Contact Us

The Fraud Files: Your SPRS Score Is a Legal Document — Two Cases That Prove It

The Fraud Files is a Team Integrity Knowledge Center series on real fraud, debarment, and enforcement cases in government contracting — drawn exclusively from official DOJ, SBA, and Inspector General records. Every story is a masterclass in what the government is watching. Every dollar stolen through fraud was taken from an honest small business that played by the rules.

Two cases. Two contractors. One clear message the entire defense industrial base should have tattooed somewhere visible: your cybersecurity self-assessment score is not an internal document — it is a legal certification attached to every invoice you submit, and the Justice Department is now settling civil cases and bringing criminal charges to prove it. Here are the cases, the mechanics, and what they mean for every contractor holding a DFARS clause or a FedRAMP authorization.

Case One: LOGZONE Inc. — The $507,144 Lesson in Honest Self-Assessment

On June 18, 2026, the Department of Justice announced that LOGZONE Inc., a defense contractor based in Huntsville, Alabama, agreed to pay $507,144 to resolve False Claims Act allegations that it knowingly failed to comply with cybersecurity requirements in two contracts with the Department of the Navy (U.S. Department of Justice, 2026a). The settlement, reached with assistance from the Navy, the Army, and the Defense Contract Management Agency, covers alleged conduct from May 2021 through March 2025 — four years of billing on contracts that, the government alleged, were secured and maintained through false cybersecurity representations.

The core allegation is straightforward: LOGZONE submitted claims for payment on contracts that required NIST SP 800-171 compliance, while knowingly failing to satisfy those requirements (Sidley Austin LLP, 2026). The settlement is the latest in the DOJ’s sustained Civil Cyber-Fraud Initiative — launched in 2021 and now, in 2026, running as a mature enforcement program with a growing settlement history and, increasingly, criminal referrals. The Sidley FCA blog summarized the practical lesson bluntly: “a low DCMA assessment score is not merely a compliance gap — it can become documentary evidence that claims for payment were knowingly false.”

The amount — $507,144 — is relatively modest compared to recent FCA resolutions. But that’s actually the scariest part. This settlement proves the government will pursue cybersecurity FCA cases regardless of dollar size. There is no threshold below which a dishonest SPRS score is safe.

Case Two: Danielle Hillmer — The Manager Who Crossed Her Fingers and Got Indicted

If the LOGZONE case is the civil warning, the Hillmer case is the criminal one. On December 10, 2025, a federal grand jury in Washington, D.C. returned an indictment charging Danielle Hillmer, a former senior manager at a Virginia-based government contractor, with major government fraud, two counts of wire fraud, and two counts of obstructing a federal audit (FedScoop, 2025). Maximum sentence if convicted on the wire fraud counts alone: 20 years per count.

The contractor provided cloud computing services to at least six federal agencies, including the Army and the departments of State and Veterans Affairs. Hillmer oversaw the cloud platform’s FedRAMP assessments and continuous monitoring. According to the indictment, beginning around March 2020, she allegedly directed the concealment of the platform’s failure to implement required security controls — including multi-factor authentication — while the contractor continued billing those agencies for services that required a level of security the platform did not actually provide (FedScoop, 2025; Hogan Lovells, 2026).

Sponsored

GovCon iSource

Find, track, and win federal contracts in one platform

Opportunity matching, bid tracking, and proposal tools built for small businesses.

Start Free Tour →

The evidence the prosecution cited is extraordinary for its specificity. A private chat message from July 2021 showed an employee writing to Hillmer: “we’ve dodged the [multi-factor authentication] implementation bullet for now, but it could come up again… We aren’t out of the woods yet.” Hillmer’s documented response: a fingers-crossed emoji (FedScoop, 2025). The indictment alleges she sought to “unlawfully enrich herself through continued compensation in salary and bonuses” by maintaining the false authorization.

Read that sequence carefully. The company wasn’t charged alone. The individual manager was indicted. Her personal income — salary and bonuses — is alleged as the motive. And the evidence is a chat message she sent years ago that federal prosecutors found and put in a grand jury indictment. The Hogan Lovells team noted this case “signals a new willingness to pursue individual liability through criminal prosecution” in cybersecurity fraud (Hogan Lovells, 2026). That willingness has only grown with the establishment of the National Fraud Enforcement Division in April 2026.

What Both Cases Are Really About

Strip both cases to their shared core and the pattern is identical: a contractor represented to the government that it met cybersecurity requirements it did not actually meet, then billed for services on contracts that required those representations to be true. In LOGZONE’s case, the mechanism was NIST 800-171 self-assessments and SPRS scores. In Hillmer’s case, it was FedRAMP authorization documents and continuous monitoring reports. In both cases, the government’s position is the same: every invoice submitted while those representations were false was a false claim.

This is the engine behind the CMMC Phase 2 suspension story that contractors may have missed: the Pentagon suspended the third-party certification requirement precisely because the SPRS self-assessment became the primary compliance mechanism. And the DOJ has now demonstrated, repeatedly, that self-assessment scores filed with false numbers are not administrative paperwork — they are the false statements that trigger FCA liability and, increasingly, criminal charges.

The Five Actions Every Contractor With a DFARS Clause Needs to Take

1. Pull your SPRS score and audit it against actual evidence. Not against what you think you’ve implemented — against documented proof for every control point. If your score reflects a capability you haven’t actually deployed, you have a false representation attached to every invoice on every affected contract. Fix the gap or correct the score; both may require legal counsel.

