Photo of Nkechi KanuPhoto of Brian Tully McLaughlinPhoto of Kate GrowleyPhoto of Matthew FerraroPhoto of Jessica ChaoPhoto of Jacob HarrisonPhoto of Ajan JayantPhoto of Bryan Dewan

In recent years, the U.S. federal government has taken significant interest in the cybersecurity compliance of its contractor base. In 2025 alone, the U.S. Department of Justice’s (DOJ) Civil Cyber-Fraud Initiative recovered more than $50 million across nine False Claims Act (FCA) cybersecurity fraud settlements, and it has secured almost 20 settlements since its launch in October 2021. Because most defendants facing FCA liability for alleged cybersecurity noncompliance enter into pre-litigation settlements, the last court decision in a cybersecurity FCA case was in 2022. However, earlier this month, on September 2, 2026, in  United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145, 2026 WL 2593317 (N.D. Ill. Sept. 2, 2026), Judge Sunil R. Harjani of the U.S. District Court for the Northern District of Illinois granted a motion to dismiss on materiality grounds and offered additional guidance on what a plaintiff must allege to adequately state an FCA cybersecurity claim.

Background

Archer Daniels Midland (ADM) is a company that receives federal grants and contracts related to food commodities and biofuel processing. On February 17, 2026, Mark Pannek, a former ADM employee, amended an earlier FCA complaint against ADM to allege that ADM had cybersecurity deficiencies, failed to comply with applicable cybersecurity regulations, and made false statements and certifications by entering into contracts and grants with terms and conditions related to cybersecurity and in the government’s System for Award Management. On April 20, 2026, ADM filed a motion to dismiss, arguing that Pannek failed to plead any element of the alleged fraud with sufficient particularity and that ADM is not bound by many of the cybersecurity regulations and standards Pannek alleged.

The Decision

To bring a successful FCA claim, a plaintiff must demonstrate that the false statement was “material” to the government, i.e., that it would have “significantly affected the government’s actions” on whether to pay the contractor. United States v. Molina Healthcare of Illinois, Inc., 17 F.4th 732, 743 (7th Cir. 2021). Judge Harjani held that Pannek had not demonstrated that any of ADM’s statements about its cybersecurity were likely to have affected the government’s payment decisions. The court found that Pannek pled only general and conclusory assertions about the government’s usual interest in cybersecurity, including references to other FCA cybersecurity settlements. Pannek did not present specific facts showing the government was particularly interested in ADM’s cybersecurity compliance when deciding whether to fund ADM’s contracts and grants. 

Although Pannek alleged that adhering to certain cybersecurity regulations was a condition of payment for ADM’s contracts and grants, Judge Harjani found that the government’s mere designation of regulatory or contractual compliance as a condition of payment was insufficient to demonstrate materiality, noting that the U.S. Supreme Court in Universal Health Services, Inc. v. United States ex rel. Escobar, 579 U.S. 176 (2016) specifically rejected that theory of materiality. Accordingly, Pannek failed to demonstrate materiality and did not sufficiently plead an FCA violation.

Judge Harjani’s decision contained other key findings:

  • Particularity: Pannek alleged that ADM made multiple false statements about its cybersecurity. Although the court found that Pannek provided sufficient details about three false statements (akin to affirmative representations) that ADM allegedly made to receive certain grants, it found that other allegations were “conclusory” and not sufficiently particular. Notably, the court found Pannek’s allegation that ADM “implicitly” certified its regulatory compliance was insufficient because, under an implicit certification theory, the relator must identify some affirmative statement the defendant made that involved a half-truth or omission, but Pannek did not identify any such specific statements.
  • Falsity: If ADM did make statements about its compliance with cybersecurity regulations, Pannek sufficiently pled a variety of deficiencies that would render such statements false — for example, that hundreds of individuals had access to sensitive information in violation of NIST requirements and that the company failed to maintain adequate records of such access.
  • Scienter: Pannek adequately pled the requisite scienter with respect to certain false statements by alleging that ADM’s executive leadership was aware of a 2019 audit and a 2022 report that identified cybersecurity issues at the company while the company was making alleged statements about its compliance with cybersecurity regulations.
  • Applicability of Cybersecurity Regulations: Because the court found it plausible that ADM had controlled unclassified information (CUI) on its systems, it dismissed the complaint without prejudice, allowing Pannek to file an amended complaint if he addressed the materiality and particularity deficiencies. If Pannek does not file an amended complaint by September 23, 2026, then the dismissal will automatically convert to a dismissal with prejudice.

Key Takeaways:

  • Materiality Matters: This decision confirms that FCA cybersecurity complaints are subject to “rigorous” materiality requirements. See Escobar, 579 U.S. at 181, 192. The mere presence of cybersecurity clauses in a contract, even if designated as a condition of payment, is not enough to show materiality. Nevertheless, given the limited precedent for when materiality is sufficiently pleaded, contractors should remain vigilant in complying with the clauses in their contracts and remediating any cybersecurity problems identified. 
  • It’s About What You Know: This case illustrates how negative internal audit or investigation findings shared with executive leadership could potentially provide support for scienter in an FCA case, or at least pleading scienter. Although conducting audits or investigations under attorney-client privilege can provide some protection amid government scrutiny, contractors should be mindful about subsequent representations if they are unable to promptly remediate identified gaps or deficiencies.
  • Know Your Data, Know Your Network: If a relator alleges that a defendant has CUI on its network, a defendant with a firm grasp of its data flow may be able to efficiently and convincingly refute that allegation, presenting an effective defense at later stages of litigation.
Print:
Email this postTweet this postLike this postShare this post on LinkedIn
Photo of Nkechi Kanu Nkechi Kanu

Nkechi A. Kanu is a counsel in the Washington, D.C. office of Crowell & Moring, where she is a member of the firm’s Government Contracts Group.

