snippetSep 10, 2026
Cyber-fraud settlement watch
DoJ's Civil Cyber-Fraud Initiative settled $51.85M across eight cases in 2025 — up 233% over 2024. A running tally of what misreporting actually costs.
The Civil Cyber-Fraud Initiative is not theoretical enforcement. It is a growing list of contractors who certified a cybersecurity posture they did not have, and paid for it:
| Contractor | Settlement | Year | The misrepresentation |
|---|---|---|---|
| MORSECORP | $4.6M | 2025 | Reported SPRS 104; the true score was −142. |
| Health Net Federal | $11.25M | 2025 | Falsely certified controls on a TRICARE contract. |
| Raytheon / RTX | $8.4M | 2025 | No compliant System Security Plan. |
| Aerojet Rocketdyne | $9.0M | 2022 | Misrepresented DFARS 7012 compliance. |
| Verizon Business | $4.09M | 2023 | Falsely reported three controls — self-disclosed, earning a 1.5× multiplier. |
| Penn State | $1.25M | 2024 | Non-compliant scores; no POA&Ms. |
| Georgia Tech | $875K | 2025 | A score built on a fictitious environment. |
Two patterns worth internalizing: whistleblowers (paid 15–30% of the recovery) initiated many of these, and self-disclosure earns credit — Verizon’s 1.5× multiplier instead of the statutory 3×. The contractors with a documented, honest record had something to disclose. The others had a number they could not defend.
Sources.
← All insightsSettlements — DoJ press releases (MORSE, Penn State) and law-firm alerts citing the DoJ actions (Aerojet, Verizon, Raytheon, Health Net, Georgia Tech)
2025 CCFI totals (+233%) — Fluet Law; Mintz (Jan 2026)
Whistleblower share — 31 U.S.C. §3730(d)