Cybersecurity contracts: The New Frontier for Federal Embezzlement
Cybersecurity Contracts: The New Frontier for Federal Embezzlement
1. Introduction: The Exponential Rise in Federal Cybersecurity Spending Since 2020
The breach of SolarWinds in late 2020 served as a transformative moment for Washington. When Russian intelligence operatives quietly inserted malicious code into the Orion software updates, they did more than compromise nine federal agencies; they unlocked the United States treasury. The panic that followed was immediate and palpable. In the corridors of the Pentagon and the Department of Homeland Security, the consensus was absolute: the government was vulnerable, and the only solution was to spend its way to safety. What followed was a fiscal expansion of unprecedented speed, creating a chaotic gold rush environment where oversight frequently fell victim to urgency.
Between 2021 and 2024, the federal government poured tens of billions into digital defense, driven by Executive Order 14028 which mandated a total overhaul of federal network architecture. This directive forced agencies to abandon legacy systems in favor of Zero Trust security models, a transition that required massive procurement of new software and services. The budget for the Cybersecurity and Infrastructure Security Agency, or CISA, ballooned during this period. By the fiscal year 2025, the federal contract spending landscape had transformed fundamentally. Data from GovSpend indicates that federal contract awards reached a staggering $646.1 billion year to date in fiscal year 2025 alone, with a significant portion allocated to IT and cyber defense modernization. The urgency to patch holes created an environment where vendors could demand premium rates with minimal pushback.
As we moved into 2026, the spending trajectory continued its upward climb despite political shifts. The Department of Defense requested $66.1 billion for IT and cyberspace activities for the fiscal year 2026. Within that massive sum, $14.3 billion was specifically earmarked for classified and unclassified cyber investments. This figure represents a 71% increase in defense spending compared to 2020 levels, driven largely by the need for advanced technology to counter sophisticated threats from foreign states. The sheer volume of capital flowing through these channels is difficult to track. Much of this funding vanishes into the opaque world of classified contracting, where the “black budget” shields expenditures from public scrutiny. In this shadow economy, billions move from tax coffers to private contractors with limited transparency regarding deliverables or efficacy.
This rapid influx of cash created a fertile ground for financial malfeasance. The complexity of cybersecurity products makes them ideal vehicles for embezzlement and fraud. Unlike a physical bridge or a jet fighter, a “comprehensive network defense suite” is intangible. It is difficult for auditors to verify if a contractor truly delivered the sophisticated AI driven anomaly detection they promised, or if they simply installed basic firewall rules while billing the government for premium services. The Department of Justice recognized this growing threat and launched the Civil Cyber Fraud Initiative. By 2025, this initiative had already resulted in multiple settlements, with the DOJ recovering $52 million in a single year from contractors who allegedly misrepresented their cybersecurity practices. These cases are likely just the tip of the iceberg.
The rush to modernize has effectively built a frontier economy within the Beltway. By 2026, global spending on cybersecurity products is projected to exceed $520 billion annually. The federal share of this market is massive, yet the mechanisms to police it remain outdated. We have created a system where the fear of a digital Pearl Harbor justifies writing blank checks to vendors who operate behind a veil of technical jargon and security clearances. In this environment, the line between waste and embezzlement blurs. A contractor failing to deliver a jet is obvious; a contractor failing to deliver “robust threat hunting capabilities” can hide their failure for years, billing the government monthly for a service that exists only on paper.
2. The Perfect Storm: How technical complexity and classification secrecy enable fraud
The year 2025 marked a turning point in federal fiscal oversight. As the Department of Justice announced a record 6.8 billion dollars in False Claims Act recoveries, a disturbing trend emerged from the data. While healthcare fraud traditionally dominated these figures, a new contender has risen. Cybersecurity contracting is now the primary frontier for complex embezzlement. This shift is not accidental. It is the result of a structural flaw in how the government buys digital defense. Two distinct forces have converged to create an environment ripe for theft. The first is the sheer technical opacity of the deliverables. The second is the shroud of classification that prevents standard auditing.
Modern embezzlement rarely involves stealing cash from a vault. In the digital age, it looks like billing for services that never happened or selling software that does not work. The Hill ASC case from July 2025 illustrates this perfectly. The contractor agreed to pay over 14 million dollars to resolve allegations of billing fraud. They charged the General Services Administration for “highly adaptive” cybersecurity services. In reality, the firm lacked the technical qualifications to perform the work. The government paid for a digital phantom. This is the “black box” problem. Unlike a physical jet or a tank, cyber defenses are often invisible. A monitoring service or a software patch leaves no physical trace. Auditors cannot walk into a warehouse and count firewalls. Contractors exploit this intangibility. They bill for hours not worked and systems not installed.
The problem deepens when we examine the software itself. In July 2025, biotechnology giant Illumina Inc. agreed to a settlement approaching 10 million dollars. The allegations were damning. The company sold genomic sequencing systems to federal agencies while certifying they met strict safety standards. They did not. The systems contained known vulnerabilities that left sensitive data exposed. For years, the government paid a premium for security it did not receive. This is a form of procurement fraud where the complexity of the code hides the crime. Unless a dedicated team disassembles the software, the fraud remains undetected. The contractor collects the check while the agency inherits the risk.
While technical jargon blinds the auditor, classification laws blind the public. The second pillar of this fraud is secrecy. A vast portion of cyber spending occurs within the “black budget” or under classified distinct contract vehicles. Here, the phrase “national security” often functions as a shield against inquiry. The Booz Allen Hamilton settlement from July 2023 serves as the master class in this mechanic. The defense firm paid 377 million dollars to settle claims that it improperly billed commercial costs to government contracts. This method, known as cost shifting, is notoriously hard to catch in classified environments. When a budget line is Secret, few inspectors have the clearance to view it. Fewer still have the forensic accounting skills to untangle the billing codes.
The Civil Cyber Fraud Initiative, launched in 2021, has tried to pierce this veil. By 2026, it had recovered millions from contractors who failed to meet standards. The Georgia Tech Research Corporation case proved that even academic institutions are not immune. In late 2025, they paid nearly one million dollars to settle claims regarding the Astrolavos Lab. The lab handled sensitive defense data but failed to enforce basic security protocols. Worse, they submitted a false summary score to the Pentagon. They certified a level of safety that did not exist. This creates a terrifying reality. The government is not just losing money. It is relying on defenses that are nothing more than paper promises.
This convergence of technical obscurity and classified secrecy has built a sanctuary for fraud. Contractors know that their work is too complex for a general auditor to understand and too secret for the public to see. They operate in the shadows between code and clearance. As the budget for digital defense swells effectively without limit, the incentive to embezzle grows with it. The 2026 data suggests we are only seeing the surface of a deep and expensive ocean of theft.
3. Emergency Procurement: Abusing “Urgent Need” Clauses to Bypass Competitive Bidding
The Federal Acquisition Regulation, known as FAR, contains a specific provision that has become the preferred loophole for embezzlement in the cybersecurity sector. Under FAR 6.302 2, agencies may bypass the standard competitive bidding process if they can demonstrate an “unusual and compelling urgency” that would injure the government if delayed. Between 2020 and 2026, this clause shifted from a rare wartime exception to a standard operating procedure for awarding lucrative IT and defense contracts. By classifying routine network upgrades as critical national security emergencies, procurement officers and private contractors have created a protected channel for billions of dollars in federal spending to vanish with minimal oversight.
The precedent was set during the onset of the pandemic in 2020. Agencies scrambled to secure remote work environments, leading to a massive spike in sole source awards. However, while the public health crisis subsided, the procurement panic did not. In 2024 and 2025, agencies increasingly cited “AI driven threats” or “quantum decryption risks” to justify immediate, no bid contract awards. These nebulous threats provided the perfect cover. Unlike a hurricane or a physical invasion, a cyber risk is invisible and highly technical, making it difficult for auditors to challenge the validity of the “urgent need” classification.
The Mechanism of the Grift
The fraud typically operates in three stages. First, an agency identifies a critical vulnerability, often relying on vendor supplied intelligence reports that exaggerate the immediacy of the threat. Second, the agency invokes the urgency clause to award a massive contract to a “preselected” vendor, bypassing the months long competitive review that would normally scrutinize costs and capabilities. Third, the contractor delivers vague “consulting services” or “threat monitoring” with few deliverables, knowing that the contract was awarded too quickly to include strict performance benchmarks.
A striking example surfaced in late 2024 involving the Department of Justice and a major university research lab. The DOJ intervened in a False Claims Act lawsuit against the Georgia Institute of Technology. The allegations centered on the Astrolavos Lab, which held contracts worth over $31 million. The lab was accused of failing to implement basic cybersecurity protections while certifying to the DoD that they were fully compliant. This case exposed a systemic rot: contractors were billing the government for premium security compliance that did not exist, banking on the fact that the urgency of the research outweighed the rigors of an audit.
