Nobody at USDA Asked About the Firewall
Archer Daniels Midland is mostly out of the False Claims Act woods, and the story of how it got there is the most useful ruling on cyber-FCA enforcement in years. Nobody sued. Nobody settled. The relator, Mark Pannek, lost on paper, in a memorandum and order from Judge Sanjay Harjani of the Northern District of Illinois dated September 2, 2026, and the Department of Justice spent 26 months investigating before deciding it wanted no part of the case. You haven’t read about it because there’s no press release. There’s just a corpse.
Sort of a corpse. The dismissal was without prejudice, and Pannek has until September 23 to file another amended complaint or watch the dismissal convert to with prejudice. This article runs 12 days before that deadline, so treat the ending as provisional.
The cases the coverage never shows you
Since DOJ launched its Civil Cyber-Fraud Initiative in October 2021, there have been at least 17 settlements, from Aerojet and Penn State to the Booz Allen spinoffs, a steady drumbeat of Controlled Unclassified Information (CUI) cases. What you almost never see is a court ruling on the merits, because defendants settle. A settlement tells you what a company will pay to make an uncomfortable case go away; it tells you nothing about what a judge actually requires to sustain a claim. My own write-ups feed the imbalance too, including a Honeywell matter that involved poorly secured quantum computing but ended in a $2 million settlement. Covering only the survivors leaves the impression that a bad security posture plus a federal contract equals liability. United States ex rel. Mark Pannek v. Archer Daniels Midland Company is a counterpoint.
What the relator said happened inside ADM
Mark Pannek was ADM’s Director of Global Data Governance, Risk & Compliance from October 2018 to May 2023, which meant he had the keys to the audits. His original complaint, filed under seal in October 2023, described a company that ingested everything.

Around that centerpiece sat roughly 500 users with excessive privileges and 52 servers in China despite the chief information security officer’s assurances otherwise. Some 25,000 data transfers went untracked, and a spring 2023 social engineering attack used AI voice cloning. Pannek alleged he was fired in May 2023, three days after an internal audit corroborating his concerns reached the executive team.
All of this attached to 366 federal awards worth about $861.7 million between 2013 and 2023, overwhelmingly soybean-meal, sorghum, and rice purchases from the US Department of Agriculture (USDA). The remainder was a handful of Department of Energy (DOE) biofuel grants and one Army Corps purchase order to repair a vessel called the MV Davenport.
If the allegations were even half right, ADM ran a sloppy shop. That was never the question.
The amended complaint ate its own best material
By the time Pannek filed his first amended complaint in February 2026, the data lake had nearly vanished from the pleadings, along with the Chinese servers and the voice cloning. The legal team had swapped the horror stories for a colder inventory of the USDA contracts themselves, a Climate-Smart Commodities grant, DOE grants, and representations made in SAM registration. When your best facts don’t connect to any statement the government relied on, your lawyers cut them. That’s not a tactical choice. It’s a concession.
The docket shows that DOJ declined to intervene on December 29, 2025 after 26 months of sealed investigation, and the two lead counsel from the original complaint had withdrawn by mid-2026, after the dismissal briefing was done. Along the way, a federal government shutdown in October 2025 put the entire case in abeyance, right as the declination decision was being brewed. Draw your own conclusions about what the people closest to the case thought about it.
Two blades, one complaint
Judge Harjani’s order granted ADM’s motion to dismiss on two grounds, and the sequencing matters. The primary blade was materiality. The Seventh Circuit’s Molina Healthcare decision requires a plaintiff to plead facts showing the government actually attaches weight to the requirement at issue, and Pannek’s amended complaint, pared down to the USDA and DOE awards, still ran to over 250 contracts’ worth of allegations without a single fact suggesting USDA’s commodity buyers cared about cybersecurity representations when cutting purchase orders. USDA kept buying grain. It never asked about the firewall, never conditioned payment on it, never suspended or terminated anything.
The second blade was Rule 9(b) particularity. For contracts before 2025, the only representations were implied ones, the theory that agreeing to a contract implies promising compliance with every applicable regulation, and the court dispatched those under Berkowitz v. Milwaukee. For USDA Master Solicitation for Commodity Purchases contracts entered after February 13, 2025, when the domestic solicitation began expressly incorporating the text of Federal Acquisition Regulation (FAR) clause 52.204-21, and after May 7, 2025 for the international version, the express agreements survived particularity. They died on materiality anyway.
