The Billion-Dollar Cyber Whistleblower Case That Just Hit A Wall
Mark Pannek believed he knew something the federal government needed to know about the cybersecurity practices of his former employer, Archer Daniels Midland.
Pannek, a former senior IT governance and compliance official at ADM, alleged that the global agricultural company had received more than $1 billion in federal grants and contracts while failing to address what he characterized as persistent cybersecurity deficiencies. According to his complaint, sensitive information was stored in a large centralized data repository without encryption, hundreds of employees and contractors allegedly had access without documented business justification, access logging was inadequate, sensitive information was transmitted to external systems without adequate encryption, third-party providers were insufficiently screened, and banned telecommunications equipment was allegedly in use. Pannek further alleged that internal reviews dating to 2019 and 2022 had identified data-protection concerns and that findings had reached company executives. ADM disputed the allegations and argued, among other things, that many of the cybersecurity requirements cited by Pannek did not apply.
The allegations were particularly consequential because ADM was receiving federal money. Pannek alleged that more than 250 government contracts included express or implied requirements for protecting sensitive information, while other federal grants required cybersecurity safeguards, internal controls or data-management plans. He argued that ADM’s acceptance of that government money, along with certain certifications and representations, amounted to false claims because the cybersecurity reality inside the company allegedly did not match what was being represented outside it.
So Pannek did something that every executive doing business with the federal government should understand. He became a whistleblower and sued his former employer on behalf of the United States under the False Claims Act .
The Department of Justice declined to intervene. Pannek continued the litigation himself. Then, on September 2, 2026, a federal judge dismissed his cybersecurity fraud complaint. Pannek’s recovery from the case so far is therefore exactly zero dollars.
But that does not make the case irrelevant. Quite the opposite. United States ex rel. Pannek v. Archer Daniels Midland Company may be one of the most instructive cybersecurity FCA decisions yet because it illuminates both the extraordinary power of America’s whistleblower system and the limits that prevent every cybersecurity deficiency from becoming fraud.
It also raises a much bigger question for the DIB: If the government cannot possibly inspect every contractor continuously, how much of cybersecurity enforcement will ultimately depend on the people who already work inside those companies?
The Whistleblower Had Information The Government Could Never Easily See
The significance of the Pannek case is not simply what he alleged. It is where the allegations allegedly came from. Pannek was not an outside security researcher scanning an internet-facing server. He was a former senior IT governance and compliance official. His complaint referenced internal cybersecurity audits and investigations that he alleged identified problems with ADM’s data storage and controls. According to the court’s description of his allegations, findings from a 2019 formal cybersecurity audit and a 2022 investigation report were shared with executives.
That is exactly what makes insiders so consequential to cybersecurity enforcement. Government auditors may see an assessment, a score, a certification or the state of an environment during an audit. Employees can potentially see something very different: what management knew before the certification was made, which vulnerabilities were identified internally, which remediation efforts were delayed, what executives were told and whether external representations changed when the internal facts changed.
In Pannek’s case, the court actually found some of those allegations sufficient to get over important preliminary hurdles. Judge Sunil Harjani concluded that Pannek had plausibly alleged that certain cybersecurity requirements could apply to ADM. For some alleged later statements, the court also found it plausible at this stage that ADM knew about alleged deficiencies when representations concerning cybersecurity compliance were made. The court emphasized, however, that these were allegations being evaluated at the motion-to-dismiss stage, not proven findings of wrongdoing. Then Pannek hit the wall.
Knowing About A Cybersecurity Problem Is Not Enough
Pannek’s problem was materiality.
Under the False Claims Act, it is not sufficient to identify a cybersecurity deficiency, point to a government requirement and conclude that fraud occurred. A relator must establish, among other elements, that an allegedly false representation was material to the government’s decision to pay. That is where Pannek’s complaint fell short.
The court concluded that he had not plausibly alleged that the government actually attached sufficient weight to ADM’s cybersecurity practices when making the relevant funding decisions. The government might care greatly about cybersecurity in general, the judge reasoned, but that is different from demonstrating that the alleged noncompliance would have significantly affected the particular government’s decision to fund the contracts or grants at issue.
That distinction is enormously important. It means a cybersecurity gap is not automatically fraud. A failed control is not automatically fraud. A disagreement about how a NIST requirement should be implemented is not automatically fraud. Even violating a contractual requirement does not by itself establish FCA liability.
The dismissal was without prejudice, so the story may not be over. Pannek was given until September 23 to file an amended complaint addressing the deficiencies identified by the court. But as of this writing, he has recovered nothing from the case.