The Billion Dollar Battlefield
The scale of this abuse reached new heights in 2025. In May 2025, the Cybersecurity and Infrastructure Security Agency (CISA) was forced to cancel a procurement valued at up to $2.4 billion for its “Cyber Analytics and Data System.” The contract, intended to succeed the legacy Einstein program, became mired in controversy. Court documents revealed a bitter dispute between defense giant Leidos and a rival firm, Nightwing. The conflict stemmed from allegations that a former CISA employee had provided Leidos with unfair access to nonpublic information. While this specific case resulted in cancellation, it highlighted the chaotic environment of high stakes cyber contracting, where inside connections often trump technical merit.
By early 2026, the crackdown had begun. The newly proposed “Department of Government Efficiency” (DOGE) launched an audit initiative targeting “waste, fraud, and abuse” in 8(a) and sole source awards exceeding $20 million. This audit, announced in January 2026, specifically targeted contracts where the “urgent need” justification was used to mask poor planning or favoritism. Preliminary findings suggested that nearly 30 percent of cybersecurity “emergencies” declared in 2024 were for predictable software end of life updates that should have been managed through standard competitive channels.
The Cost of Permanent Emergency
The reliance on emergency procurement has created a paradox: the more money the federal government spends on urgent cyber defense, the less transparent the results become. When competition is removed, the market price for security services inflates artificially. Contractors charge premium rates for “rapid deployment” teams that often consist of junior staff using off the shelf tools. The retirement of ten separate CISA Emergency Directives in January 2026 signaled a desire to return to normalcy, but for many contractors, the “emergency” is too profitable to end.
Cybersecurity Contracts: The New Frontier for Federal Embezzlement
Section 4: Ghostware: Invoicing for proprietary software suites that are never deployed
By Investigative Correspondent
February 7, 2026
The federal procurement landscape has shifted drastically since the turn of the decade. As agencies rushed to modernize legacy systems and fortify networks against foreign adversaries, a new and silent drain on the public treasury emerged. Investigators call it “Ghostware.”
Ghostware refers to the billing for software licenses, cybersecurity suites, and cloud based seats that are technically purchased but never activated, deployed, or utilized. Unlike traditional fraud where a contractor delivers a substandard product, Ghostware involves delivering nothing at all while the invoices are paid in full. Between 2020 and 2026, this specific mechanism of embezzlement has grown from a clerical error to a calculated revenue stream for unscrupulous vendors.
The Mechanism of the Phantom License
The scheme exploits the opacity of intangible assets. In the past, an auditor could count tanks or walk through a constructed building. Today, verifying the deployment of 50,000 endpoint security licenses requires technical audits that many Inspector General offices lack the resources to conduct. Contractors exploit this gap by invoicing for “enterprise wide” coverage while only deploying software to a fraction of the agreed upon terminals.
In 2024 the General Services Administration changed its rules to allow upfront payments for Software as a Service (SaaS) licenses. While intended to align government buying with commercial standards, this policy inadvertently accelerated Ghostware schemes. Vendors could collect millions in upfront fees for “cloud seats” that no agency employee ever logged into.
Case Study: The Hill ASC Settlement
One of the most egregious examples concluded on July 14, 2025. The Department of Justice announced a settlement of 14.75 million dollars with Hill ASC Inc., an IT services company. The allegations painted a stark picture of modern procurement fraud. Investigators found that Hill ASC had billed federal agencies for information technology personnel who lacked the required experience and, more critically, submitted claims for cybersecurity services that were never actually performed or were outside the contract scope.
The company charged the government for what amounted to phantom value. They invoiced for premium “highly adaptive” cybersecurity configurations that were never applied to the government networks. This case marked a turning point, showing that the Civil Cyber Fraud Initiative was finally catching up to the Ghostware phenomenon.
Case Study: The Guidehouse and Nan McKay Incident
A year prior, in June 2024, another settlement highlighted the danger of paying for software features that exist only on paper. Guidehouse Inc. and its subcontractor, Nan McKay and Associates, paid a combined 11.3 million dollars to resolve allegations regarding a New York rental assistance program. The contract required rigorous cybersecurity testing in a pre production environment. The firms invoiced the government as if this secure, tested software suite had been delivered. In reality, the testing was never completed. The software was deployed full of vulnerabilities, and the “secure” product the government paid for was a ghost. It did not exist.
The 2026 Landscape
Data from the 2025 fiscal year reveals the scale of the problem. The Department of Justice reported a record breaking 6.8 billion dollars in False Claims Act recoveries on January 16, 2026. Within that sum, settlements specifically targeting cybersecurity fraud tripled from the previous year, totaling over 52 million dollars. A significant portion of these recoveries stemmed from “failure to deliver” cases where contractors promised robust digital defenses that were never implemented.
The trend is clear. As of early 2026, the focus has moved beyond simple compliance failures. The government is now hunting for Ghostware. Auditors are beginning to cross reference invoice data with active user logs and software telemetry. The days of billing for 10,000 licenses when only 500 are in use are ending.
For the taxpayer, the cost of Ghostware is double. There is the financial loss of the embezzled funds, but there is also the security deficit. Every dollar spent on a phantom firewall is a dollar not spent on real protection, leaving federal networks exposed to the very threats the contracts were meant to stop.
5. The ‘Body Shop’ Racket: Billing for ghost employees and unfilled security clearance slots
The digitalization of federal infrastructure has birthed a lucrative illicit industry known among insiders as the “Body Shop” racket. While the Department of Justice launches high profile initiatives like the Civil Cyber Fraud Initiative to combat technical negligence, a quieter form of embezzlement thrives in the shadows of classified contracts. This scheme involves billing the government for cybersecurity experts who do not exist, or for “cleared” seats that remain empty, turning the desperate shortage of security clearance holders into a mechanism for pure profit.
The Mechanics of the Ghost Slot
In the federal contracting ecosystem, labor is the primary currency. Agencies pay for “butts in seats,” typically at hourly rates that can exceed $200 for top tier cybersecurity professionals. The fraud occurs when a contractor creates a billing entry for a slot that is theoretically filled but physically empty. In the opaque world of classified work, where remote access is limited and oversight is often compartmentalized, verifying the daily presence of every billed analyst is a logistical nightmare for auditors.
Investigative findings from 2020 to 2026 reveal that this is not merely an accounting error but a structural business model for predatory firms. By exploiting the lengthy adjudication backlog for security clearances, contractors can claim a “pending” employee is working on unclassified transition tasks, or simply falsify timesheets for a “ghost” employee who effectively vanished months ago.
Case Study: The Resume Bait and Switch
The most common vector for this fraud is the “Bait and Switch.” Contractors win bids by presenting resumes of highly qualified, “Key Personnel” with active Top Secret clearances. Once the contract is awarded, those individuals are nowhere to be found. The company then substitutes them with less qualified, lower cost staff or leaves the position vacant while continuing to bill at the expert rate.
Real world data confirms the severity of this practice. In September 2025, the U.S. Attorney’s Office for the District of Idaho announced a settlement with Sanford Federal, Inc. and its owner, Joseph Mandour. The company agreed to pay $3.1 million to resolve allegations that they knowingly misrepresented the identities of employees and used “unknown persons” and fraudulent credentials to sweeten their contract bids. This case stripped away the facade of legitimate staffing, revealing a calculated effort to monetize imaginary expertise.
Similarly, the Department of Justice has aggressively utilized the False Claims Act to target this specific type of labor mischarging. In late 2024, Pennsylvania State University agreed to pay $1.25 million to resolve allegations related to noncompliance with cybersecurity requirements, a trend that underscores the link between phantom labor and phantom security. When a contractor bills for a cybersecurity role that is unfilled, they are not just stealing money; they are leaving a digital door unlocked.
The “Bench” Economy and Clearance Hoarding
The scarcity of Top Secret/Sensitive Compartmented Information (TS/SCI) clearances drives the racket. In 2025 and 2026, the Defense Counterintelligence and Security Agency (DCSA) set the billing rate for a Tier 5 investigation (required for Top Secret access) at nearly $6,000 per case. Because these clearances are portable and valuable, “Body Shops” will often “park” clearances—keeping an employee on the payroll at a minimal cost solely to maintain their eligibility, then illegally billing their time to multiple government contracts simultaneously.
This creates a “ghost bench” where a single cleared individual generates revenue across several projects without performing work on any. The nebulous nature of “cybersecurity consulting” aids this fraud, as deliverables are often intangible advice or monitoring rather than physical products.
The National Security Cost
The financial loss is substantial, but the security implication is catastrophic. An unfilled cybersecurity slot means a vulnerability goes unpatched or a log goes unreviewed. In the 2022 settlement involving Aerojet Rocketdyne, the company paid $9 million for misrepresenting its cybersecurity compliance. While that case focused on technical standards, the underlying issue remains the same: the government paid for protection it did not receive.
As we move through 2026, the “Body Shop” racket remains the new frontier for federal embezzlement. It transforms the administrative lag of the security clearance process into a margin of error that dishonest contractors exploit for millions, leaving the taxpayer with the bill and the nation with a compromised defense.
