Annual Threat Brief — June 2026

Texas Defense
Contractors
Cyber Threat Brief

CMMC Phase 2 enforcement begins November 10, 2026. Nine documented incidents. $26M+ in False Claims Act settlements. Four active threat actor campaigns targeting Texas DIB. This is your compliance and threat reference for the Texas defense industrial base.

  • DIB is the #2 most-attacked sector in the U.S. — after healthcare
  • CMMC Level 2 C3PAO assessment now a condition of award
  • SPRS score fraud is personal FCA exposure for signing officials
  • CoreRecon SDVOSB — primes can flow subcontract awards to hit set-aside goals
Take SPRS Calculator Free Gap Assessment
★ SDVOSB Certified Report 1302192 June 16, 2026 37 primary sources
Defense contractor cybersecurity threat brief
$26M+
FCA Settlements
9
Documented Incidents
Nov '26
CMMC Phase 2
4
Active Threat Actors

DIB is under systematic
compliance and cyber assault

#2
Most-Attacked Sector in the U.S.
After healthcare. Every defense contractor in Texas is in scope — prime or sub. Source: CISA director testimony, 2024.
$28,619
Per False Claim — FCA Penalty
Each inaccurate SPRS submission is a potential false claim. FCA penalties up to $28,619 per claim plus treble damages. Whistleblower awards 15–30% of recovery.
110
NIST 800-171 Controls for CMMC L2
Phase 2 enforcement begins November 10, 2026. C3PAO third-party assessment required. Self-assessment is no longer sufficient for applicable contracts.
CoreRecon SDVOSB — Structural Competitive Advantage

Primes can flow subcontract awards through CoreRecon to meet FAR 19.14 SDVOSB set-aside goals under DFARS 252.219-7012. No other Texas MSSP has this certification.

  • Large defense primes (Lockheed Martin, Raytheon, L3Harris, BAE) must hit 20–25% small-business subcontracting goals
  • Awarding a subcontract to an SDVOSB like CoreRecon counts toward that goal
  • CoreRecon provides CMMC compliance services while the prime hits its small-business percentage
  • Texas primes with Fort Worth F-35, Bell V-280, McKinney Raytheon contracts — this is a compliance and procurement strategy in one

Nine documented incidents.
Every one sourced.

Company Incident Date Financial Exposure Key Source
Aerojet Rocketdyne Qui tam FCA suit alleging false DFARS 252.204-7012 compliance certifications. Nation-state breach concealed from government (2013–2014). DOJ intervened. FCA July 2022 $9M DOJ Press Release 22-726, E.D. California
Penn State Applied Research Lab Former CIO filed qui tam alleging false SPRS scores, 15 NIST 800-171 controls unimplemented, non-FedRAMP cloud for CUI on DoD/NASA contracts. FCA Oct 2024 $1.25M DOJ U.S. Attorney E.D. Pennsylvania, Oct 22, 2024
MORSECORP Inc. Admitted failure to ensure third-party SaaS email hosting met FedRAMP Moderate on Army/Air Force contracts (DFARS 252.204-7012), Jan 2018–Sep 2022. FCA Mar 2025 $4.6M DOJ Civil Division, March 26, 2025, D. Massachusetts
Raytheon / RTX / Nightwing Non-compliant internal development network ("1.0") used across 29 DoD contracts (2015–2021). No SSP. NIST 800-171 controls not implemented. DOJ civil fraud. FCA May 2025 $8.4M DOJ Civil Division, May 1, 2025, D. Massachusetts
Georgia Tech Research Corp. DOJ intervened Aug 2024 — false SPRS scores, missing antivirus, absent security plan on Air Force/DARPA contracts (Astrolavos Lab). Disputed, filed motion to dismiss. Settlement Sept 2025 $875K DOJ Civil Division, Sept 30, 2025, N.D. Georgia
Boeing LockBit ransomware on parts and distribution business. $200M ransom demanded, refused. ~43GB data published including engineering specs, supplier data, internal comms. Exploited Citrix Bleed (CVE-2023-4966). Oct–Nov 2023 Undisclosed (IP, supply chain, reputational) DOJ indictment; Cloudskope; BleepingComputer; Bloomberg
HENSOLDT (Germany, UK subsidiary) Lorenz ransomware claimed attack on UK subsidiary. Stolen files published on Lorenz leak site (labeled "Paid"). Confirmed compromise. Prior Snatch ransomware at French subsidiary (Nexeya, 2019). Dec 2021–2022 Undisclosed BleepingComputer, Dec 2021; Security Affairs
L3Harris Technologies $62M FCA settlement (pre-merger with Harris) for inaccurate cost/pricing data on communications equipment contracts. Cyber-adjacent FCA climate. FCA FY2025 $62M DOJ FY2025 FCA Fact Sheet, Jan 2026
Aerojet Rocketdyne (breach context) Reuters: company concealed nation-state breach from Pentagon while representing it was secure. Internal ethics reports ignored. Qui tam filed 2015. Breach 2013–2014 $9M FCA + ongoing monitoring Reuters; Thyberglaw client alert

All settlements are FCA civil fraud actions. "No admission of wrongdoing" in all cases — but the money was real and the reputational damage was real.

