Close Menu
    DevStackTipsDevStackTips
    • Home
    • News & Updates
      1. Tech & Work
      2. View All

      Slack’s AI search now works across an organization’s entire knowledge base

      July 17, 2025

      In-House vs Outsourcing for React.js Development: Understand What Is Best for Your Enterprise

      July 17, 2025

      Tiny Screens, Big Impact: The Forgotten Art Of Developing Web Apps For Feature Phones

      July 16, 2025

      Kong AI Gateway 3.11 introduces new method for reducing token costs

      July 16, 2025

      Got ChatGPT Plus? You can record and summarize meetings on a Mac now – here’s how

      July 17, 2025

      I put this buzzworthy 2-in-1 robot vacuum to work in my house – here’s how it fared

      July 17, 2025

      AI agents will change work and society in internet-sized ways, says AWS VP

      July 17, 2025

      This slick gadget is like a Swiss Army Knife for my keys (and fully trackable)

      July 17, 2025
    • Development
      1. Algorithms & Data Structures
      2. Artificial Intelligence
      3. Back-End Development
      4. Databases
      5. Front-End Development
      6. Libraries & Frameworks
      7. Machine Learning
      8. Security
      9. Software Engineering
      10. Tools & IDEs
      11. Web Design
      12. Web Development
      13. Web Security
      14. Programming Languages
        • PHP
        • JavaScript
      Featured

      The details of TC39’s last meeting

      July 17, 2025
      Recent

      The details of TC39’s last meeting

      July 17, 2025

      Notes Android App Using SQLite

      July 17, 2025

      How to Get Security Patches for Legacy Unsupported Node.js Versions

      July 17, 2025
    • Operating Systems
      1. Windows
      2. Linux
      3. macOS
      Featured

      Microsoft says it won’t change Windows 11’s system tray design after users feedback

      July 17, 2025
      Recent

      Microsoft says it won’t change Windows 11’s system tray design after users feedback

      July 17, 2025

      How Rust’s Debut in the Linux Kernel is Shoring Up System Stability

      July 17, 2025

      Microsoft is on track to become the second $4 trillion company by market cap, following NVIDIA — and mass layoffs

      July 17, 2025
    • Learning Resources
      • Books
      • Cheatsheets
      • Tutorials & Guides
    Home»Development»Federal IT Contractor Pays $14.75 Million Fine to Settle Cyber Fraud Charges

    Federal IT Contractor Pays $14.75 Million Fine to Settle Cyber Fraud Charges

    July 15, 2025

    Federal Contractor, Cybersecurity, Federal IT Contractor, Cyber Fraud, False Claim Act

    A Maryland-based IT firm, Hill ASC Inc., has agreed to fork over at least $14.75 million in a settlement that brings the federal contractors under the scanner. This isn’t just about money but a reminder that cutting corners on IT services for Uncle Sam carries a hefty price, especially when national security is on the line.

    The U.S. Department of Justice on Monday revealed that Hill Associates allegedly billed federal agencies for IT staff who simply didn’t meet the contractually required experience or education. For five years, from 2018 to 2023, the company operated under a General Services Administration (GSA) program, a pipeline meant to get top-tier commercial services to the government efficiently.

    Investigators also claimed Hill Associates submitted invoices for specific cybersecurity services despite failing a critical technical evaluation. The GSA demands these rigorous assessments for contractors offering highly adaptive cybersecurity solutions to government clients. Not passing such an evaluation points to significant gaps in the company’s advertised capabilities.

    The firm reportedly charged unauthorized fees and neglected to give government customers crucial information about prompt payment discounts. Additionally, Hill Associates included unallowable incentive compensation within a cost submission for a new contract proposal, further muddying its billing practices.

    Cybersecurity experts believe there is an absolute necessity for strict oversight in government IT contracts. Agencies depend on contractors to uphold the highest standards, particularly when services directly impact federal operations and critical data integrity. Any slip from agreed-upon terms, whether unqualified personnel or misrepresented capabilities, erodes trust and opens doors for potential vulnerabilities.