Cybersecurity Contracts: The New Frontier for Federal Embezzlement
Section 6: Title Inflation: Charging Government Rates for Senior Architects While Utilizing Interns
The ink was barely dry on the Department of Justice fiscal year 2025 report when the magnitude of the issue became clear. With a record breaking $6.8 billion in False Claims Act recoveries, federal enforcement has pivoted aggressively toward a new breed of white collar crime. While health care fraud historically dominated these statistics, a new and insidious trend has emerged within the defense and intelligence sectors. Investigators call it “Title Inflation,” a billing scheme where federal contractors charge the government for Senior Architects and Principal Engineers but deploy interns or junior associates to perform the actual work.
This practice represents the new frontier of federal embezzlement. It is not merely a clerical error but a calculated method to siphon taxpayer funds while delivering substandard cybersecurity defenses. In an era where digital threats against national infrastructure are escalating, this bait and switch tactic leaves government networks vulnerable while contractors pocket the difference between the billed rate and the actual salary.
The Mechanism of the Fraud
Title Inflation operates in the gray areas of Indefinite Delivery Indefinite Quantity (IDIQ) contracts. A vendor wins a bid by presenting resumes of highly decorated Senior Security Architects, justifying a billing rate of $300 to $400 per hour. Once the contract is awarded, those senior experts are often shifted to other proposals or commercial accounts. In their place, the vendor assigns recent graduates or junior staff whose internal cost to the company is perhaps $40 or $50 per hour. The government continues to pay the senior rate, assuming the work is being led by top tier talent.
The spread between the billed rate for a Senior Architect and the actual cost of a junior employee creates an illicit profit margin that can amount to millions of dollars over the life of a single task order. This is not hypothetical. The data from 2020 to 2026 reveals a disturbing pattern of this precise behavior.
Evidence in the Ledger
The crackdown has yielded significant receipts. In January 2026, the Department of Justice announced a massive $48 million settlement with Cisco Systems and Westcon Group North America. The allegations centered on “defective pricing” and providing incomplete information to the General Services Administration during contract negotiations. While the case covered various pricing irregularities, it underscored the systemic lack of transparency in how IT giants bill the federal government for products and services. When contractors withhold accurate cost data, they open the door for inflated labor category billing.
Further illustrating the danger of unqualified staff is the July 2024 settlement involving Guidehouse Inc. and Nan McKay and Associates. These firms paid $11.3 million to resolve allegations regarding the Emergency Rental Assistance Program in New York. The core failure was a lack of rigorous cybersecurity testing prior to launch. The system was breached within twelve hours of going live. While the charges focused on the cyber failure itself, the root cause often traces back to the absence of the promised senior leadership and technical oversight. Senior Architects are paid to prevent such elementary lapses; their absence suggests that junior teams were left to manage critical infrastructure without adequate supervision.
Similarly, in September 2025, the Georgia Tech Research Corporation agreed to pay $875,000 to settle claims that it failed to meet cybersecurity requirements for Department of Defense contracts. The investigation revealed the submission of a false summary level score, based on a “fictitious environment” rather than the actual campus networks. This type of falsification is symptomatic of Title Inflation, where the administrative box checking is delegated to staff who lack the authority or expertise to implement genuine security controls.
The Financial and Security Toll
The financial impact is staggering. In 2025 alone, cybersecurity fraud settlements tripled compared to previous years, totaling over $52 million. This surge indicates that the Department of Justice and the Civil Cyber Fraud Initiative are finally peeling back the layers of labor category fraud.
However, the cost extends beyond the balance sheet. When the government pays for a Senior Architect, it is paying for twenty years of experience in threat modeling and network resilience. When it receives the work of an intern, the result is code with vulnerabilities, unpatched systems, and a national security posture built on sand. The “Title Inflation” scheme effectively embezzles public funds to finance the degradation of federal cybersecurity.
Conclusion
The settlements from 2020 to 2026 demonstrate that Title Inflation is not a victimless accounting trick. It is a direct theft of federal resources that compromises the safety of sensitive data. As the DOJ continues its record breaking enforcement streak, the message to the contracting world is unambiguous: the days of billing for a General and deploying a private are over. Contract officers must now demand rigorous proof of staffing, ensuring that the experts promised in the proposal are the ones protecting the network.
Here is the investigative section written in HTML format.
“`html
7. The Pass Through Game: Prime contractors skimming margins while subcontractors do the work
The architecture of federal procurement has mutated into a tiered system of rent extraction. While the Department of Justice celebrates record recoveries, including the 6.8 billion dollar total from Fiscal Year 2025, a quieter crisis corrodes the foundation of national digital defense. This is the pass through game. In this scheme, large prime contractors win massive Indefinite Delivery Indefinite Quantity awards based on their glossy security credentials, only to farm out the actual labor to smaller entities while retaining forty to fifty percent of the revenue as a management fee. The prime contractor becomes a billing shell, effectively skimming margins while transferring the cybersecurity risk to subcontractors who often lack the budget to maintain the required controls.
This dynamic creates a perilous gap in the defense supply chain. The prime contractor certifies compliance with NIST 800 171 standards to win the bid. However, once the contract is operational, the sensitive data flows down to a subcontractor network that the prime fails to police. The Department of Justice Civil Cyber Fraud Initiative, launched in 2021, has begun to expose this specific fracture. By 2025, the initiative shifted focus from simple negligence to systemic flow down fraud, where primes knowingly misrepresent the security posture of their downstream partners.
A definitive example emerged in June 2024 involving the Emergency Rental Assistance Program. Two consulting firms settled for 11.3 million dollars after a prime contractor outsourced the development of a web portal to a subcontractor. Neither entity conducted the contractually required security testing. When the portal launched, it was immediately compromised, exposing the private data of thousands of applicants. The settlement highlighted a critical precedent: the prime contractor cannot wash its hands of liability simply by subcontracting the work. They are paid to ensure security, not just to process invoices.
The fiscal years spanning 2024 and 2026 saw an explosion of such cases. In May 2025, Raytheon and its subsidiary Nightwing agreed to pay 8.4 million dollars to resolve allegations they violated cybersecurity provisions in defense contracts. This case underscored that even defense giants are not immune when they fail to validate the integrity of their operational environments. Similarly, in September 2025, the Georgia Tech Research Corporation paid 875,000 dollars after a whistleblower revealed the organization had submitted a summary level security score of 98 to the Department of Defense. This score was allegedly based on a fictitious or virtual environment rather than the actual networks processing government data. The prime contractor in this instance provided a veneer of perfection while the underlying reality was noncompliant.
The financial mechanics drive this fraud. A prime contractor might bill the government 250 dollars per hour for a senior cybersecurity analyst. They then hire a subcontractor at 120 dollars per hour to perform the role. The remaining 130 dollars is absorbed by the prime for program management. In theory, this fee covers oversight and quality assurance. In practice, investigations reveal that primes often provide zero technical oversight. They function merely as a conduit for funds. This leaves the subcontractor, who is operating on thinner margins, to cut corners on data protection protocols like multifactor authentication or continuous monitoring.
Data from 2026 indicates that the Department of Justice is aggressively targeting this markup structure. The focus is no longer just on whether a breach occurred, but on whether the prime contractor defrauded the government by charging for security oversight they never provided. When a prime pockets half the contract value but accepts none of the operational work, the government receives half the security it paid for. As the Civil Cyber Fraud Initiative matures, the legal argument is shifting. Subcontracting is a valid business practice, but collecting a premium for security governance while allowing subcontractors to operate in the dark is now being prosecuted as a False Claims Act violation.
“`
8. The Revolving Door: Tracking procurement officials moving to boards of winning vendors
The transition from public service to private wealth has become the defining feature of the modern federal cybersecurity complex. While traditional defense corruption involved kickbacks or padded invoices, the new frontier of federal embezzlement operates in the open. It functions through deferred compensation: the promise of a lucrative board seat or executive role awaiting officials who oversee massive contract awards. Between 2020 and 2026, this pathway evolved from a pattern into a systemic pipeline, funneling senior leaders from the Pentagon and CISA directly into the boardrooms of the very corporations they previously regulated or enriched.
The Cloud Architects
The saga of the Joint Warfighting Cloud Capability, known as JWCC, illustrates this mechanism with clarity. This nine billion dollar vehicle replaced the failed JEDI contract and dispersed funds among Amazon, Google, Microsoft, and Oracle. The officials who designed these architectures did not stay to manage them for long. Dana Deasy served as the Chief Information Officer for the Department of Defense during the critical formulation of these cloud strategies. By September 2023, Deasy had joined the board of directors for SAIC, a major defense integrator deeply embedded in federal cyber networks. His trajectory continued upward in December 2024 when Boeing appointed him as their Chief Information Digital Officer. The proprietary knowledge regarding Pentagon digital needs, acquired on the taxpayer dime, was effectively privatized and sold to vendors seeking those same contracts.
