Aerojet Rocketdyne cybersecurity compliance settlement

A federal-contract cybersecurity compliance dispute ended in a settlement. The cited notice does not establish a cyber intrusion.

Last modified

Summary

  • Environment: Cybersecurity requirements in federal contracts
  • Operational impact: No operational disruption established by the notice
  • Financial impact: $9 million settlement
  • Record status: Documented record. Reviewed October 7, 2026; updated as evidence emerges.

What happened

The U.S. Department of Justice announced a settlement with Aerojet Rocketdyne on July 8, 2022. It resolved allegations of misrepresented cybersecurity compliance in federal contracts. [1]

Impact

  • The settlement amount was $9 million. [1]
  • The notice does not establish a data-exposure count or operational outage.

Timeline

  1. Settlement announced

    DOJ published its settlement notice.

    [1]
  2. Briefing updated

    This briefing was last reviewed and updated on October 7, 2026.

Threat Group & Attack Vector

This is a cybersecurity compliance proceeding. The cited notice establishes no technical intrusion or attack path.

Actors

  • No cyber threat actor is established by the settlement notice.

TTPs

  • MITRE ATT&CK techniques are not mapped to this compliance proceeding.

Response

The agreement resolved a whistleblower lawsuit and was reached on the second day of trial. DOJ expressly stated that the resolved claims were allegations and that liability had not been determined. [1]