    “Federal agencies should get what they have paid for from GSA contractors, nothing less,” GSA’s Deputy Inspector General, Robert Erickson said. This sentiment resonates deeply within the cybersecurity community, where the quality of IT infrastructure and the expertise of its stewards directly influence national security and operational resilience.

    Loren Sciurba, Treasury Deputy Inspector General, added that “false claims and similar unfair advantage by contractors undermine the integrity of the contracting process and can result in significant adverse effects to vital security concerns.” The implications stretch far beyond mere financial misconduct; subpar IT services can expose federal systems to advanced persistent threats (APTs) and sophisticated nation-state hackers.

    Apart from the fine, Hill Associates also agreed to pay 2.5% of its annual gross revenue exceeding $18.8 million beginning next year.

    The allegations were filed under the False Claims Act, a U.S. federal law that imposes liability on individuals and companies who defraud the government. In fiscal year 2024, the DOJ recovered over $2.9 billion from civil cases involving fraud and false claims.

    Another defense contractor who settled with DOJ earlier this year was Morse Corp Inc., a Massachusetts-based company. The contractor agreed to pay $4.6 million to resolve allegations of cybersecurity fraud that involved the company misrepresenting its compliance with federal cybersecurity standards while working on contracts with the Departments of the Army and Air Force.

    Also read: Defense Contractor Morse Corp Settles Cybersecurity Fraud Allegations for $4.6M

    According to the settlement agreement, Morse Corp submitted a misleading score of 104 on its cybersecurity assessment to the Department of Defense’s Supplier Performance Risk System (SPRS) in January 2021. However, an independent evaluation in July 2022 revealed a significantly lower score of -142, indicating that the company had only implemented 22% of the required controls.

    While Hill Associates and Morse Corp. agreed to pay the fine and settle without admitting liability, the case shines a bright light on a persistent challenge in public sector contracting. Ensuring vendors truly possess the stated qualifications and deliver services as promised is fundamental to robust cloud security and strong application security. This vigilance protects against future data breaches and maintains the integrity of critical government systems.

    Source: Read More

    Facebook Twitter Reddit Email Copy Link
    Previous ArticleNorth Korean Hackers Flood npm Registry with XORIndex Malware in Ongoing Attack Campaign
    Next Article Third Time in 90 Days: Louis Vuitton UK Latest Victim in LVMH Cyberattacks

    Related Posts

    Repurposing Protein Folding Models for Generation with Latent Diffusion
    Artificial Intelligence

    Repurposing Protein Folding Models for Generation with Latent Diffusion

    July 17, 2025
    Artificial Intelligence

    Scaling Up Reinforcement Learning for Traffic Smoothing: A 100-AV Highway Deployment

    July 17, 2025
    Leave A Reply Cancel Reply

    For security, use of Google's reCAPTCHA service is required which is subject to the Google Privacy Policy and Terms of Use.

    Continue Reading

    CVE-2025-5234 – WordPress Gutenverse News Plugin Stored Cross-Site Scripting Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    This new RTX 5060 gaming laptop is already $400 off — the cheapest way to get NVIDIA’s DLSS 4 and Multi Frame Gen

    News & Updates

    Chinese-owned VPN apps hide their origin

    Development

    CVE-2025-4005 – PHPGurukul COVID19 Testing Management System SQL Injection Vulnerability

    Common Vulnerabilities and Exposures (CVEs)

    Highlights

    What’s new in iOS 18.4? AI priority notifications and 9 other big updates

    April 1, 2025

    Apple also released software updates for iPadOS, WatchOS, MacOS, VisionOS, and TVOS. Here’s a list…

    Perform OS upgrades for Amazon RDS Custom for SQL Server CEV with Multi-AZ

    May 9, 2025

    Model Performance Begins with Data: Researchers from Ai2 Release DataDecide—A Benchmark Suite to Understand Pretraining Data Impact Across 30K LLM Checkpoints

    April 17, 2025

    Xbox gamers are waking up to surprise treasure—free $5 or $10 Microsoft Store gift cards dropping into their inboxes like digital gold

    April 18, 2025
    © DevStackTips 2025. All rights reserved.
    • Contact
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.