Contact Us

The Fraud Files: Your SPRS Score Is a Legal Document — Two Cases That Prove It

The Fraud Files is a Team Integrity Knowledge Center series on real fraud, debarment, and enforcement cases in government contracting — drawn exclusively from official DOJ, SBA, and Inspector General records.

Two cases. One clear message: your cybersecurity self-assessment score is a legal certification attached to every invoice you submit, and the Justice Department is now settling civil cases and bringing criminal charges to prove it.

Case One: LOGZONE Inc. — The $507,144 Lesson in Honest Self-Assessment

On June 18, 2026, the DOJ announced that LOGZONE Inc., a defense contractor based in Huntsville, Alabama, agreed to pay $507,144 to resolve False Claims Act allegations that it knowingly failed to comply with cybersecurity requirements in two Navy contracts. The core allegation: LOGZONE submitted claims for payment on contracts requiring NIST SP 800-171 compliance while knowingly failing to satisfy those requirements. This settlement proves the government will pursue cybersecurity FCA cases regardless of dollar size. There is no threshold below which a dishonest SPRS score is safe.

Case Two: Danielle Hillmer — The Manager Who Crossed Her Fingers and Got Indicted

If the LOGZONE case is the civil warning, the Hillmer case is the criminal one. A federal grand jury charged Danielle Hillmer, a former senior manager at a Virginia-based government contractor, with major government fraud, two counts of wire fraud, and two counts of obstructing a federal audit. Maximum sentence on wire fraud alone: 20 years per count. According to the indictment, she allegedly directed the concealment of the platform’s failure to implement required security controls — including multi-factor authentication — while the contractor billed six federal agencies for services that required a level of security the platform did not actually provide.

The evidence: a private chat message showed an employee writing to Hillmer about dodging MFA implementation. Hillmer’s documented response was a fingers-crossed emoji. The individual manager was indicted. Her personal salary and bonuses are alleged as the motive.

GovCon iSource — Your pipeline runs while you run your business.

The Five Actions Every Contractor With a DFARS Clause Needs to Take

1. Pull your SPRS score and audit it against actual evidence. Not against what you think you’ve implemented — against documented proof for every control point. If your score reflects a capability you haven’t actually deployed, you have a false representation attached to every invoice on every affected contract.

2. Treat your System Security Plan as a living document. The SSP is the evidence base behind your SPRS score. Review it, update it, and make sure the people responsible understand the legal significance of what they’re signing.

3. Create a paper trail for remediation decisions. If you discover a control gap, document your discovery, your response, and your remediation timeline. Proactive disclosure to your contracting officer is far better than hoping the gap never surfaces.

4. Audit your subcontractors’ representations. DFARS 7012 flows down. Verify what your subs are certifying and confirm it’s accurate before their representations become yours.

5. Read your certifications before you sign them. The individual is the one who gets indicted. Know what you are certifying before your name goes on it.

The Bottom Line

The LOGZONE settlement and the Hillmer indictment aren’t isolated cautionary tales — they are two data points on a trendline that runs directly into 2026 and beyond. For the contractor who actually implements the controls they certify, these cases are nothing. For the contractor banking on the gap between what they certified and what they built never being examined — the examination is coming, and it now comes with a criminal referral option. Certify honestly. Implement what you promise. Document everything. Brick by brick, the clean firms win.

Not sure where you fit? Start with a call. Book Free Call.

Frequently Asked Questions

What is an SPRS score and why does it matter legally?

The Supplier Performance Risk System (SPRS) score reflects a defense contractor’s self-assessment of its implementation of NIST SP 800-171 cybersecurity controls. Contractors certify this score when they submit it under DFARS clauses — making it a legal representation to the government. Submitting invoices while maintaining a false SPRS score means each invoice is a potentially false claim under the False Claims Act.

Can individual managers be personally charged in cybersecurity fraud cases?

Yes. The Hillmer indictment demonstrates exactly this: a mid-level manager, not a CEO, was personally indicted on federal fraud charges for allegedly directing the concealment of cybersecurity noncompliance. DOJ has explicitly stated it will pursue individual liability in cybersecurity fraud cases, not just corporate settlements.

How do cybersecurity gaps become False Claims Act violations?

When a contractor submits a claim for payment on a contract that requires cybersecurity compliance — and knowingly has not implemented required controls — the claim may be “false or fraudulent” under the FCA. The false representation itself can be sufficient for liability; the government does not need to prove a specific monetary loss.

GovCon iSource — Your pipeline runs while you run your business.

References

U.S. Department of Justice. (2026, June 18). Alabama defense contractor agrees to pay $507,144 to resolve False Claims Act cybersecurity allegations. https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-cybersecurity-allegations

FedScoop. (2025, December 10). DOJ says government contractor misled agencies about platform’s FedRAMP compliance. https://fedscoop.com/government-contractor-fedramp-compliance-justice-department-army-veterans-affairs/

Melanie Patterson

About the Author

Melanie Patterson

Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource. Former nurse turned entrepreneur with over 10 years guiding small, women-owned, and minority-owned businesses to over $10 million in government awards. Build, grow, scale — brick by brick. Contact

Most Read

Federal law protects contractor employees who report waste, fraud, or law violations — and punishes
The Anti-Kickback Act and the FAR gratuities rules criminalize improper payments up and down the

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading