Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Sunshine And March Vibes (2025 Wallpapers Edition)

      May 16, 2025

      The Case For Minimal WordPress Setups: A Contrarian View On Theme Frameworks

      May 16, 2025

      How To Fix Largest Contentful Paint Issues With Subpart Analysis

      May 16, 2025

      How To Prevent WordPress SQL Injection Attacks

      May 16, 2025

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025

      Minecraft licensing robbed us of this controversial NFL schedule release video

      May 16, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The power of generators

      May 16, 2025
      Recent

      The power of generators

      May 16, 2025

      Simplify Factory Associations with Laravel’s UseFactory Attribute

      May 16, 2025

      This Week in Laravel: React Native, PhpStorm Junie, and more

      May 16, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025
      Recent

      Microsoft has closed its “Experience Center” store in Sydney, Australia — as it ramps up a continued digital growth campaign

      May 16, 2025

      Bing Search APIs to be “decommissioned completely” as Microsoft urges developers to use its Azure agentic AI alternative

      May 16, 2025

      Microsoft might kill the Surface Laptop Studio as production is quietly halted

      May 16, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Defense Contractor Morse Corp Settles Cybersecurity Fraud Allegations for $4.6M

    Defense Contractor Morse Corp Settles Cybersecurity Fraud Allegations for $4.6M

    March 26, 2025

    Defense Contractor, U.S. Air Force, Morse Corp, Cybersecurity Compliance, NIST, Federal Cybersecurity Standards, Department of Justice, Settlement Agreement

    Morse Corp Inc., a Massachusetts-based defense contractor, has agreed to pay $4.6 million to resolve allegations of cybersecurity fraud under the False Claims Act. The U.S. Department of Justice announced the settlement, claiming that the company misrepresented its compliance with federal cybersecurity standards while working on contracts with the Departments of the Army and Air Force.

    Morse Corp Allegations and Legal Proceedings

    The case began in January 2023 when a whistleblower, Kevin Berich, filed a qui tam lawsuit against Morse Corp under the False Claims Act. The DOJ joined the case in March 2023, accusing the company of violating the Defense Federal Acquisition Regulation Supplement (DFARS) clauses. These regulations mandate that contractors adhere to the cybersecurity standards outlined in the National Institute of Standards and Technology (NIST) Special Publication 800-171.

    The DOJ’s investigation revealed that from January 2018 to September 2022, Morse Corp used a third-party service to host its emails without ensuring compliance with the FedRAMP Moderate baseline—a critical cybersecurity requirement for handling covered defense information. The company also failed to implement the required cybersecurity controls from NIST SP 800-171, which protect controlled unclassified information from unauthorized access.

    Misrepresentation of Cybersecurity Compliance

    According to the settlement agreement, Morse Corp submitted a misleading score of 104 on its cybersecurity assessment to the Department of Defense’s Supplier Performance Risk System (SPRS) in January 2021. However, an independent evaluation in July 2022 revealed a significantly lower score of -142, indicating that the company had only implemented 22% of the required controls. Despite this discovery, Morse Corp failed to update its score until June 2023.

    The settlement document also detailed that the defense contractor lacked a consolidated cybersecurity plan outlining system boundaries, operational environments, and connections to other networks. These oversights exposed sensitive defense data to potential exploitation and unauthorized access, violating its contractual obligations.

    Also Read: US Department of Defense Contractor Targeted by Donut Ransomware

    Financial Penalties and Whistleblower Award

    As part of the settlement, Morse Corp will pay $4.6 million, including $2.3 million as restitution. The whistleblower, Kevin Berich, will receive 18.5% of the total settlement amount for bringing the case to light. The agreement also requires Morse Corp to cover $198,616 in legal fees for Berich’s attorneys.

    “Failure to implement cybersecurity requirements can have devastating consequences, leaving sensitive DoD data vulnerable to cyber threats and malicious actors,” said Special Agent William Richards of the Air Force Office of Special Investigations (AFOSI). “(We) will continue to combat fraud affecting the Department of the Air Force and hold those accountable that fail to properly safeguard sensitive defense information.”

    Implications for Defense Contractors

    The settlement serves as a warning to defense contractors about the consequences of misrepresenting cybersecurity compliance. The DOJ emphasized that ensuring cybersecurity standards is not a procedural formality but a critical element of national security.

    Experts suggest that the case could lead to stricter enforcement of cybersecurity regulations and increased scrutiny of defense contractors. The outcome may prompt more whistleblowers to report non-compliance, given the significant financial incentives under the False Claims Act.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleHow Cognistx’s SQUARY AI is Redefining Information Access
    Next Article New SparrowDoor Backdoor Variants Found in Attacks on U.S. and Mexican Organizations

    Related Posts

    Security

    Nmap 7.96 Launches with Lightning-Fast DNS and 612 Scripts

    May 17, 2025
    Common Vulnerabilities and Exposures (CVEs)

    CVE-2024-47893 – VMware GPU Firmware Memory Disclosure

    May 17, 2025
    Leave A Reply Cancel Reply

    Continue Reading

    The AI Fix #27: Why is AI full of real-life Bond villains?

    Development

    CNCF Triggers a Platform Parity Breakthrough for Arm64 and x86

    Development

    The tasks college students are using Claude AI for most, according to Anthropic

    News & Updates

    Linux Foundation & Google Form New Group to Manage Chromium

    Linux

    Highlights

    The best early Black Friday AirPods deals: Shop early deals

    November 4, 2024

    Black Friday could be a great time to shop for a new pair of AirPods.…

    UX Tools Map 2024

    November 15, 2024

    Tinder for Jobs is Now Here: Revolutionizing Recruitment with Sorce

    January 30, 2025

    Kolmogorov-Arnold Networks (KANs): A New Era of Interpretability and Accuracy in Deep Learning

    May 2, 2024
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.