By Chuck Gallagher — Business Ethics Keynote Speaker and Trainer

TL;DR: A record $6.8 billion False Claims Act year has moved federal enforcement away from what contractors bill and onto what they certify. I want to show you why the gap between the paperwork and the practice is now the exposure — and why that gap is a decision problem long before it’s a legal one.

Somebody Signed It Anyway

Picture a conference room on a Thursday. The annual certification is due Friday. A compliance officer slides it across the table. The operations lead knows — knows — that three of the security controls listed in that document are not actually running. He said so in a memo fourteen months ago. The fix got funded, then cut, then moved to next quarter. Everybody at that table knows.

Somebody signs it anyway.

That moment used to be a paperwork problem. It’s a federal fraud case.

What Actually Changed at the Justice Department?

In January 2026, DOJ reported more than $6.8 billion in False Claims Act settlements and judgments for fiscal year 2025. Largest single year in the statute’s history. Roughly double the prior year.

For most of the FCA’s modern life, these were billing cases. Did you overbill? Did you invoice for work you never performed? Those still write enormous checks — a $428 million settlement over false cost and pricing data on a Defense Department weapons maintenance contract ranked among the largest procurement fraud recoveries ever.

But billing is no longer the whole game. A growing share of that number comes from a different question. Not “you billed us for something you didn’t do.” Something closer to: “you told us you were doing something, and you weren’t.”

Stop. You may want to read that last line again, because that’s the whole point here.

Why Do Certifications Matter More Than Invoices Now?

The theory is called implied certification. The Supreme Court blessed it in Escobar in 2016, and for ten years the government has been feeling out how far it stretches. The answer, in 2026, appears to be: pretty far.

You sign a federal contract. Certifications are baked in — some obvious, some buried on page forty-seven of an appendix. Your cybersecurity posture. Your labor practices. Your supply chain. Dozens of things nobody has read closely since the proposal went out the door.

Under the old model, none of it mattered much without a fraudulent invoice. That’s changed. The certification is the case now. If it was material to the payment decision and knowingly false, the lie in the paperwork is the claim. No inflated invoice required. No breach. No loss to the taxpayer.

I’ve watched executives absorb that sentence in real time from the front of a room. The room gets quiet.

What Do the Cybersecurity Cases Actually Show?

Penn State paid $1.25 million in October 2024 over allegations that it failed to implement cybersecurity controls it had certified across fifteen Defense Department and NASA contracts. No breach. No hack. No stolen data. The university admitted no wrongdoing and said it settled to avoid costly litigation. But look at the theory: the certification itself — made to win the work and keep it — was alleged to be the false claim.

That wasn’t a one-off. DOJ recovered more than $52 million in civil cyber-fraud settlements in fiscal 2025 alone, and says such settlements have more than tripled in two years. The pattern repeats. Failed to implement. Failed to maintain the security plan. Failed to close a gap somebody already wrote down.

Every one of those bills was accurate. The certification sitting behind them wasn’t, and that is now enough.

Where Else Is This Theory Going?

In April 2026, DOJ announced its first resolution under the Civil Rights Fraud Initiative. IBM agreed to pay $17,077,043 over allegations that its employment practices breached anti-discrimination requirements in its federal contracts. The company denied wrongdoing. No admission, no judicial finding, and the theory is still untested in court.

Set the policy fight aside — that’s not my lane. The mechanism is what I want you to see. DOJ took a compliance area most contractors had filed under “administrative enforcement” and dropped it into a statute carrying treble damages, per-claim penalties, and private whistleblowers with a bounty. Every representation your HR team signs now sits in the same exposure as your invoices.

Who Is Actually Watching Your Paperwork?

Relators filed roughly 1,300 qui tam suits in fiscal 2025 — a record — after 980 the year before. And the profile is changing. The old whistleblower was a billing clerk who watched a bad invoice go out the door. Now the relator may have never worked at your company at all. DOJ says data miners — outsiders running analytics on public government data — filed more than 45 percent of all qui tam complaints since fiscal 2024, and in April 2026 the Civil Division launched an initiative inviting them to sit down with prosecutors and explain their methods.

So the question has changed on you. It used to be whether your own people would report you. Now it’s whether a stranger with a laptop and a public dataset can stare at your filings and find a story.

That’s a harder question.

What Does This Have to Do With Ethics?

Here’s the pattern, and it’s older than the False Claims Act. Somebody in the building knows the gap. Somebody flagged it in a memo. Somebody one level up said the fix is coming. Then the certification comes due and it gets signed anyway, because telling your customer you don’t meet the requirement feels worse today than the deferred risk of getting caught later.