Nkechi’s practice focuses on False Claims Act investigations and litigation. Nkechi has significant experience assisting companies with…

Nkechi A. Kanu is a counsel in the Washington, D.C. office of Crowell & Moring, where she is a member of the firm’s Government Contracts Group.

Nkechi’s practice focuses on False Claims Act investigations and litigation. Nkechi has significant experience assisting companies with complex internal investigations and represents clients in government investigations involving allegations of fraud. She also focuses on assisting clients with investigations relating to cybersecurity and information security compliance. Her complementary litigation practice involves defending companies in government-facing litigation arising under the FCA, resulting in the dismissal of qui tam complaints and successful settlements of FCA claims with DOJ.

Photo of Brian Tully McLaughlin Brian Tully McLaughlin

Brian Tully McLaughlin is a partner in the Government Contracts Group in Washington, D.C. and co-chair of the False Claims Act Practice. Tully’s practice focuses on False Claims Act investigations and litigation, particularly trial and appellate work, as well as litigation of a…

Brian Tully McLaughlin is a partner in the Government Contracts Group in Washington, D.C. and co-chair of the False Claims Act Practice. Tully’s practice focuses on False Claims Act investigations and litigation, particularly trial and appellate work, as well as litigation of a variety of complex claims, disputes, and recovery matters. Tully’s False Claims Act experience spans procurement fraud, healthcare fraud, defense industry fraud, and more. He conducts internal investigations and represents clients in government investigations who are facing fraud or False Claims Act allegations. Tully has successfully litigated False Claims Act cases through trial and appeal, both those brought by whistleblowers / qui tam relators and the Department of Justice alike. He also focuses on affirmative claims recovery matters, analyzing potential claims and changes, counseling clients, and representing government contractors, including subcontractors, in claims and disputes proceedings before administrative boards of contract appeals and the Court of Federal Claims, as well as in international arbitration. His claims recovery experience includes unprecedented damages and fee awards. Tully has appeared and tried cases before judges and juries in federal district courts, state courts, and administrative boards of contract appeals, and he has argued successful appeals before the D.C. Circuit, the Federal Circuit, and the Fourth and Seventh Circuits.

Photo of Kate Growley Kate Growley

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy…

Kate M. Growley (CIPP/US, CIPP/G) is a director with Crowell & Moring International and based in Hong Kong. Drawing from over a decade of experience as a practicing attorney in the United States, Kate helps her clients understand, navigate, and shape the policy and regulatory environment for some of the most complex data issues facing multinational companies, including cybersecurity, privacy, and digital transformation. Kate has worked with clients across every major sector, with particular experience in technology, health care, manufacturing, and aerospace and defense. Kate is a Certified Information Privacy Professional (CIPP) in both the U.S. private and government sectors by the International Association of Privacy Professionals (IAPP). She is also a Registered Practitioner with the U.S. Cybersecurity Maturity Model Certification (CMMC) Cyber Accreditation Body (AB).

Photo of Matthew Ferraro Matthew Ferraro

Matthew F. Ferraro is a partner in Crowell & Moring’s Privacy and Cybersecurity Group, where he helps clients address complex regulatory matters at the intersection of advanced technology, national security, and crisis management. He advises leading organizations on high-impact matters related to artificial

Matthew F. Ferraro is a partner in Crowell & Moring’s Privacy and Cybersecurity Group, where he helps clients address complex regulatory matters at the intersection of advanced technology, national security, and crisis management. He advises leading organizations on high-impact matters related to artificial intelligence (AI) and other emerging technologies, cyberattacks, domestic and international privacy compliance, internal investigations, foreign direct investment reviews, and high-stakes crises.

Before joining the firm, Matthew served as the Senior Counselor for Cybersecurity and Emerging Technology to the Secretary of Homeland Security. As a principal advisor to the Secretary and a member of the U.S. Department of Homeland Security’s leadership team, he served at the heart of U.S. government policymaking around AI and cybersecurity. He assisted in the development and drafting of key AI, cyber, and technology policies and regulations; advised on the deployment of AI to fulfill the department’s missions; and counseled on cyber-incident responses and investigations. Matthew also helped establish and served as the Executive Director of the Artificial Intelligence Safety and Security Board, a flagship public-private advisory committee focused on AI’s use in critical infrastructure and chaired by the Secretary and composed of industry, nonprofit, and government luminaries.

Photo of Jacob Harrison Jacob Harrison

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including

Jacob Harrison helps his clients navigate both domestic and international legal challenges.

Jake advises U.S. government contractors on internal investigations and state and federal regulatory compliance. His compliance practice focuses on counseling clients operating at the intersection of government contracts and cybersecurity, including for cybersecurity compliance reviews, risk assessments, and data breaches.

In his international practice, Jake represents foreign and domestic clients in Foreign Sovereign Immunities Act and Anti-Terrorism Act litigation. He also has experience advising clients involved in cross-border commercial arbitration proceedings.

During law school, Jake served as an associate editor of the Emory Law Journal and interned at the Supreme Court of Georgia and the Georgia House Democratic Caucus. Before attending law school, Jake worked in politics and state government.