DOJ Announces New Civil Cyber-Fraud Initiative


On October 6, 2021, Deputy Attorney General Lisa O. Monaco announced the launch of the US Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative. The initiative will focus on using the False Claims Act (FCA) to pursue fraud related to cybersecurity, with an emphasis on fraudulent acts perpetrated by government contractors and recipients of federal funds. The FCA gives the DOJ authority to bring civil enforcement actions against companies that make false claims for federal funds, and it empowers whistleblowers to advance the government’s interest in combatting fraud by allowing private parties to bring lawsuits on the government’s behalf and take a share of the proceeds of any recovery.

Led by the Fraud Section of the DOJ Civil Division’s Commercial Litigation Branch, the initiative seeks to “hold accountable entities or individuals that put U.S. information or systems at risk by knowingly providing deficient cybersecurity products or services, knowingly misrepresenting their cybersecurity protocols, or knowingly violating obligations to monitor and report cybersecurity incidents and breaches.” The DOJ’s announcement lists a series of benefits the DOJ hopes to achieve through the initiative, which include “[h]olding contractors and grantees to their commitments to protect government information and infrastructure[,]” and “[e]nsuring that companies that follow the rules and invest in meeting cybersecurity requirements are not at a competitive disadvantage.”

INCREASED EMPHASIS ON CIVIL ENFORCEMENT

Notably, the Civil Cyber-Fraud Initiative is the first major initiative announced by the Department as a result of an ongoing cyber review ordered by the Deputy Attorney General in May 2021.* The initiative also puts into action statements made by DOJ officials following the 2020 presidential election, and it underscores the importance of affirmative civil enforcement in broader efforts to counter threats posed by ransomware attacks and other cyberattacks. For example, last December, at the ABA Civil False Claims Act and Qui Tam Enforcement Institute, Deputy Assistant Attorney General Michael D. Granson warned that there may be enhanced False Claims Act activity in the cybersecurity space. In February 2021, Acting Assistant Attorney General Brian M. Boynton emphasized in remarks at the Federal Bar Association Qui Tam Conference that “[t]o the extent that the government pays for systems or services that purport to comply with required cybersecurity standards but fail to do so, it is not difficult to imagine a situation where False Claims Act liability may arise.”

On the same day that the DOJ announced the creation of the Civil Cyber-Fraud Initiative, Deputy Attorney General Monaco published an op-ed in which she urged Congress to pass legislation to create a national standard for reporting cyber incidents that pose significant risk, including ransomware and incidents that affect critical infrastructure. Deputy Attorney General Monaco called for Congress to designate a single mechanism where victims can file reports to the federal government to be shared immediately with the DOJ and US Department of Homeland Security.

The Civil Cyber-Fraud Initiative and Deputy Attorney General Monaco’s op-ed should be viewed in conjunction with a variety of other recent measures from the Biden administration that seek to combat ransomware and malign cyber activities, including:

In addition, a bipartisan group of US Senators has introduced the Cyber Incident Notification Act; if enacted, the legislation would require federal agencies, government contractors and critical infrastructure owners and operators to report cyber intrusions to CISA within 24 hours of their discovery. A number of states—including New York, North Carolina, Pennsylvania and Texas—are considering legislation that would ban or restrict state and local government agencies from paying ransom in the event of a cyberattack.

IMMEDIATE TAKEAWAYS

The Civil Cyber-Fraud Initiative demonstrates that cybersecurity is increasingly on the government’s enforcement radar. In light of DOJ’s announcement, government contractors should keep in mind the following key takeaways:


© 2025 McDermott Will & Emery
National Law Review, Volume XI, Number 285