initiative shift.

  • enforcement/trade-press

    Ryuk operator pleads as Blackcat/AlphV conspirator gets 70 months

    The Record reports that a man accused of deploying Ryuk ransomware pleaded guilty Wednesday in Oregon federal court to conspiracy and computer fraud. Separately, a Florida federal court sentenced another man to 70 months for helping the Blackcat/AlphV gang extort multiple victims. The operational lesson is narrow but real: extortion infrastructure changes names faster than the charging theories do.

  • enforcement/judicial

    Court gives former ransomware negotiator 70 months for BlackCat conspiracy

    A federal court sentenced Angelo Martino, a 41-year-old former ransomware negotiator from Land O’Lakes, Florida, to 70 months for conspiring with BlackCat/ALPHV actors to extort multiple U.S. victims and with other former cybersecurity professionals to attack additional victims in 2023. Contractors, managed service providers and executives should read this as an insider-risk case, not just another ransomware plea. DOJ’s target was the person inside the negotiation channel, not merely the criminals outside it.

  • enforcement/judicial

    DOJ sentences BlackCat ransomware negotiator to 70 months

    DOJ sentenced Angelo Martino, 41, of Land O’Lakes, to 70 months for conspiring with BlackCat/ALPHV actors to extort multiple victims and with other former cybersecurity professionals to attack additional victims in 2023. Contractors, managed service providers, C3PAOs and counsel should read this as counterparty-risk news: the person negotiating a ransomware demand may also understand exactly how to weaponize the response process.

  • procurement/independent

    GSA weighs Buy American labels for GSA Advantage

    The General Services Administration's June 24 Request for Information, citing Executive Order 14392, asks for July 24 comments on two GSA Advantage ideas: voluntary Buy American Act component-test representations that would trigger an icon and higher search placement, and a new original equipment manufacturer-only Special Item Number for selected categories. GSA Advantage contractors, resellers, manufacturers and federal buyers get no immediate mandate. After the Small Business Administration and GSA delisted 22 offerings over false Made in America representations, the catalog label carries certification risk.

  • enforcement/trade-press

    DOJ extradites Peter Stokes in Scattered Spider case

    The Justice Department says Peter Stokes, 19, was extradited to the United States last week and remains jailed in Chicago on conspiracy, cyber intrusion and fraud charges tied to Scattered Spider. Officials say the group has hit more than 100 businesses since 2022 and extorted more than $100 million worldwide. The alleged victims include a luxury jewelry retailer and a U.S. insurance company, which keeps this in the incident-response lane, not just the cybercrime gossip column.

  • procurement/independent

    1260H listing moves WuXi AppTec toward BIOSECURE procurement ban

    The June 8 Section 1260H update added WuXi AppTec to the Chinese military company list, putting the China-based contract research and manufacturing organization on a near-automatic path to BIOSECURE Act biotechnology company of concern (BCOC) status. Primes, subcontractors and Cybersecurity Maturity Model Certification third-party assessment organizations (C3PAOs) tied to federal biotech work should map WuXi AppTec research and development, manufacturing or testing use before procurement bars and termination risk land on active awards. OMB still has not published the formal BCOC list or a divestment deadline.

Open questions

  • 01How many CCFI cases reference NIST 800-171 compliance representations as the predicate?
  • 02Are settlements moving toward higher dollar figures over time?
  • 03When does the first criminal referral connected to CMMC or FedRAMP misrepresentation appear?

Sources we watch

Earlier coverage