The Department of Justice recovered more than $6.8 billion in False Claims Act settlements and judgments in fiscal year 2025 — a record, announced January 16, 2026 — alongside the highest-ever number of qui tam (whistleblower) lawsuits filed: 1,297. The Civil Cyber-Fraud Initiative alone produced $51,849,634 across 8 settlements, a 233% increase over FY24's $15.5M / 4 settlements. Per Morgan Lewis, Mayer Brown, and Fluet.
What DOJ said about cyber
Deputy Assistant Attorney General Brenna Jenny called the cyber-FCA trajectory "significant upward." She emphasized that cyber-fraud cases are "not about data breaches" but instead "premised on misrepresentations" — i.e., the FCA hook is the contractor's certification, not the underlying compromise. Whistleblower share rose from $2.7M to $4.5M (+68% YoY). Since CCFI launched, DOJ has settled 15 civil cyber-fraud cases — more than half of those during FY2025.
Recent cyber settlement landmarks
- Raytheon/Nightwing — $8.4M for DFARS 7012 / FAR 52.204-21 controls failures
- Health Net Federal Services / Centene — $11.25M for false TRICARE cybersecurity certifications
- December 2025: precision machining supplier resolved DFARS 7012 inadequate-cybersecurity allegations (qui tam by former QC manager)
What to do
- Treat your cybersecurity certifications as the first FCA exposure surface — review who signs and what they're attesting to
- Build internal qui tam pre-emption: when a complaint is raised, document and remediate before it migrates to DOJ
- For grant recipients (universities, healthcare, research orgs): cyber-FCA enforcement extends past traditional defense primes