DenseDefenseInsights
snippetSep 10, 2026

Cyber-fraud settlement watch

DoJ's Civil Cyber-Fraud Initiative settled $51.85M across eight cases in 2025 — up 233% over 2024. A running tally of what misreporting actually costs.


The Civil Cyber-Fraud Initiative is not theoretical enforcement. It is a growing list of contractors who certified a cybersecurity posture they did not have, and paid for it:

ContractorSettlementYearThe misrepresentation
MORSECORP$4.6M2025Reported SPRS 104; the true score was −142.
Health Net Federal$11.25M2025Falsely certified controls on a TRICARE contract.
Raytheon / RTX$8.4M2025No compliant System Security Plan.
Aerojet Rocketdyne$9.0M2022Misrepresented DFARS 7012 compliance.
Verizon Business$4.09M2023Falsely reported three controls — self-disclosed, earning a 1.5× multiplier.
Penn State$1.25M2024Non-compliant scores; no POA&Ms.
Georgia Tech$875K2025A score built on a fictitious environment.

Two patterns worth internalizing: whistleblowers (paid 15–30% of the recovery) initiated many of these, and self-disclosure earns credit — Verizon’s 1.5× multiplier instead of the statutory 3×. The contractors with a documented, honest record had something to disclose. The others had a number they could not defend.

Sources.
Settlements — DoJ press releases (MORSE, Penn State) and law-firm alerts citing the DoJ actions (Aerojet, Verizon, Raytheon, Health Net, Georgia Tech)
2025 CCFI totals (+233%) — Fluet Law; Mintz (Jan 2026)
Whistleblower share — 31 U.S.C. §3730(d)
← All insights