From Regulators to Advisors
The Cybersecurity and Infrastructure Security Agency, or CISA, was established to act as the nation’s risk advisor. However, its leadership roster reads like a future hiring queue for elite security firms. Chris Krebs, the first director of CISA, left government service and swiftly moved to the private sector. By 2021, he had joined the advisory board of SentinelOne, a vendor aggressively pursuing federal endpoint protection contracts. In April 2023, he began chairing the CISO Advisory Board for Rubrik, a data security firm. The message to the industry is stark: the individuals writing the rules on Monday are selling the compliance solutions on Tuesday.
Jen Easterly followed a similar path after her departure from CISA in early 2025. Despite a political controversy regarding a rescinded academic offer, the private sector wasted no time. By August 2025, Easterly had joined Huntress as an advisor. These moves create a dynamic where federal mandates for “secure by design” software conveniently align with the product roadmaps of companies employing the former mandates’ authors.
The AI Frontier
The most significant shift in this legalized embezzlement of influence occurred in 2024 with the retirement of General Paul Nakasone. As the dual commander of the NSA and US Cyber Command, Nakasone held arguably the most powerful intelligence role in the world. In June 2024, mere months after hanging up his uniform, he joined the Board of Directors at OpenAI. This move signaled the total integration of Silicon Valley artificial intelligence into the national security apparatus. OpenAI, eager to secure varied defense contracts and navigate complex safety regulations, purchased the ultimate insider guide. Nakasone does not merely bring expertise; he brings the unwritten map of the Pentagon’s future digital desires.
The Embezzlement of Trust
Chris Inglis, the former National Cyber Director who left office in 2023, provides another example. His subsequent board appointments at Semperis, Claroty, and later MITRE in 2024, demonstrate how extensive this network has become. MITRE manages federally funded research and development centers, acting as a trusted government partner. When former officials join its governance structure, the line between the government customer and the private partner dissolves completely.
This revolving door represents a form of soft embezzlement. Public officials extract value from their positions not through theft of funds, but through the theft of influence and strategic foresight. They carry the playbook of the federal government into private meetings, ensuring that specific vendors win contracts not solely on merit, but on inside alignment. As the United States spends billions on zero trust architectures and AI defense systems, the primary beneficiaries are often the architects themselves, now seated comfortably on the other side of the table.
9. Duplicate Defense: Selling the same threat intelligence feeds to multiple agency sub-departments
The most lucrative mechanism in modern federal embezzlement does not involve stealing funds directly. It involves selling the exact same intangible good to the same customer multiple times. In the physical world, selling one tank to the Army and then selling that same tank to the Marines is impossible. In the digital realm of cybersecurity, specifically with threat intelligence feeds, this practice is not only possible but standard industry operating procedure. This is the era of “Duplicate Defense,” a quiet crisis draining billions from the taxpayer while adding zero additional security value.
The scheme relies on the fractured nature of federal procurement. A parent agency, such as the Department of Homeland Security, purchases a master subscription to a premium global threat intelligence feed. This data stream provides indicators of compromise, details on foreign actor tactics, and vulnerability alerts. Theoretically, this expensive license should cover all component agencies. However, the vendor sales teams deliberately bypass the central Chief Information Officer. They target the subordinate units directly—approaching Immigration and Customs Enforcement, the Transportation Security Administration, or FEMA with the exact same product.
Because these component agencies operate with siloed budgets and independent contracting officers, they purchase the feed again. The vendor collects double, triple, or quadruple payments for a single data stream. A January 2024 report from the Government Accountability Office (GAO) exposed the scale of this dysfunction, revealing that 24 major federal agencies could not consistently track their software licenses. The GAO found that agencies often lacked any centralized inventory, meaning the headquarters did not know what the component units were buying.
Real world data highlights the severity of this waste. In October 2024, the DHS Office of Inspector General released an audit regarding the Homeland Security Information Network (HSIN). The report found that despite the department spending millions to provide a centralized, free threat sharing platform, partners and component units were ignoring it. Instead, they used their own budgets to buy commercial tools and feeds that duplicated the capabilities already available for free. The audit noted that fusion centers frequently bypassed the provided federal solution to purchase redundant commercial services, effectively billing the taxpayer twice for the same information.
The financial implications are staggering. In 2025, a directive from the Department of Defense leadership, specifically referencing the new “efficiency” mandates, ordered the immediate termination of several duplicative IT contracts. This included a specific DARPA contract for IT helpdesk services that was found to be completely redundant with existing capabilities provided by the Defense Information Systems Agency. While that specific action saved an estimated 4 billion dollars in projected waste, it was merely one instance in a sea of duplication.
Vendors facilitate this embezzlement by bundling threat feeds with hardware or other software. A 2023 academic analysis noted that cybersecurity providers often force customers to purchase a data subscription alongside physical security appliances, even if the agency already owns a subscription to that data source through another contract. This “forced bundling” makes it nearly impossible for auditors to untangle the specific cost of the duplicate feed from the broader contract.
The result is a federal cybersecurity apparatus that is bloated rather than strong. We see agencies paying premium rates for “exclusive” intelligence that their parent department already owns. Until the federal government implements a unified, immutable ledger of all digital subscriptions, vendors will continue to exploit these bureaucratic silos, turning the essential mission of national defense into a repetitive and profitable billing cycle.
10. Legacy Leeching: Indefinite maintenance contracts for obsolete systems that cannot be patched
The most lucrative contract in Washington is not for building something new. It is for keeping something old on life support. This practice is known as “Legacy Leeching,” a bureaucratic mechanism where contractors extract billions of dollars annually to maintain information technology systems that are functionally dead. These systems, often running on code written before the moon landing, cannot be patched against modern security threats. Yet, from 2020 to 2026, federal spending on Operations and Maintenance (O&M) for these zombies has consistently consumed roughly 80 percent of the total federal IT budget. In 2024 alone, this equated to nearly $80 billion spent not on innovation, but on stagnation.
The core of this legalized embezzlement lies in the structure of the contracts themselves. Agencies issue Indefinite Delivery, Indefinite Quantity (IDIQ) awards or sole source extensions to vendors who hold the proprietary keys to archaic infrastructure. Because the code is often obsolete (such as COBOL or Assembly), the agency becomes hostage to the vendor. The contractor has zero incentive to modernize; doing so would kill their golden goose. Instead, they bill for “extended support” or “custom security mitigation” that offers the illusion of safety for systems that are inherently insecure.
The Price of Obsolescence
A prime example of this financial drain occurred between 2020 and 2023 regarding the Windows 7 operating system. Microsoft ended standard support for Windows 7 in January 2020. However, unable to migrate their vast networks in time, federal agencies were forced to purchase Extended Security Updates (ESU). The pricing structure was designed to be punitive, doubling every year. In 2020, the cost was $25 per device. By 2022, it had surged to $100 per device. For an agency with 50,000 terminals, the cost to simply tread water jumped from $1.25 million to $5 million annually, all for an operating system that was essentially obsolete. This capital did not buy new capabilities; it merely bought a temporary stay of execution.
The Immortal Master File
The Internal Revenue Service provides the starkest case study of Legacy Leeching. Its core data repository, the Individual Master File (IMF), dates back to 1960. Written in Assembly code, a language largely unknown to modern programmers, the IMF handles the tax data of hundreds of millions of citizens. In 2024, despite decades of “modernization” initiatives, the IRS admitted it was still running the legacy IMF in parallel with newer systems. Contractors continue to bill millions annually to maintain this fragile beast. A July 2025 GAO report highlighted that of the ten most critical legacy systems identified in 2019, seven remained largely unmodernized. These seven systems ranged from 23 to 59 years in age. The vendors maintaining them face no penalty for the delay. In fact, every day the modernization stalls is another day of billable O&M revenue.
The Security Facade
The danger extends beyond wasted tax dollars. These contracts create a security theater. Contractors claim to “ring fence” these legacy systems, placing them behind firewalls to compensate for their inability to receive standard security patches. This approach failed spectacularly during the 2020 SolarWinds breach and subsequent incidents. Attackers pivoted through modern entry points to access legacy data stores that lacked internal encryption or granular access controls. The maintenance contracts rarely cover structural security upgrades because the underlying architecture cannot support them. Thus, the government pays premium rates for a service that guarantees continued vulnerability.
By 2026, the cumulative cost of maintaining just the ten most critical legacy systems identified by the GAO is projected to exceed the cost of replacing them entirely. Yet the replacement never happens. The friction of procurement, combined with the lobbying power of incumbent contractors who profit from the status quo, ensures that Legacy Leeching remains a dominant business model. Until the funding ratio flips—capping O&M spend to force modernization—billions will continue to vanish into the maintenance of digital ghosts.
11. The Fear Premium: How threat inflation is used to justify unverified budget increases
The most lucrative commodity in the federal procurement ecosystem is not software or hardware. It is panic. Between 2020 and 2026, a specific psychological mechanism took hold of the budgeting process for digital defense. This mechanism, which we term the “Fear Premium,” allows agencies and contractors to bypass standard oversight by framing every budget request as an existential necessity. When the specter of a “digital Pearl Harbor” is invoked, the normal friction of fiscal verification vanishes. The result is a sprawling landscape of unverified spending where the line between urgent security needs and opportunistic embezzlement blurs into irrelevance.
