Another defense contractor is paying six figure fines after settling with the Department of Justice for allegedly failing to comply with DFARS clause 252.204-7012. The kicker: their own employee blew the noncompliance whistle and got a cut of penalty money. This is the fifth such settlement in 2025 and the DOJ is crystal clear that the don’t discriminate just because a company is small.
Transcript
[Music]
All right, folks. It is December of 2025, almost the end of the year, and wouldn’t you know it, another False Claims Act whistleblower has been paid out by the defense contractor that they turned into the Department of Justice. Swiss Automation Incorporated has agreed to pay $421,234 to resolve alleged False Claims Act violations relating to its failure to provide adequate cybersecurity for certain drawings of parts that the company machined and supplied to Department of Defense contractors. They got turned in by their own employee, who’s going to get $65,000 for their troubles. This is the fifth cybersecurity settlement under the False Claims Act in 2025. Remember, CMMC verifies requirements that are already in your contracts. So don’t wait until you see a solicitation with CMMC in it to get compliant. The DOJ certainly isn’t. And that’s what we’re going to talk about today.
We were told at the beginning of the year that there were a bunch of these cases potentially going to be unsealed and that they were just like a jack-in-the-box piled in there, and we were just turning the crank every single day to see what pops out and if it’s an FCA case and if the clown’s happy, sad, or got a 10% discount because it turned itself in. Here we are. It’s a little different this time. It’s not a university. It’s not a major prime company. It’s a smaller company. And like we’ve said before when we’ve talked about other FCA cases involving smaller companies, this is one that people in the Defense Industrial Base can look at and see themselves in. Same scenario, same setup, not a lot of contracts. This was a 300-person company, and their $400,000 fine stems from a handful of purchase orders that they worked with. The employee said, “I don’t feel comfortable with what’s going on here. We have obligations. We’re not meeting them.” One thing led to another, and now they’re writing a check for way more than they got paid on the actual purchase orders thanks to the nature of the False Claims Act.
This comes straight from the DOJ’s press release. The Department of Justice says the settlement resolves allegations that Swiss Automation caused the submission of false claims by not providing adequate cybersecurity to safeguard certain drawings of parts that the company machined and supplied to defense contractors. Swiss Automation allegedly knew that the requirement to provide adequate security by implementing certain cybersecurity controls applied not only to DoD prime contractors but also to subcontractors and suppliers to those primes. The obligation to implement security controls specified in NIST SP 800-171 to protect certain DoD information, DOJ’s words here, has applied to DoD contracts, subcontracts, and similar contractual instruments since 2017 and will continue under the CMMC program that DoD recently finalized. We’ve said this multiple times. CMMC is just the verification mechanism for existing requirements that have been in contracts for a long time. Every DOJ settlement regarding cybersecurity under the False Claims Act refers to noncompliance with existing requirements, nothing to do with CMMC itself.
Sometimes in these cases you see companies say, “Oh, we didn’t know.” We’ve talked about that excuse before. But clearly in this settlement it says that they knew and grossly negligently ignored it. You might think that the penalty would be much harsher in that situation than in cases where organizations self-report. The nature of the fine is highly variable, although it’s always significant. If you accept the terms of the contract, according to the way the lawyers look at it, you know what’s in your contract. If you weren’t aware of what you signed up for, that’s your problem. That doesn’t provide a legal defense. If you didn’t know what was in your contract, sorry about it. Read your contracts.
The False Claims Act is a federal statute originally enacted in 1863 in response to defense contractor fraud during the American Civil War. According to the government, the Act provides that any person who knowingly submits or causes to submit false claims to the government is liable for three times the government’s damages plus a penalty linked to inflation. The size of the fines is determined by the value of the contract, not the size of the company. The Department of Justice routinely goes after individuals for fraud under the False Claims Act. No one is too small to be a target. This is the fifth cyber False Claims Act settlement in 2025, and they’ve gone after everybody from mega corporations to 100-person defense subcontractors.
Back in March, Morse Corp had a $4.6 million settlement. In May, Raytheon and Nightwing had an $8.4 million settlement. In July, Aero Turbine settled for $1.75 million. In September, Georgia Tech Research Corporation settled for $875,000. And now in December 2025, Illinois Precision is paying $421,000 under the False Claims Act. In some cases, like Aero Turbine, other parties such as private equity firms were involved. They don’t just go after a specific corporate entity. There are no exclusions. If you’re doing something wrong, no one is safe.