That outcome provides an important counterweight to another story unfolding across federal cybersecurity enforcement. Other whistleblowers have received millions.
When The Whistleblower Wins, The Rewards Can Be Enormous
The FCA is an unusual enforcement mechanism because private citizens can effectively become partners in protecting the federal treasury.
Under its qui tam provisions, a private person known as a relator can sue on behalf of the United States. The complaint is initially filed under seal while the government investigates. DOJ can intervene and take over the case, decline intervention and allow the relator to continue, or in some circumstances seek dismissal. When a qualifying case results in a recovery, whistleblowers can generally receive between 15% and 30% of the proceeds, depending partly on whether the government intervenes.
In the Aerojet Rocketdyne cybersecurity case, former employee Brian Markus received $2.61 million from a $9 million settlement. In the Guidehouse and Nan McKay matter involving cybersecurity requirements for a federally funded rental-assistance system, the whistleblower entity received approximately $1.95 million from combined settlements totaling $11.3 million. A former Illumina director received $1.9 million from a $9.8 million settlement involving alleged cybersecurity vulnerabilities in genomic sequencing systems.
The pattern has continued. A former Penn State Applied Research Laboratory CIO received $250,000 from a $1.25 million settlement. Two former Georgia Tech cybersecurity employees received $201,250 following an $875,000 settlement. More recently, the former employee who brought a case involving Honeywell Aerospace is set to receive $375,823 from a settlement exceeding $2 million.
The numbers become even more striking when viewed across the entire FCA system. In fiscal 2025, whistleblowers filed a record 1,297 qui tam lawsuits, and more than $5.3 billion of that year’s FCA settlements and judgments came from whistleblower-filed matters. Since Congress strengthened the law in 1986, FCA settlements and judgments have exceeded $85 billion.
Cybersecurity is now becoming part of that machinery. DOJ reported more than $52 million recovered through nine cybersecurity fraud settlements in fiscal 2025 alone.
Why Cybersecurity Is Almost Designed For Whistleblower Enforcement
There is an uncomfortable reality at the center of federal cybersecurity enforcement: the government cannot be everywhere. The DIB alone includes tens of thousands of companies and an enormous web of subcontractors. Across the federal government, contractors operate countless systems, applications, cloud environments and endpoints while processing different categories of government information.
No federal agency could continuously inspect every one of those environments. Employees, however, are already inside them. They see internal assessments. They participate in security meetings. They read vulnerability reports. They know whether remediation projects are funded or repeatedly postponed. They may know whether a score submitted to the government accurately reflects the environment. And they may know whether executives signing certifications have been told something materially different internally.
Whistleblowers therefore solve a fundamental information problem for government enforcement. Instead of requiring investigators to discover every discrepancy independently, an insider can hand investigators the roadmap.
That can be an extraordinarily effective enforcement model. It can also be dangerous if every disagreement, control deficiency or technical interpretation becomes potential litigation. Pannek demonstrates why both sides of that equation matter.
When There Is No Enforcement, The Economics Can Reward The Wrong Behavior
Cybersecurity compliance costs real money. Companies have to hire qualified people, modernize aging infrastructure, implement identity and access controls, deploy monitoring, protect endpoints, document their environments, remediate vulnerabilities and maintain evidence that controls are actually operating.
Consider two defense contractors bidding for the same work. One spends heavily to satisfy its contractual cybersecurity obligations and accurately represents the deficiencies it still needs to address. Another spends less, leaves substantial requirements unfinished and represents itself as compliant anyway. If nobody ever checks, the second company may have the economic advantage and that is fundamentally unfair.
DOJ explicitly identified protecting contractors that follow cybersecurity requirements from competitive disadvantage as one purpose of its Civil Cyber-Fraud Initiative . Enforcement therefore serves a purpose beyond recovering money after misconduct occurs. It changes the economic calculation beforehand.
If contractors believe there is little probability that inaccurate cybersecurity representations will ever be discovered, the incentive to invest in compliance weakens. If an employee, competitor, auditor or government investigator can expose a material misrepresentation, the calculation changes considerably. Whistleblowers are one answer to the enforcement gap, but they cannot be the only answer.
The System Has Benefits And Real Risks
There is a compelling argument for rewarding whistleblowers. Insiders can expose information the government might never discover. Technical employees can translate complicated systems for investigators. Retaliation protections can give employees a mechanism to raise concerns when doing so may jeopardize their careers. Financial awards can compensate people for assuming significant professional and personal risk.