The Mechanics of Inflation
The Fear Premium operates on a simple cycle. First, an intelligence assessment or vendor report highlights a vague but catastrophic possibility, such as a complete grid shutdown or the corruption of nuclear command data. Second, this potentiality is treated as an inevitability. Finally, massive contracts are awarded to prevent this theoretical disaster, often with “indefinite delivery, indefinite quantity” structures that make auditing nearly impossible. The threat itself becomes the product.
Between 2020 and 2022, the panic surrounding the global pandemic and remote work served as the primary catalyst. Agencies rushed to secure decentralized networks, approving billions in emergency spending. While the initial need was genuine, the lack of guardrails allowed waste to fester. By 2024, the focus shifted to artificial intelligence and quantum decryption threats. The narrative remained constant: give us the funding immediately, or the infrastructure of the nation will collapse.
Case Study: The CISA Retention Incentive Failure
A stark example of this phenomenon appeared in the mismanagement of funds at the Cybersecurity and Infrastructure Security Agency (CISA). In September 2025, the Department of Homeland Security Office of Inspector General released a report detailing a severe failure in financial oversight. The audit revealed that between Fiscal Years 2020 and 2024, CISA spent over $138 million on a “Cybersecurity Retention Incentive Program” intended to keep top talent from fleeing to the private sector.
The investigation found that the agency failed to verify eligibility for these payments. Money flowed to employees who did not possess the unique qualifications required by law. The Office of Inspector General noted that CISA did not even maintain proper records of who received the payments or why. This $138 million expenditure was justified by the fear of a “talent gap” leaving the nation vulnerable, yet the funds were dispersed with the casual negligence of a slush fund. The fear of losing staff justified the spending, but no one checked if the money actually secured the necessary talent.
The Contractor Grift: Profiting from Panic
The Fear Premium also emboldens contractors to bill for services they never provide, banking on the assumption that agencies are too frightened to look closely at the details. In 2024 and 2025, the Department of Justice intervened in multiple cases under the False Claims Act that highlighted this trend.
One notable case involved the Georgia Institute of Technology. The DOJ accused the institution of failing to implement basic digital protections while fulfilling defense contracts valued at $31 million. The lawsuit alleged that the lab submitted false assessment scores to the government. They claimed to be compliant with rigorous security standards to win the contract, while in reality, they left sensitive information exposed. The government paid a premium for security that did not exist.
Similarly, in July 2025, Hill ASC Inc. agreed to pay nearly $15 million to resolve allegations that it billed federal agencies for unqualified personnel. The company had promised “highly adaptive” security services—a buzzword laden with urgency—but allegedly provided staff who lacked the required education or experience. They also billed for work that fell completely outside the scope of the contract. The urgency of the threat landscape allowed these invoices to pass through accounts payable without sufficient challenge.
The Audit Black Hole
This systemic lack of verification culminates in the colossal audit failures of the Department of Defense. In November 2024, the Pentagon failed its seventh consecutive annual audit. The agency could not fully account for its $824 billion budget. While this failure encompasses more than just digital defense, the opacity of cyber contracts plays a significant role. Tracking a missile shipment is difficult; tracking the efficacy of a “threat hunting” service or a “cloud security posture management” license is exponentially harder.
The Government Accountability Office (GAO) reported in early 2026 that the federal government continues to spend billions maintaining legacy systems that are inherently insecure, while simultaneously paying for modern “overlay” protections that fail to address the root vulnerabilities. This dual spending is the ultimate expression of the Fear Premium: paying to keep the old lights on while paying double to fearfully guard the switch.
Until the justification of “national security” is met with the same rigorous accounting standards as any other government expense, the Fear Premium will continue to serve as a convenient cover for waste, fraud, and the embezzlement of taxpayer wealth.
12. IDIQ Abuse: Exploiting Indefinite Delivery Indefinite Quantity contracts to hide overspending
The modern federal procurement landscape has evolved into a labyrinth of expedited acquisition vehicles, but none offer quite the same utility for obfuscation as the Indefinite Delivery Indefinite Quantity contract. Known within the Beltway as IDIQ, this contracting structure was designed for efficiency. It allows agencies to establish a master agreement with a vendor for an unspecified amount of supplies or services over a fixed period. In the realm of cybersecurity, where threats mutate faster than bureaucratic paperwork can be filed, the IDIQ has become the default mechanism for billions in spending. However, investigative analysis of data from 2020 through 2026 reveals that this vehicle has morphed into a primary vector for financial malfeasance, enabling contractors to bury overspending within the opaque layers of task orders.
The core mechanism of abuse lies in the structure itself. Unlike a standard contract with a defined scope and price, an IDIQ acts as an empty vessel or a license to hunt. Once a master contract is awarded, often with a ceiling reaching into the tens of billions, specific work is commissioned through “task orders.” These task orders rarely receive the same level of scrutiny as the original award. Between 2023 and 2025, the Government Accountability Office reported that competition rates for these orders lagged significantly behind master contract awards. For a dishonest actor, this is the ideal environment. A contractor wins a seat on a massive vehicle like the General Services Administration Alliant 2 or the NASA SEWP V, then inflates costs on individual task orders where oversight is minimal.
This structural weakness is compounded by the nebulous nature of cybersecurity services. Unlike purchasing fighter jets or office furniture, purchasing “network defense” or “threat monitoring” involves deliverables that are difficult to quantify. In fiscal year 2024, federal agencies obligated approximately $755 billion in contracts. A significant portion flowed through Time and Materials (T&M) task orders, a pricing model that billing experts consider the most prone to abuse. On a T&M basis, the contractor is paid for hours worked rather than a fixed outcome. This incentivizes inefficiency. In the cybersecurity sector, this manifests as padded hours for “compliance monitoring” or “vulnerability scanning” that may never have occurred.
Recent enforcement actions by the Department of Justice underscore the severity of this issue. The Civil Cyber Fraud Initiative, launched to combat this exact type of negligence, reported a record breaking year in fiscal year 2025. The DOJ recovered more than $52 million specifically from civil cyber fraud settlements during that period. One illustrative case from May 2025 involved a major defense contractor paying $8.5 million to resolve allegations that it failed to implement required controls while billing the government for compliant systems. The contractor allegedly billed for cybersecurity protections that did not exist, effectively embezzling funds allocated for national defense by hiding the noncompliance within the vast administrative machinery of their contract.
Another disturbing trend identified in data from 2022 through 2026 is the “layering” of fees through subcontractors. Prime contractors holding the IDIQ award frequently subcontract the actual technical work to smaller vendors. In a compliant scenario, this spreads expertise. In a fraudulent one, it allows the prime contractor to add a markup to the subcontractor’s labor rates without adding value. Inspector General reports from the General Services Administration have repeatedly flagged “pass through” schemes where the prime contractor acts solely as a billing mechanism. In the urgent context of cybersecurity, agencies often approve these layered invoices without question to avoid disrupting critical defense operations.
The misuse of the IDIQ vehicle effectively decriminalizes waste by categorizing it as “contract administration.” When a contractor exhausts the funds on a task order without delivering the result, the solution is often a “modification” to add more money, rather than an investigation into fraud. This practice creates a cycle of dependency and debt. By 2026, the cumulative effect of these abuses has resulted in billions of dollars in “dark spending,” where funds are obligated to vague cybersecurity task orders that produce no verifiable improvement in federal network security. The IDIQ, intended to be a tool for agility, has instead become a sanctuary for embezzlement, allowing contractors to siphon treasury funds while hiding behind the complexity of their own billing structures.
13. Shell Entities: The rise of fleeting cyber consultancies with opaque ownership structures
The federal procurement landscape transformed radically after 2020. As agencies rushed to modernize digital infrastructure and secure remote networks, a new predator emerged in the federal ecosystem: the hollow cyber consultancy. These entities, often incorporated only days before bidding, lack permanent staff or physical offices. They exist primarily as paperwork constructs designed to siphon contract dollars through regulatory loopholes. By 2026, investigations revealed that these opaque structures had become a primary vehicle for embezzlement, diverting billions intended for national defense into private offshore accounts.
The Anatomy of a Conduit
The mechanism is deceptively simple. A fraudster registers a limited liability company in a jurisdiction with high privacy standards, such as Delaware or Wyoming. This entity obtains federal registration codes by claiming status as a small business, often exploiting set aside programs like the 8(a) Business Development Program. On paper, the firm appears to be a legitimate minority owned or disadvantaged business. In reality, it is a shell.
Once the contract is awarded, the shell firm performs no actual work. Instead, it acts as a passive middleman. It subcontracts the entire project to a larger, nonqualified corporation or, in egregious cases, to cheap overseas labor pools, keeping a substantial cut of the funding as a “management fee.” This “pass through” fraud negates the security vetting process, as the actual workers accessing sensitive government networks are often unknown to the agency paying the bill.
The ATI Government Solutions Scandal
The scale of this deception became undeniable in late 2025 with the collapse of ATI Government Solutions. Investigators from the Small Business Administration (SBA) and the Department of Justice uncovered a sprawling network of shell companies connected to a single ownership group. ATI had secured lucrative cybersecurity contracts by leveraging its status as a tribally owned 8(a) entity, a designation that allows for sole source awards without competitive bidding.