The majority of False Claims Act cases go after healthcare fraud, Medicare fraud, nursing homes, and things like that. During COVID, they went after individuals committing fraud under programs like the Paycheck Protection Program. They go after gigantic corporations, individuals, and everything in between. But the thing about the False Claims Act that should really get your attention as a defense contractor is the whistleblower provision. In addition to allowing the United States to pursue perpetrators of fraud on its own, the Act allows private citizens to file suits on behalf of the government against those who have defrauded the government. Private citizens who successfully execute these actions may receive a portion of the government’s recovery, typically 10 to 30 percent of the fine. They take the value of all the contracts for which you submitted a false claim, hit you for triple damages, and then the whistleblower gets 10 to 30 percent of those fines.
For example, in the Morse Corp settlement, the whistleblower got 18.5 percent of $4.6 million, and the company also had to pay almost $200,000 in legal fees for the whistleblower. In the Raytheon and Nightwing settlement, the whistleblower got about $1.5 million. In the Aero Turbine case, they self-reported but still paid almost $2 million. Georgia Tech’s whistleblower received $21,000. In the Illinois Precision case, the quality manager who blew the whistle received $65,000. The percentage varies, and it would be helpful to have more experts explain why sometimes it’s 10 percent and sometimes 30 percent. Either way, the people blowing the whistle are often not high-level executives. They can be quality managers or other employees. They’re highly incentivized. Probably the biggest insider risk inside your company, if you’re not compliant with your contractual requirements, is your own employees. Out of the five cybersecurity False Claims Act settlements this year, four involved whistleblowers walking away with significant payouts.
We did an entire episode outlining the basics of DFARS clause 252.204-7012. The entire CMMC program exists largely to verify compliance with that clause because there is no inherent proof to the government that you’re complying. They’re just taking your attestation. If you handle controlled DoD information on your information system, you operate what’s known as a covered contractor information system. Pursuant to DFARS 252.204-7012, if you submit invoices without complying with that clause, you are making a false claim to the government. Previous False Claims Act cases have held that cybersecurity compliance is material to the contract. Therefore, the government can pursue treble damages for triple the value of the contract.
From the most recent settlement, Assistant Attorney General Brett Shumate of the DOJ Civil Division said they will continue efforts to hold defense contractors, subcontractors, and suppliers accountable when they fail to honor their DoD cybersecurity commitments. Special Agent in Charge Jason Sarenski from the DoD Inspector General’s Defense Criminal Investigative Service echoed that they will hold contractors accountable when they fall short of their cybersecurity obligations. They all say the same thing: you have these obligations. If you don’t meet them, they’re coming after you.
Some people don’t like being told that these obligations have been in their contracts all along. They call it fear, uncertainty, and doubt. But we’ve had multiple settlements just this year alone, with companies paying hundreds of thousands or millions of dollars. It’s only fear, uncertainty, and doubt if it’s not true. The False Claims Act has been around since 1863. If you submit an invoice and didn’t do what the contract requires, the government has an avenue to pursue you for making a false claim.
The Department of Justice obtained more than $2.9 billion in settlements and judgments from civil cases involving fraud and false claims against the government in fiscal year 2025 alone. That’s an enormous amount of money. Only a small fraction so far has come from cyber civil fraud, but in 2021 the DOJ launched its Cyber Civil Fraud Initiative and said it would use its civil enforcement tools to pursue government contractors who fail to follow required cybersecurity standards. Every year since then, we’ve seen more of these settlements. They take time to work through the system, but they are ramping up. CMMC is DoD’s program. Cyber civil fraud enforcement is DOJ’s program. They’re related, but they’re not the same thing.
Every time a cyber False Claims Act settlement is posted, it gets massive attention. These things are real. They are happening. The DOJ is very interested in your compliance with DFARS 7012. Even if you’re not all that interested in pursuing CMMC certification, you should at least understand your contractual obligations. The DOJ recovered $2.9 billion last year, and they’re likely just scratching the surface. As taxpayers, that’s money being recovered for work that was paid for but not properly performed.
We’re at five cyber False Claims Act settlements for the year, and there will likely be more in 2026. Do you think the DOJ is right? Do you think the False Claims Act should exist? Do you think we’ll see more? Let us know in the comments. Like and subscribe. We’ll see you next week. See you next week.
[Music]
Contact
Speak With Our Team
Our team of compliance and cybersecurity experts are on standby and ready to help. We’ll walk you through what you need and what to expect.



