On September 2, 2026, Judge Sunil R. Harjani of the Northern District of Illinois dismissed a qui tam False Claims Act complaint alleging that Archer Daniels Midland misrepresented its cybersecurity practices to obtain federal grants and contracts, holding that the relator failed to plead materiality. The case is United States ex rel. Pannek v. Archer Daniels Midland Co., No. 23-cv-15145 (N.D. Ill. Sept. 2, 2026). The dismissal was without prejudice, and the rest of the opinion is at least as instructive for contractors as the headline.
The allegations
Mark Pannek, a former ADM employee, alleged that ADM received USDA, Department of Energy, and other federal grants and more than 250 contracts while its data-protection practices fell short of federal requirements. The complaint described a centralized data repository with no encryption, broad access with no access logs, unencrypted transfers to external systems, weak screening of third-party providers, and use of banned telecommunications equipment. It invoked the CUI program rules at 32 C.F.R. Part 2002, NIST SP 800-171, and FAR 52.204-21, and alleged that 2019 audits and a 2022 investigation had put ADM executives on notice.
The holding: materiality
The court applied the FCA's strict materiality standard from Universal Health Services v. Escobar, 579 U.S. 176 (2016), and Seventh Circuit precedent. The relator pointed to agency data-protection policies and to other cyber-FCA settlements as proof that the government cares about cybersecurity. The court found that insufficient: none of those allegations connected to the government's specific decisions to fund ADM's grants and contracts. Alleging that cybersecurity compliance was a condition of payment, or that the government could have declined to pay, does not establish materiality under Escobar. The complaint needed facts showing the government actually relied on ADM's cybersecurity practices in its payment decisions.
What the court did *not* reject
Contractors should read the remaining sections carefully, because the court went out of its way to address them "in the event that Pannek repleads."
- Some statements were pled with particularity. Terms in a USDA Climate-Smart Commodities grant, SAM registration representations about covered telecommunications equipment, and DOE grant conditions requiring cybersecurity measures and a data management plan were detailed enough. So were contracts after February 2025 that allegedly incorporated cybersecurity requirements expressly. Vague "comply with all laws" theories tied to other grants and older contracts were not.
- Falsity survived. Allegations of excessive access and missing access records, if paired with a compliance representation, would render that representation false. Whether ADM's practices were in fact reasonable is a question for discovery.
- Scienter was plausible — for later statements. Statements made before the 2019 audit could not have been knowingly false; statements made after internal reviews identified problems plausibly were.
- The regulations plausibly applied. ADM argued that the CUI rules, SP 800-171, and FAR 52.204-21 did not apply to it at all. At the pleading stage, the court accepted the allegations that ADM holds producer records (names, Social Security numbers, addresses, pricing) for the government and that FAR 52.204-21 appears in its post-2025 contracts. That was enough.
The relator was given until September 23, 2026 to file an amended complaint, after which the dismissal would convert to one with prejudice. We have not confirmed from the public docket whether an amendment was filed.
Why this matters to contractors
This is one district court ruling at the pleading stage. It does not bind other courts, and it does not mean cyber-FCA exposure has receded. DOJ-initiated matters, which have produced the recent settlements covered on our enforcement page, typically come with evidence of agency reliance that a relator working from internal documents may lack. And the defense-sector posture is different: SPRS scores and CMMC affirmations are built into award and option decisions, which makes a materiality showing easier to plead.
The more durable lessons sit in the sections the court did not dismiss:
1. Non-DoD awards carry cyber terms too. Grant conditions, SAM representations, and FAR 52.204-21 were all treated as potential false statements. If you hold USDA, DOE, or other civilian awards, inventory the cybersecurity and data-protection terms in them — see Find My Requirements. 2. Your own audits define your knowledge. The court drew the scienter line at the date internal reviews surfaced problems. Once an audit finds gaps, representations made afterward are judged against what you knew. Track remediation through a documented plan and align your representations with it — our program-building guide covers the mechanics. 3. Know whether you hold CUI or FCI. The "it doesn't apply to us" argument lost at this stage because the relator plausibly alleged that ADM held government-related records. Settle that question before someone else frames it — see CUI vs. FCI and FAR 52.204-21.
Key Takeaways
- Pannek v. ADM dismissed a cyber-FCA complaint because the relator did not plead facts showing the government relied on ADM's cybersecurity practices when funding its awards; general agency interest in cybersecurity and other settlements were not enough under Escobar.
- The dismissal was without prejudice, and the court found several alleged statements, the falsity theory, post-audit scienter, and the applicability of the CUI rules, SP 800-171, and FAR 52.204-21 adequately pled.
- Treat civilian grant and contract cyber terms as representations, align representations with what your own audits have found, and resolve whether you hold CUI or FCI before a dispute forces the question.
This post is educational information, not legal advice. It does not create an attorney-client relationship.