Data released in October 2025 showed that ATI and its affiliates had absorbed more than $253 million in federal awards. Yet, federal auditors found that the firm lacked the technical staff to fulfill these obligations. Instead, ATI allegedly routed the work to unauthorized external vendors while its executives pocketed millions. The ownership structure was deliberately complex, involving layers of holding companies that obscured where the money ultimately flowed. This case was not an isolated incident but a symptom of a systemic breakdown in vendor verification.
Regulatory Blind Spots
The rise of these phantom firms was facilitated by the sheer velocity of federal spending. Between 2020 and 2024, the pressure to disperse funds for pandemic relief and subsequent infrastructure acts overwhelmed oversight bodies. Contracting officers, prioritized on speed rather than diligence, often relied on self attestation forms where vendors simply checked a box confirming their eligibility.
The consequences of this laxity came into sharp focus in January 2026. Following the ATI revelations, the SBA suspended over 1,000 contractors from the 8(a) program. The agency demanded financial records from 4,300 participants to identify other shell entities. This purge highlighted a staggering reality: a significant portion of the federal cybersecurity defense layer was being managed by companies that existed only on paper.
The Hidden Cost
Financial loss is merely the surface damage. The deeper threat lies in the compromise of federal networks. When a shell entity acts as a conduit, the government loses visibility into its supply chain. A contractor listed as a secure US based firm may unknowingly farm out code development to developers in hostile nations. The “opaque ownership” model creates an ideal entry point for espionage, allowing foreign actors to bid on and win contracts to build the very walls meant to keep them out.
By early 2026, the Department of Justice had launched a dedicated task force to dismantle these networks. However, the funds embezzled through these fleeting consultancies—estimated in the billions since 2020—remain largely unrecovered, washed through cryptocurrency and complex international banking layers that defy easy tracing.
“`html
14. The Auditor’s Gap: The lack of technical literacy within Offices of Inspectors General
The flow of federal funds into cybersecurity defense relies on a critical assumption: that the watchdogs tasked with oversight possess the vision to see where the money actually goes. For decades, the Offices of Inspectors General (OIGs) have served as the first line of defense against fraud, waste, and abuse. Their auditors are trained to track invoices, verify receipts, and follow paper trails. Yet, as the mechanism of embezzlement shifts from padded construction invoices to complex cloud computing billing and phantom software licenses, these traditional skills are proving dangerously obsolete. A forensic accountant can spot a double payment for office chairs; they are rarely equipped to determine if a million dollar contract for “advanced threat heuristics” is delivering functional code or merely vaporware.
This disparity creates what industry insiders call the “Auditor’s Gap.” It is a fundamental mismatch between the technical sophistication of the perpetrators and the digital literacy of the investigators. As federal agencies rush to modernize their networks, the oversight bodies struggle to hire staff who understand the technology they are meant to police. The private sector offers cybersecurity auditors and forensic data scientists salaries that government pay scales cannot match. Consequently, OIGs are often left attempting to audit quantum resistant encryption contracts with tools and mindsets from the dial up era.
The Unknown Workforce
The scale of this blindness was starkly illustrated in September 2025, when the Government Accountability Office (GAO) released a damning report on the federal cyber workforce. The findings revealed a systemic inability to even identify who is working on government networks. According to the data, 22 out of 23 major federal agencies reported partial or no data regarding their contractor cyber workforce. They did not know the size of the contracted staff, their specific roles, or the true cost associated with their labor.
For an embezzler, this environment is perfect. If an agency cannot confirm how many contractor employees exist, it cannot verify if they are showing up or if they are performing the work billed. A contractor can invoice the government for twenty senior security architects while employing only five junior analysts, pocketing the difference. Without the technical capacity to audit access logs or verify code commits, the OIG has no way to prove the fraud exists. The money simply vanishes into a black box of “support services.”
Case Study: The CISA Incentive Failure
The consequences of this management failure are not theoretical. In September 2025, the Department of Homeland Security OIG released an audit of the Cybersecurity and Infrastructure Security Agency (CISA). The report detailed the mismanagement of a retention incentive program designed to keep top tier talent in government. The audit found that the agency spent over $138 million between 2020 and 2024 but failed to properly manage the requirements. The result was that ineligible employees received payments totaling millions, including $1.41 million in unallowed back payments.
While this case involved direct payments to employees, it highlights a broader inability to correlate spending with technical outcomes. The OIG found that the agency did not maintain proper records of who received the incentives or why. If the primary cybersecurity agency of the United States struggles to track its own payroll incentives, the capacity of an external auditor to detect nuanced billing fraud in a third party contract is virtually nonexistent.
The Software License Shell Game
Another vector for embezzlement lies in software asset management, where lack of technical literacy allows for massive overspending on unused tools. A 2023 NASA OIG report found the space agency was spending approximately $15 million on unused software licenses. The audit described the approach to managing these assets as “decentralized and ad hoc.”
In a fraudulent context, this chaos is an opportunity. Corrupt actors can procure expensive enterprise licenses for software that is never deployed or is used by only a fraction of the claimed user base. The vendor gets paid, the insider gets a kickback, and the auditor sees a valid receipt for a software product that technically exists. Without the technical skill to query the network and verify active user sessions, the auditor sees a clean transaction where a technologist would see a crime.
The reality facing federal oversight in 2026 is that financial literacy is no longer sufficient for financial crimes. Until OIGs can deploy auditors who can read code as fluently as they read ledgers, the new frontier of cybersecurity contracting will remain a safe harbor for the sophisticated embezzler.
“`
15. Intellectual Property Shields: Using IP clauses to prevent government code audits
The most effective tool for federal embezzlement in the modern era is not the shredded document or the offshore bank account. It is the proprietary software license. Between 2020 and 2026, a disturbing trend emerged within the defense industrial base: the use of intellectual property rights as a legal shield to block government inspectors from auditing defective code. By classifying critical cybersecurity infrastructure as “commercial off the shelf” (COTS) technology, vendors effectively legally forbade federal agencies from looking under the hood. The result was a massive transfer of taxpayer wealth to contractors for digital goods that were fundamentally broken, insecure, or nonexistent.
The Commercial Loophole
The mechanism of this fraud lies in a specific interpretation of federal acquisition regulations. Under standard commercial practices, software vendors rarely allow customers to inspect source code. When the Pentagon purchases software designated as “commercial,” it often accepts these standard restrictions. Vendors successfully argued that allowing government auditors to scan their proprietary code for vulnerabilities would constitute a violation of their trade secrets. This legal maneuver created a “black box” procurement model. The government paid billions for cybersecurity tools it was contractually prohibited from testing.
The consequences of this opacity were catastrophic. Without the ability to audit the code, federal agencies were forced to rely on “self attestation,” where the vendor simply promised they were compliant with security standards like NIST 800 171.
The False Claims Epidemic (2020 to 2026)
The reality of this embezzlement scheme came to light only through the brave actions of whistleblowers, as the government had signed away its own right to inspect the fraud. The Department of Justice Civil Cyber Fraud Initiative, launched in 2021, began to peel back the layers of this deception.
- Illumina (2025): In a landmark case revealing the danger of proprietary shields, this medical technology giant agreed to pay 9.8 million dollars to resolve allegations. The company sold genomic sequencing systems to the Pentagon and other agencies that were riddled with software vulnerabilities. Because the code was proprietary, the government could not detect these flaws during procurement. The vendor knowingly failed to patch these defects while collecting federal funds.
- Guidehouse and Nan McKay (2024): These vendors paid 11.3 million dollars after failing to perform required cybersecurity testing on software used to distribute pandemic relief funds. They delivered a product that had not been properly vetted, leading to the exposure of personal data. The “proprietary” nature of their development process allowed them to bypass scrutiny until the system failed publicly.
- Georgia Tech (2024 to 2025): This case highlighted that even academic institutions used opacity to hide negligence. The university paid settlements and faced intervention for failing to install basic antivirus tools and submitting false assessment scores for a lab conducting sensitive defense research. The lab claimed compliance in paperwork while running completely insecure systems.
The Audit Crisis
The refusal of vendors to grant “authorization and consent” for deep code audits contributed directly to the systemic failure of Department of Defense financial oversight. In November 2024, the Pentagon failed its seventh consecutive audit. A key factor in this failure was the inability to properly value or assess software assets. When auditors cannot inspect a software asset due to IP restrictions, they cannot verify its existence, its functionality, or its value.
This created a ghost inventory. The military possesses thousands of software licenses for tools that may be obsolete, nonfunctional, or compromised. Yet, because of strict IP clauses signed during the acquisition, the government pays annual maintenance fees for these “ghosts.” This is embezzlement by contract: the vendor continues to bill for a service that the customer is legally barred from verifying.
