Related Federal Cases
- Georgia Man Charged in $566K Sedgwick County Cyber Heist · Georgia
- Brian P. Johnson Sentenced in Georgia-Pacific Cyberattack · Georgia
- Georgia Man Pleads Guilty to Selling Stolen Credit Data · Georgia
- Pirate App Rings Busted, 6 Charged in Georgia · Georgia
- Georgia Woman Pleads Guilty to Damaging Protected Computer · Vermont
Defendant Name, Crime, Location, Year
The United States has filed a complaint-in-intervention against the Georgia Institute of Technology (Georgia Tech) and Georgia Tech Research Corporation (GTRC) for allegedly violating cybersecurity requirements in connection with Department of Defense (DoD) contracts.
According to the complaint, GTRC is an affiliate of Georgia Tech that contracts with government agencies for work to be performed at Georgia Tech. The lawsuit was initiated by current and former members of Georgia Tech’s Cybersecurity team, Christopher Craig and Kyle Koza.
“Government contractors that fail to fully implement required cybersecurity controls jeopardize the confidentiality of sensitive government information,” said Principal Deputy Assistant Attorney General Brian M. Boynton. “The department’s Civil Cyber-Fraud Initiative was designed to identify such contractors and to hold them accountable.”
The lawsuit alleges that until at least February 2020, the Astrolavos Lab at Georgia Tech failed to develop and implement a system security plan, which is required by DoD cybersecurity regulations, that set out the cybersecurity controls that Georgia Tech was required to put in place in the lab. Even when the Astrolavos Lab finally implemented a system security plan in February 2020, the lawsuit alleges that Georgia Tech failed to properly scope that plan to include all covered laptops, desktops, and servers.
The lawsuit further alleges that in December 2020, Georgia Tech and GTRC submitted a false cybersecurity assessment score to DoD for the Georgia Tech campus. DoD requires contractors to submit summary-level scores reflecting the status of their compliance with applicable cybersecurity requirements on covered contracting systems that are used to store or access covered defense information. The submission of this score was a “condition of contract award” for Georgia Tech’s DoD contracts.
“Cybersecurity compliance by government contractors is critical in safeguarding U.S. information and systems against threats posed by malicious actors,” said U.S. Attorney Ryan K. Buchanan for the Northern District of Georgia. “For this reason, we expect contractors to abide by cybersecurity requirements in their contracts and grants, regardless of the size or type of the organization or the number of contracts involved.”
The whistleblower lawsuit was filed by Christopher Craig and Kyle Koza, who were previously senior members of Georgia Tech’s cybersecurity team. The U.S. will hold accountable those contractors who ignore cybersecurity rules, said Special Agent in Charge Darrin K. Jones of the DoD’s Office of Inspector General, Defense Criminal Investigative Service (DCIS), Southeast Field Office.
Key Facts
- State: Georgia
- Category: Cybercrime
- Source: DOJ Press Release â†â€â€
ðŸâ€Â’ Get the grimiest stories delivered weekly. Subscribe free →