There is also a deterrent effect that is impossible to measure precisely. An executive who knows that dozens of engineers, compliance professionals and security analysts can see the underlying evidence has another reason to ensure that external representations match internal reality.
But there are legitimate criticisms of the system as well. Large financial awards can create incentives for aggressive allegations. Cybersecurity standards can be complicated and sometimes subject to reasonable interpretation. Internal security teams routinely disagree about risk, prioritization and implementation, and disagreement does not equal fraud. Even a FCA case that ultimately fails can impose substantial legal expense, management distraction and reputational damage.
There is another danger that cybersecurity leaders should take seriously. Organizations need their security professionals to identify and document problems. If executives begin treating every internal assessment, vulnerability report or dissenting technical opinion primarily as potential litigation evidence, the perverse response may be to document less. That would make organizations less secure, not more secure.
Pannek therefore represents an important safeguard as well as a warning. The court did not say cybersecurity obligations do not matter. In fact, it found that Pannek had plausibly alleged that several cybersecurity requirements could apply and that some of his allegations concerning knowledge could proceed past an initial plausibility threshold. What he had not sufficiently connected was the alleged cybersecurity misrepresentation to the government’s actual payment decision. That is an important line for courts to police.
Five Things DIB Executives Should Do Now
For Defense Industrial Base executives, the practical lesson is not to fear whistleblowers or discourage employees from documenting cybersecurity deficiencies. The better response is to build an organization in which employees have little reason to believe that internal reality and external representations are materially different. That requires more than preparing for an assessment. It requires continuously knowing whether the security controls an organization claims to have are actually operating.
- Know exactly what you are representing to the government. CEOs, CFOs, CIOs and other executives should understand the cybersecurity representations embedded in contracts, SPRS submissions, CMMC affirmations and other certifications. These cannot be treated as paperwork owned exclusively by IT or compliance. Executives should know what evidence supports those representations and how current that evidence is.
- Reconcile internal findings with external representations. If an assessment, penetration test, vulnerability scan, security monitoring system or employee identifies a material deficiency, determine whether that discovery affects anything previously represented to a customer or government agency. Compliance and cybersecurity operations cannot exist in separate worlds.
- Create a credible internal escalation path. Employees need somewhere to raise cybersecurity concerns where they will be investigated rather than buried. Ignored internal warnings can later become some of the most consequential evidence in litigation. A mature security program should surface bad news early, escalate it appropriately and track it through remediation.
- Document remediation rather than hide imperfection. No serious cybersecurity program is perfect. What matters is whether deficiencies are identified, accurately represented, prioritized and corrected. Organizations should maintain evidence not only that a control exists on paper, but that it continues to operate and that identified failures are being addressed.
- Independently verify before executives certify. When an executive’s name is attached to a cybersecurity affirmation , there should be evidence behind it. That evidence should be continuously maintained and periodically tested by people with enough independence and expertise to challenge assumptions rather than simply validate them. Executives should be able to trace a certification back to actual controls, evidence and remediation activity rather than a spreadsheet or point-in-time assessment.
Those five actions will not eliminate FCA risk, nor should that be the objective. The objective is to ensure that an organization can demonstrate that it took its cybersecurity obligations seriously, continuously monitored whether its controls were working, investigated problems when they were identified, corrected them when necessary and, above all, told the truth about its security posture.
Whistleblowers Are Becoming Part Of The Cybersecurity Control Environment
The Pannek case is fascinating precisely because the whistleblower did not walk away with millions of dollars. His allegations were serious enough that a federal court found some of the cybersecurity requirements he cited plausibly applicable and some of his allegations concerning ADM’s knowledge plausible at the pleading stage. But the judge still dismissed the case because alleging cybersecurity deficiencies and knowledge of those deficiencies did not sufficiently establish that the alleged representations were material to the government’s payment decisions.
That is how the system should be tested. Whistleblowers should have a mechanism to expose alleged fraud that government investigators may never independently discover, while companies should not face liability simply because their cybersecurity programs are imperfect.
The broader trend, however, is difficult to ignore. The government has created substantial financial incentives for insiders to report alleged fraud, DOJ has made cybersecurity an explicit FCA enforcement priority, and successful cyber whistleblowers have already collected millions of dollars.
For the DIB, this creates a new reality. The cybersecurity control environment no longer consists only of firewalls, identity systems, encryption, monitoring, assessments and audits. It also includes the people sitting inside the organization who know whether what is being said outside the company matches what is known inside it.
That may ultimately be the most powerful feature of the whistleblower system.
The government does not have to be inside every contractor.
Sometimes, somebody already is.