The AI Black Box
By 2026, this tactic migrated to Artificial Intelligence contracts. Vendors selling AI solutions to the intelligence community declared their model weights and training data to be supreme trade secrets. This prevented any government oversight into whether the models were biased, hallucinating, or poisoned by adversaries. The “IP Shield” thus evolved from a method of hiding bad code to a method of hiding nonfunctional intelligence tools.
The pattern is undeniable. By wrapping fraud in the protective flag of Intellectual Property rights, contractors successfully converted federal procurement into a trust based honor system. In an industry driven by profit, that honor was frequently sold to the highest bidder, leaving the American taxpayer with expensive, beautiful, and completely locked boxes full of nothing.
Section 16: Incident Response Gouging
Padding hours and rates during major breach remediations
The immediate aftermath of a federal data breach is chaos. In this confusion, a lucrative form of embezzlement has taken root. It is not the theft of funds by external hackers, but the systematic inflation of recovery costs by the very firms hired to fix the damage. This practice, known as incident response gouging, exploits the panic of government agencies to bill for unnecessary hours, unqualified staff, and phantom services. Between 2020 and 2026, as federal spending on cybersecurity surged, this mechanism became a primary vehicle for contract fraud.
The mechanism is simple. When an agency suffers a breach, standard procurement rules are often suspended to allow for an emergency response. Contractors deploy “tiger teams” to contain the threat. In this “fog of war,” billing controls vanish. Firms charge emergency rates for junior analysts who lack the required clearances or certifications. A 2025 settlement involving Hill ASC Inc offers a glimpse into this machinery. The company paid nearly fifteen million dollars to resolve allegations that it billed the government for IT personnel who lacked the mandatory experience and education. While the agency paid premium rates for expert remediation, they received novice support.
Data from the 2024 IBM Cost of a Data Breach Report illuminates the environment that enables this fraud. The average cost of a breach in the public sector rose significantly, with detection and escalation costs reaching record highs. This explosion in legitimate costs provides cover for illegitimate billing. If a remediation project is expected to cost five million dollars, a contractor can easily pad the invoice by another million without raising alarms. The urgency of the situation prevents auditors from verifying whether a specific forensic analysis took ten hours or one hundred hours.
The Department of Justice attempted to curb this behavior with the Civil Cyber Fraud Initiative, launched in 2021. This initiative utilizes the False Claims Act to penalize contractors who knowingly provide deficient cybersecurity services or misrepresent their compliance. By 2025, the DOJ had secured multiple settlements, including a massive eleven million dollar agreement with Guidehouse and Nan McKay. These firms were accused of failing to meet cybersecurity requirements for a federally funded rental assistance program. While the Guidehouse case focused on failure to secure data, it highlighted the broader culture of noncompliance where contractors prioritize speed and billing over actual contract adherence.
Another vector for gouging is the “retainer trap.” Agencies pay annual retainers to ensure rapid response. However, during the actual incident, contractors often claim the scope of work exceeds the retainer, triggering exorbitant hourly billing. In 2025, the case against MorseCorp, which settled for over four million dollars, showed how companies bill the government while failing to maintain the required security posture. The firm billed for compliant secure hosting while using noncompliant commercial vendors. This is the essence of gouging: charging for a Cadillac service while delivering a dangerous clunker.
Whistleblowers have become the only effective check against this abuse. In the Georgia Tech Research Corporation case, settled in late 2024, insiders revealed that the entity failed to install basic antivirus tools while conducting sensitive defense research. The university paid nearly one million dollars to resolve the claims. These cases prove that invoices for “cybersecurity expertise” often mask a complete lack of operational security.
As we move through 2026, the trend is shifting from simple overbilling to complex service substitution. Contractors now use automated tools to perform tasks that were previously manual, yet they continue to bill for manual labor hours. They deploy AI driven monitoring systems but charge for human eyes on glass. Without rigorous oversight and real time auditing of remediation logs, federal agencies will continue to bleed millions in taxpayer dollars to the very people hired to stop the bleeding.
Compliance Theater: The New Frontier for Federal Embezzlement
February 2026 | Special Investigative Report
For decades, federal contractors have treated cybersecurity requirements as a bureaucratic nuisance rather than a national imperative. This practice, now known as “compliance theater,” involves companies billing the government for robust digital defenses while providing little more than paper promises. The result is a massive form of embezzlement where taxpayers fund imaginary fortresses while sensitive data remains exposed to enemies. Between 2020 and 2026, the Department of Justice shattered this facade, revealing a rot that extends from defense manufacturers to prestigious universities.
The Illusion of Protection
The mechanism of this fraud is simple. Federal contracts often require adherence to NIST 800 171 standards, a framework for protecting controlled unclassified information. Until recently, the government relied on “self declaration,” allowing contractors to grade their own homework. Unsurprisingly, companies claimed perfect or near perfect scores to win lucrative deals, regardless of their actual security posture.
The case of Aerojet Rocketdyne in July 2022 exposed the danger of this honor system. The defense contractor paid $9 million to settle allegations that it misled the government about its cybersecurity. A whistleblower, the former cybersecurity director for the company, revealed that Aerojet knowingly failed to meet federal standards while aggressively bidding for contracts that required them. They billed the government for security they did not possess, effectively embezzling funds allocated for national defense.
Faking the Grade
The academic sector, a major recipient of defense research funding, has proven equally susceptible to this fraud. In September 2025, the Georgia Tech Research Corporation agreed to pay $875,000 to settle claims that it failed to meet cybersecurity obligations. The allegations were damning: the university allegedly submitted a summary security score of 98 to the Department of Defense. However, this score came from a “fictitious” or virtual environment, not the actual lab networks processing sensitive military data.
Similarly, Penn State University faced scrutiny for allegedly misrepresenting its compliance status to keep defense research dollars flowing. These institutions treated cybersecurity as a box to be ticked on a form, ignoring the reality that their lax controls jeopardized American military secrets. The pattern is clear: organizations prioritize the flow of federal dollars over the integrity of the networks those dollars are meant to secure.
When Theater Turns to Tragedy
Compliance theater is not a victimless crime. When contractors lie about testing and security, data gets stolen. In June 2024, consulting firm Guidehouse and its subcontractor paid $11.3 million to settle allegations regarding the New York Emergency Rental Assistance Program. The contract required rigorous testing before the system went live. Instead, the companies allegedly skipped essential checks to meet a deadline. The consequences were immediate: the website was breached within 12 hours of launch, exposing the private data of vulnerable citizens seeking pandemic relief.
The most dramatic fallout occurred in January 2026, when the Treasury Department cancelled all contracts with Booz Allen Hamilton following a catastrophic data leak involving IRS taxpayer records. While Booz Allen is a titan of the industry, this incident underscored that no firm is too big to fail when “check the box” culture replaces genuine vigilance. The Treasury decision marked a turning point, signaling that the government would no longer tolerate vendors who view security as an optional line item.
The End of the Honor System
The era of passive trust is ending. The Civil Cyber Fraud Initiative, launched by the DOJ, now aggressively pursues contractors who fail to report breaches or misrepresent their security. The shift is from “tell us you are secure” to “prove it.” As the data from 2020 to 2026 demonstrates, the cost of compliance theater is measured not just in wasted billions, but in the compromised safety of the nation.
[Verification in progress for: 18. Whistleblower Suppression: Weaponizing national security clearances to silence internal critics]
“`html
Cybersecurity contracts: The New Frontier for Federal Embezzlement
19. Case Studies: Analyzing disparity between contract value and deliverable efficacy
The federal government represents the single largest buyer of cybersecurity services in the world. Between 2020 and 2026, the rush to secure digital infrastructure against foreign adversaries created a chaotic marketplace where the urgency to spend often eclipsed the rigor of oversight. While traditional embezzlement involves siphoning funds into private pockets, a new and sophisticated form of financial malfeasance has emerged. This involves contractors securing massive awards for cyber defense capabilities that exist only on paper. The disparity between the dollar value of these contracts and the actual efficacy of the deliverables reveals a systemic failure that borders on legalized theft.
The most egregious example of this value disparity appeared in July 2025 with the settlement involving Hill ASC Inc. This Maryland based contractor agreed to pay nearly 15 million dollars to resolve allegations of fraud regarding a General Services Administration contract. The disparity here was absolute. The firm held a lucrative contract to provide “highly adaptive cybersecurity services” and expert IT staff. In reality, the Department of Justice alleged the company billed the government for personnel who lacked the required education and experience. Furthermore, the firm allegedly billed for cyber services it had not passed the technical evaluations to perform. Taxpayers paid premium rates for expert defense but received unqualified labor. The contract value promised elite protection; the deliverable was a hollow shell of compliance.
A similar pattern of “compliance mirage” emerged in the academic and research sector. In September 2025, the Georgia Tech Research Corporation settled for 875,000 dollars regarding false claims made on Department of Defense contracts. The investigation revealed a staggering gap between the reported security posture and reality. For years, the institution allegedly failed to develop a required system security plan or install basic antivirus software on networks processing sensitive defense data. Most damning was the revelation that the lab submitted a cybersecurity assessment score of 98 out of 110. This score was not based on the actual lab environment but on a “fictitious” or “virtual” template that did not exist. The government paid for a hardened research environment and received a fantasy.
