Law.com Subscribers SAVE 30%

Call 855-808-4530 or email [email protected] to receive your discount on a new subscription.

The DOJ Goes Phishing: The Rise of False Claims Act Cybersecurity Litigation

By Annie Railton, James Gatta, Jud Welle and Emily Notini
March 01, 2022

This past October, Deputy Attorney General Lisa Monaco announced the launch of the Department of Justice's (DOJ) Civil Cyber-Fraud Initiative targeting entities and individuals that fail to follow government cybersecurity standards. Under the initiative, to be led by the Fraud Section of the Civil Division's Commercial Litigation Branch, the DOJ announced that it would utilize its powerful enforcement tool — the False Claims Act (FCA) — to pursue cybersecurity-related fraud by government contractors and grant recipients. Shortly after the announcement, in remarks at the Cybersecurity and Infrastructure Security Agency (CISA) 4th Annual National Cybersecurity Summit on Oct. 13, 2021, DOJ Civil Division acting Assistant Attorney General Brian Boynton described three "prime candidates" for potential FCA enforcement under the initiative: 1) providing products or services that fail to comply with cybersecurity standards; 2) misrepresenting security controls and practices; and 3) failing to timely report suspected cybersecurity breaches.

The DOJ's initiative comes alongside increased government activity to curb cybersecurity and government contractor risks. Earlier last year, emphasizing this new focus on cybersecurity and compliance, President Biden issued an Executive Order on Improving the Nation's Cybersecurity (EO 14028), which called for, among other things, federal agencies to adopt updated contractual requirements for information technology (IT) and operational technology (OT) contractors to share information about potential cyber threats. In January 2022, President Biden signed a National Security Memorandum to Improve the Cybersecurity of National Security, Department of Defense, and Intelligence Community Systems, calling out cybersecurity as a national security and economic security imperative for the administration. And on Feb. 9, 2022, the Securities and Exchange Commission (SEC) announced upcoming new rules requiring registrants to maintain cybersecurity polices and standards and report significant cyber incidents to the SEC, among other things.

This premium content is locked for Entertainment Law & Finance subscribers only

  • Stay current on the latest information, rulings, regulations, and trends
  • Includes practical, must-have information on copyrights, royalties, AI, and more
  • Tap into expert guidance from top entertainment lawyers and experts

For enterprise-wide or corporate acess, please contact Customer Service at [email protected] or 877-256-2473

Read These Next
The DOJ's Corporate Enforcement Policy: One Year Later Image

The DOJ's Criminal Division issued three declinations since the issuance of the revised CEP a year ago. Review of these cases gives insight into DOJ's implementation of the new policy in practice.

The Bankruptcy Hotline Image

Recent cases of importance to your practice.

Use of Deferred Prosecution Agreements In White Collar Investigations Image

This article discusses the practical and policy reasons for the use of DPAs and NPAs in white-collar criminal investigations, and considers the NDAA's new reporting provision and its relationship with other efforts to enhance transparency in DOJ decision-making.

How AI Has Affected PR Image

When we consider how the use of AI affects legal PR and communications, we have to look at it as an industrywide global phenomenon. A recent online conference provided an overview of the latest AI trends in public relations, and specifically, the impact of AI on communications. Here are some of the key points and takeaways from several of the speakers, who provided current best practices, tips, concerns and case studies.

The DOJ's New Parameters for Evaluating Corporate Compliance Programs Image

The parameters set forth in the DOJ's memorandum have implications not only for the government's evaluation of compliance programs in the context of criminal charging decisions, but also for how defense counsel structure their conference-room advocacy seeking declinations or lesser sanctions in both criminal and civil investigations.