That’s a rationalization. It’s the same one in every fraud case I’ve ever studied, my own included. I told myself I’d pay the money back, so it wasn’t theft. It was a loan. I even typed up the note. The person signing that certification is almost never a villain. He’s almost always somebody who has convinced himself he’ll make it right before anybody notices.

DOJ just took away the safety margin that rationalization depends on. So inventory your certifications. All of them, five years back. Then ask a compliance officer and an operations owner — separately — whether each one is true today. Where the answers don’t match, you’ve found your next investigation before a whistleblower does.

I work with federal contractors, and let me be clear about the hard part. A certification is not a formality. It’s a statement to the federal government, made to induce payment. It deserves the attention a 10-K disclosure gets. In most organizations, it doesn’t get it.

The old FCA question was: did you bill for something you didn’t deliver? The new one is: is the story you told the government the story your operations tell back? Those are not the same question. And a lot of contractors are going to learn the difference the expensive way.

Frequently Asked Questions

What is the implied certification theory under the False Claims Act?

It’s the theory the Supreme Court recognized in Universal Health Services v. United States ex rel. Escobar (2016): a contractor can face False Claims Act liability by knowingly misrepresenting compliance with a requirement the government treats as material to its decision to pay. The false statement in the certification becomes the false claim. The invoice never has to be wrong. That’s the part that surprises people — a company can be exposed even when every bill it submitted was accurate.

Can a company face False Claims Act liability without a data breach?

Yes. Penn State paid $1.25 million in October 2024 to resolve allegations that it had not implemented cybersecurity controls it certified across fifteen Department of Defense and NASA contracts. No breach was alleged. No intrusion. The university admitted no wrongdoing. DOJ recovered more than $52 million through civil cyber-fraud settlements in fiscal 2025 alone, and has reported that cybersecurity settlements more than tripled in two years.

How much did DOJ recover under the False Claims Act in fiscal year 2025?

More than $6.8 billion in settlements and judgments — the highest single-year total in the statute’s history and roughly double the prior year. Whistleblowers filed about 1,300 qui tam suits, another record, up from 980 in fiscal 2024. Health care matters accounted for over $5.7 billion of the total. Procurement, cybersecurity, and customs enforcement all grew too.

What was the IBM Civil Rights Fraud Initiative settlement?

In April 2026, DOJ announced its first False Claims Act resolution under the Civil Rights Fraud Initiative, with IBM agreeing to pay $17,077,043 to resolve allegations that its employment practices failed to comply with anti-discrimination requirements in its federal contracts. IBM denied wrongdoing, and there was no admission or judicial finding of liability. For every other contractor, what matters here is the mechanism: compliance certifications well outside the finance function are now getting tested under a statute that carries treble damages.

How should federal contractors reduce certification risk?

Start with an inventory. Every certification signed in the last five years. Then have compliance and operations independently confirm whether each one is accurate today, and where those answers diverge, you have found a problem before a relator does. The deeper fix is cultural, and I’ll say it plainly: a certification is a statement made to induce payment from the federal government, and treating it as an administrative signature is how organizations end up in a settlement press release.

Bring This to Your Team

If your organization sells to the federal government, the distance between what you certified and what is actually running is now a number with a dollar sign on it. You don’t close that distance with a policy update. You close it by changing how people decide, and deciding is human work. I speak internationally on business ethics, AI governance, and the behavior behind compliance failures, and I work with federal contractors, defense primes, and the compliance teams who carry the signature. To bring this conversation to your leadership team, board, or compliance summit, visit ChuckGallagher.com.

Five Questions for Reflection

1. Name the certifications your organization has signed in the last twelve months. If you can’t name them, who can — and why isn’t that person in the room when they come due?

2. When someone in your company flags a gap between what was certified and what is operating, what happens to that memo? Trace the path with names and dates.

3. Where in your organization does “we’ll fix it before anyone notices” currently pass for a plan?

4. If an outsider ran analytics on every public filing your company has made, what story would the pattern tell about you?

5. Whose signature is on the line, and does that person have the authority — and the cover — to refuse to sign?

Source: “The Expanding False Claims Act: DOJ’s New Enforcement Theories and What Federal Contractors Must Know,” K&L Gates, June 17, 2026, by Nora E. Becerra and Michael H. Phillips. Enforcement figures drawn from DOJ’s January 2026 FY 2025 False Claims Act statistics release and related DOJ announcements.

n?

Leave a Reply