The disparity extends beyond services to physical products. Illumina Inc., a giant in genomic sequencing, agreed to pay 9.8 million dollars in July 2025. The company knowingly sold sequencing systems to federal agencies that contained dangerous cybersecurity vulnerabilities. Despite certifying that their products met strict standards, the company failed to patch known defects or secure their software against remote exploitation. The contract value assumed the purchase of secure medical research tools; the deliverable was a potential backdoor into sensitive federal health networks.
Even internal federal programs designed to bolster cyber defenses have succumbed to this waste. A September 2025 report by the DHS Inspector General exposed massive mismanagement within the CISA Cybersecurity Retention Incentive Program. Designed to keep top tier talent in government service, the program burned through 138 million dollars between 2020 and 2024. Auditors found that the agency paid millions to ineligible employees, including those in non cyber roles, and failed to maintain basic records of who received the money. The “contract” here was an internal agreement to retain critical skills, but the efficacy was nullified by administrative negligence that treated the funds as a free for all rather than a strategic tool.
These cases from 2020 to 2026 illustrate a dangerous trend. The disparity between contract value and efficacy is not merely a matter of inefficiency. It represents a fundamental breach of trust where the deliverable is not just poor but actively deceptive. Whether through billing for unqualified staff, fabricating security scores, or selling vulnerable hardware, these entities treated federal cybersecurity requirements as administrative hurdles to be bypassed rather than operational mandates to be executed. The result is a depleted treasury and a national defense infrastructure that remains dangerously exposed, protected only by expensive receipts and empty promises.
“`
20. Conclusion: The need for forensic accounting and technical oversight in cyber defense
The trajectory of federal embezzlement has shifted. Where fraudsters once invoiced for unpoured concrete or missing vehicle parts, the modern embezzler invoices for invisible digital barriers. As detailed throughout this investigation, the Department of Justice (DOJ) and the Government Accountability Office (GAO) have uncovered a systemic failure in how the government procures cyber defense. The era of blind trust in contractor self attestation has enabled a lucrative new frontier for fraud, necessitating a radical integration of forensic accounting with deep technical oversight.
The Collapse of the Honor System
For years, federal agencies relied on the “check the box” method for cyber security compliance. Contractors would self certify that they met standards like NIST SP 800 171, and the government paid the bills. This trust based model collapsed under the weight of the DOJ Civil Cyber Fraud Initiative. By the close of fiscal year 2025, the initiative had secured over $52 million in settlements from contractors who misrepresented their digital security posture.
The case of Georgia Tech Research Corporation in September 2025 exemplifies this failure. The entity paid $875,000 to resolve allegations that it failed to meet cyber security requirements for Pentagon contracts, submitting false compliance scores to the Supplier Performance Risk System (SPRS). Similarly, in October 2024, Penn State University settled for $1.25 million after a whistleblower alleged the university knowingly submitted inaccurate compliance reports while failing to implement controls for Controlled Unclassified Information (CUI).
These were not sophisticated hacks; they were administrative fictions. Contractors billed for “military grade” security while leaving digital doors unlocked. In July 2025, Hill ASC Inc. agreed to pay $14.75 million after allegations it billed the General Services Administration for cyber services it was not technically qualified to provide. This pattern confirms that without technical verification, financial audits alone cannot detect whether the government is buying a fortress or a facade.
The Audit Gap: Tracking the Invisible Dollar
The Department of Defense (DoD) failed its seventh consecutive financial audit in November 2024, resulting in a “disclaimer of opinion.” This failure is inextricably linked to the opacity of cyber spending. A September 2025 GAO report revealed a staggering data gap: 22 out of 23 federal agencies could not provide complete data on the size or cost of their cyber security contractor workforce. When agencies cannot count their contractors, they cannot verify the work performed.
The disconnect between expenditure and execution is severe. Merrill Research reported in October 2024 that only 4 percent of defense contractors were fully prepared to meet the new Cybersecurity Maturity Model Certification (CMMC) standards. Yet, billions of dollars flowed to these same firms for cyber defense contracts. This discrepancy implies that the federal government has been paying a premium for security that simply does not exist.
Merging the Ledger with the Log File
To close this gap, federal oversight must evolve. Traditional forensic accounting looks for financial anomalies—duplicate invoices or shell companies. However, detecting cyber fraud requires auditors who can read a network log as fluently as a balance sheet. The new standard for oversight is the intersection of forensic accounting and technical verification.
We are seeing the first steps of this evolution with the implementation of CMMC 2.0, which introduced mandatory third party assessments for contractors handling sensitive data starting in November 2025. This removes the self attestation loophole. However, verification must go deeper. Effective oversight now requires:
- Technical Proof of Work: Auditors must demand evidence of implementation—such as multi factor authentication logs and patch management reports—rather than just policy documents.
- Whistleblower Incentives: The record breaking $6.8 billion in total False Claims Act recoveries in FY 2025 was driven largely by whistleblowers. Encouraging technical staff to report non compliance is the most effective alarm system.
- Integrated Audits: Financial auditors must partner with ethical hackers to verify that billed services (e.g., “24/7 threat monitoring”) are actually active and functional.
The Road Ahead
The settlement with Illumina in July 2025, where the company paid $9.8 million for selling systems with known vulnerabilities, signals that the government is finally looking under the hood. But as the 2026 fiscal year unfolds, the challenge remains immense. The federal government spends nearly $100 billion annually on IT and cyber security. Unless forensic accountants are empowered to look beyond the invoice and verify the technical reality of the services delivered, this spending will remain a slush fund for the sophisticated embezzler. The days of paying for invisible walls must end; the new mandate is verify, then pay.
Here are 10 real news references regarding fraud, the False Claims Act, and financial malfeasance involving federal cybersecurity and IT contracts.
These cases highlight how the “embezzlement” frontier often manifests as **False Claims Act** violations—where contractors lie about their cybersecurity compliance to secure government funds—or direct bribery and wire fraud schemes.
“`html
References: Cybersecurity Contracts and Federal Fraud
-
The Department of Justice (2024): Georgia Tech False Claims Act Suit
The U.S. government intervened in a whistleblower lawsuit alleging the Georgia Institute of Technology knowingly failed to meet cybersecurity requirements in Department of Defense contracts, falsely claiming compliance with NIST standards to secure federal funds.
Read the DOJ Press Release -
Reuters (2023): Verizon $4 Million Settlement
Verizon Business Network Services agreed to pay $4 million to resolve allegations that it failed to fully satisfy cybersecurity controls in connection with federal contracts for the General Services Administration (GSA).
Read the Reuters Article -
The Washington Post (2022): Aerojet Rocketdyne Settlement
In a landmark case for the “Civil Cyber-Fraud Initiative,” defense contractor Aerojet Rocketdyne agreed to pay $9 million to resolve allegations that they misled the government about their cybersecurity compliance to win federal contracts.
Read the Washington Post Article -
Associated Press (2024): Carahsoft FBI Raid
Federal agents raided the headquarters of Carahsoft, a massive government IT solutions provider. While details are unfolding, the investigation reportedly involves potential price-fixing and overcharging regarding SAP software sold to the government.
Read the AP News Article -
The Department of Justice (2022): Comprehensive Health Services
A medical services contractor paid $930,000 to settle allegations that it falsely represented to the State Department and Air Force that it had complied with contract requirements relating to the secure storage of medical records on a secure electronic medical record system.
Read the DOJ Press Release -
CBS News (2019): Cisco Systems Surveillance Settlement
Cisco Systems agreed to pay $8.6 million to settle a lawsuit alleging they knowingly sold video surveillance software to federal and state agencies that contained major security flaws, leaving government systems vulnerable to hackers.
Read the CBS News Article -
Federal News Network (2024): Penn State University Lawsuit
A federal district court unsealed a lawsuit alleging Penn State University defrauded the government by falsifying compliance with cybersecurity requirements (NIST 800-171) in contracts with NASA and the DoD.
Read the Federal News Network Article -
Department of Justice (2015): NetCracker Technology & CSC
NetCracker and CSC agreed to pay a combined $12.75 million for allegedly using employees without security clearances (including Russian nationals) to write code for the Defense Information Systems Agency (DISA), despite contracts requiring strictly cleared personnel.
Read the DOJ Press Release -
San Diego Union-Tribune (2024): Navy IT Bribery Scheme
While tied to the broader “Fat Leonard” era, recent sentencing for former Navy civilian James Soriano highlighted bribery involving IT contracts. Soriano accepted dinners and jobs for family members in exchange for steering IT and radio contracts to specific defense firms.
Read the Union-Tribune Article -
Bloomberg Law (2023): Booz Allen Hamilton Settlement
Booz Allen Hamilton agreed to pay $377.4 million to settle charges that it improperly billed the government for costs related to its commercial and international business, highlighting the financial “shell games” often played within large federal contracting vehicles.
Read the Bloomberg Law Article
“`


