2. Treat your System Security Plan as a living document, not a filing artifact. The SSP is the evidence base behind your SPRS score. If your SSP says you have multi-factor authentication and you don’t, the SSP is the document that proves the representation was false. Review it, update it, and make sure the people responsible for it understand the legal significance of what they’re signing.

3. Create a paper trail for remediation decisions. The Hillmer case turned on what she knew and when. If you discover a control gap, document your discovery, your response, and your remediation timeline. Proactive disclosure to your contracting officer — where appropriate — is far better than hoping the gap never surfaces.

4. Audit your subcontractors’ representations. DFARS 7012 flows down. If a sub makes false cybersecurity representations and you pay them on your prime contract, your prime-level claims may also carry exposure. Verify what your subs are certifying and confirm it’s accurate before their representations become yours.

5. Read your certifications before you sign them. This sounds obvious — and it is — but the compliance assembly line in many contracting firms treats annual certifications as administrative checklists rather than legal instruments. The pick-and-kent bribery case and the Hillmer indictment both turned on the decision by a real individual to sign a false representation. That individual is the one who gets indicted. Know what you are certifying before your name goes on it.

The Bottom Line

The LOGZONE settlement and the Hillmer indictment aren’t isolated cautionary tales — they are two data points on a trendline that runs directly into 2026 and beyond, accelerated by a DOJ with a new dedicated fraud division and a data-analytics center designed to surface billing anomalies at scale. For the contractor who actually implements the controls they certify, these cases are nothing. For the contractor banking on the gap between what they certified and what they built never being examined — the examination is coming, and it now comes with a criminal referral option. Certify honestly. Implement what you promise. Document everything. Brick by brick, the clean firms win.

Free Download

The First Federal Contract Roadmap

The complete 90-day guide — done right, with compliance built in from day one.

Get the Free Roadmap →

Frequently Asked Questions

What is an SPRS score and why does it matter legally?

The Supplier Performance Risk System (SPRS) score reflects a defense contractor’s self-assessment of its implementation of NIST SP 800-171 cybersecurity controls. Under DFARS clauses, contractors certify this score when they submit it — making it a legal representation to the government. Submitting invoices on contracts while maintaining a false SPRS score means each invoice is a potentially false claim under the False Claims Act, carrying treble-damages liability.

What is FedRAMP and why was it relevant in the Hillmer case?

FedRAMP (Federal Risk and Authorization Management Program) is the government’s authorization framework for cloud services used by federal agencies. Cloud service providers must meet rigorous security requirements and maintain continuous monitoring. Hillmer allegedly directed concealment of the platform’s failure to implement required controls — including multi-factor authentication — while the contractor billed agencies under contracts that required FedRAMP compliance.

How do cybersecurity gaps become False Claims Act violations?

When a contractor submits a claim for payment on a contract that requires cybersecurity compliance — and the contractor knows it has not actually implemented required controls — the claim may be “false or fraudulent” under the FCA. The FCA does not require the government to suffer a specific monetary loss; the false representation itself can be sufficient for liability.

Can individual managers be personally charged in cybersecurity fraud cases?

Yes. The Hillmer indictment demonstrates exactly this: a mid-level manager, not a CEO or owner, was personally indicted on federal fraud charges for allegedly directing the concealment of cybersecurity noncompliance. DOJ has explicitly stated it will pursue individual liability in cybersecurity fraud cases, not just corporate settlements.

GovCon iSource  surfaces live opportunities matched to your NAICS codes.

Explore iSource →

References

FedScoop. (2025, December 10). DOJ says government contractor misled agencies about platform’s FedRAMP compliance. https://fedscoop.com/government-contractor-fedramp-compliance-justice-department-army-veterans-affairs/

Hogan Lovells. (2026). DOJ brings individual criminal charges for FedRAMP fraud: What government contractors need to know. https://www.hoganlovells.com/en/publications/doj-brings-individual-criminal-charges-for-fedramp-fraud-what-government-contractors-need-to-know

Mayer Brown. (2026, June 23). Alabama defense contractor to pay $507,144 to resolve False Claims Act cybersecurity allegations. https://www.mayerbrown.com/en/insights/publications/2026/06/alabama-defense-contractor-to-pay-507144-to-resolve-false-claims-act-cybersecurity-allegations

Sidley Austin LLP. (2026, June 23). DOJ reaches $507,144 settlement with defense contractor, signals increased FCA scrutiny of cybersecurity self-assessments. https://fcablog.sidley.com/2026/06/23/doj-reaches-507144-settlement-with-defense-contractor-signals-increased-fca-scrutiny-of-cybersecurity-self-assessments/

U.S. Department of Justice. (2026a, June 18). Alabama defense contractor agrees to pay $507,144 to resolve False Claims Act cybersecurity allegations. https://www.justice.gov/opa/pr/alabama-defense-contractor-agrees-pay-507144-resolve-false-claims-act-cybersecurity-allegations

Melanie Patterson, Founder and CEO of Team Integrity Knowledge Center

About the Author

Melanie Patterson

Founder & CEO of Team Integrity Knowledge Center and creator of GovCon iSource, Melanie has spent more than a decade helping small, women-owned, and minority-owned businesses win state and federal contracts — including guiding her clients to over $10 million in government awards. A former nurse turned entrepreneur with hands-on DoD and FEMA freight experience, she serves on the board of Women in Logistics. Build, grow, scale — brick by brick. YouTube · Contact

Most Read

In April 2026, DOJ stood up the National Fraud Enforcement Division — its first unified
A $21.3 million settlement, a $240 million rent-a-vet conviction, and whistleblowers walking away with millions

Related

Discover more from Team Integrity Knowledge Center

Subscribe now to keep reading and get access to the full archive.

Continue reading