Before you skip past that clause, notice what it is. FAR 52.204-21, Basic Safeguarding of Covered Contractor Information Systems, is the 15-control minimum for Federal Contract Information (FCI). That’s FCI, not CUI, the lowest rung on the federal cybersecurity ladder, and it became express in these awards because somebody revised a master solicitation template, not because a regulation changed. The strongest hook Pannek ever had was a checkbox on the weakest standard in the building.
The court did hand Pannek a few things on the way down. Falsity and scienter were plausibly pleaded for statements made after ADM’s own 2019 audit and 2022 internal report documented the problems, because you can’t knowingly lie about facts you haven’t learned yet. Statements made before those findings existed got a pass. The court also declined to decide whether National Institute of Standards and Technology (NIST) SP 800-171 and the various CUI regulations applied at all, calling that premature.
The order includes this banger of a footnote addressed to every lawyer drafting a cyber complaint:
The amended complaint was “sprawling, and so full of jargon and acronyms that it is difficult for the Court to identify the pertinent facts.”
LOGZONE, the opposite
I wrote in June about LOGZONE, a veteran-owned small business in Huntsville that sold to the Department of Defense (DOD). It self-reported a perfect 110 on its NIST SP 800-171 assessment in October 2021, then watched DIBCAC’s Medium Assessment in February 2024 score it a negative 170. The settlement, executed June 17, 2026, cost $507,144 in restitution and penalties against $682,193.37 in Navy billings. Compare the architecture:
| Dimension | LOGZONE | Pannek v. ADM |
|---|---|---|
| Buyer | Navy / DOD | USDA, DOE |
| Contract regime | DFARS 252.204-7012, CUI, SPRS scoring | FAR basic safeguarding, FCI |
| Representation | Sworn self-assessment score, 110 | Implied terms, then one express 52.204-21 checkbox |
| Proof of falsity | DIBCAC rescored it at -170 | Enterprise-wide hygiene narrative |
| Government’s role | Settled through the Task Force to Eliminate Fraud | Declined after 26 months |
| Outcome | $507,144 settlement | Dismissed under Rule 12(b)(6) |
The regime column, for anyone who hasn’t memorized the alphabet soup, means the Defense Federal Acquisition Regulation Supplement (DFARS) clause covering CUI safeguarding, a self-score posted to the Supplier Performance Risk System (SPRS), and verification by the Defense Industrial Base Cybersecurity Assessment Center (DIBCAC). DOD built machinery that makes materiality mechanical. A sworn score, assessment authorities who verify it, and a solicitation structure where the score feeds payment decisions. USDA commodity procurement has no equivalent, so the same species of conduct becomes a half-million-dollar liability in one lane and a dismissed complaint in the other. Now, LOGZONE settled and never had to clear the materiality bar. It just had facts nobody would bother to contest.
That’s the whole thesis, and it’s the one from my book. There’s no such thing as “cyber risk”. There are business risks, some of which involve computers, and something to think through is whether your counterparty built a payment structure that notices.
What a quiet failure teaches
If you run security or compliance for a federal contractor, the takeaways from this case:
- Implied certification just lost a well-funded fight in the Seventh Circuit. What binds you now is what your representative expressly agreed to, which for civilian contracts increasingly means the 52.204-21 text showing up in solicitation revisions.
- On the Defense Industrial Base (DIB) side, none of this pauses with the Cybersecurity Maturity Model Certification (CMMC) suspension. SPRS affirmations, DIBCAC audits, and DOJ’s appetite all survived the summer’s changes. The machinery that convicted LOGZONE runs on.
- Audit findings are scienter with a delay fuze. The Pannek court’s own logic says statements become actionable once your internal reports document the problem and you keep billing anyway. Remediation is now litigation defense.
- Check what your buyers actually ask about, because the agencies you sell to are making your risk decisions for you. Sorghum sellers and submarine component suppliers have wildly different exposure schedules, and neither chose theirs.
12 days
On September 23, Pannek either files again, lets the dismissal harden into with prejudice, or negotiates his exit on the record. I’ve added the case to my tracking list, and whichever ending arrives, the lesson stands. The government enforces what it bothers to write down, ask about, and pay against. Everything else is a security posture nobody invoices.