The largest defense corridor
in the United States

Prime Contractors in Texas

Company Location Key Programs TX Workforce
Lockheed Martin Aeronautics Fort Worth F-35 Lightning II final assembly; F-16; classified programs ~17,000
Bell Textron Amarillo / Fort Worth V-280 Valor tiltrotor (Army FLRAA); Bell 412; FTUAS ~9,500
L3Harris Technologies Greenville ISR/aerospace comms; EW; classified C4ISR ~4,000
BAE Systems P&S Austin, San Antonio Armored vehicles; combat vehicles; Fort Bliss/Cavazos sustainment Major (4 sites)
Raytheon Missiles & Defense McKinney AIM-120 AMRAAM; Patriot PAC-3; Precision fires; SM-6 ~1,800
Peterson Manufacturing Waco Tactical vehicle lighting; DFARS-subjected manufacturer ~1,000
General Dynamics OTS Austin, Marion Ammunition; small arms; training systems TX ops
Boeing Defense, Space & Security Houston Space systems; missile defense; Phantom Works TX ops

Texas Military Installations and Contractor Ecosystem

Installation Location Key Mission Contractor Concentration
Joint Base San Antonio (JBSA) San Antonio Medical training; Air Force basic training; pilot training Highest in TX; BAE, Booz Allen, CACI, SAIC, SDVOSBs
Fort Cavazos (formerly Fort Hood) Killeen/Copperas Cove III Corps / largest armored division in Army Vehicle sustainment, logistics, IT contractors
Fort Bliss El Paso Army air defense; large-scale training; 1st Armored Division Vehicle sustainment, electronics, comms contractors
NAS Fort Worth JRB Fort Worth F-35 training and logistics Lockheed Martin prime; small subcontractors
NAS Corpus Christi Corpus Christi T-6 training aircraft; Coast Guard helicopter training Small subcontractors for naval aviation
Dyess AFB Abilene B-1 bomber mission Contractor support for bomber sustainment

Gartner/DoD research estimated 60–70% of DoD contractors were NIST 800-171 non-compliant as of 2021. DFARS 252.204-7012 has applied to Texas defense contractors since December 2017 — over 8 years of required compliance. Lockheed Martin Fort Worth has been checking SPRS scores in subcontract solicitations since 2024.

Four groups with active
TX DIB campaigns

APT41 CRITICAL
China / PRC — People's Liberation Army contractors

Dual-mandate: cyber espionage for Beijing + financially motivated operations for personal gain. Targets defense contractors to steal source code, F-35/V-280/ISR program data, and weapons system specifications under "Made in China 2025." CISA AA20-275A specifically names DIB as an APT41 target.

CVE-2023-4966 (Citrix Bleed) Zoho ManageEngine ShadowPad malware CCleaner supply chain Credential theft

★ CISA: DIB is primary target. TX aerospace manufacturers handling F-35/V-280/ISR data are high-priority.

CoreRecon says: APT41's dual-mandate means financially motivated AND state-directed — same resources as a nation-state, but they also profit from selling your IP to multiple buyers. Treat every alert as potentially APT41 until proven otherwise.
Volt Typhoon CRITICAL
China / PRC — State-sponsored, pre-positioning for destructive ops

Distinct from espionage: pre-positioning persistent access inside U.S. critical infrastructure — comms, energy, transportation, water — to enable disruptive or destructive cyberattacks during a future Taiwan crisis. FBI Director Wray: "the defining threat of our generation." CISA Director Easterly: "the real-world threat the Chinese government poses to our critical infrastructure."

Living-off-the-land (LOTL) PowerShell / WMI SOHO routers / VPN NTDS.dit extraction OT/ICS targeting

★ CISA AA24-038A: Volt Typhoon specifically named Texas — targeting military strategic locations, power grids, water systems, comms.

CoreRecon says: Volt Typhoon is not stealing data — they're establishing a war footing inside your network. Even if you have nothing to steal today, a Volt Typhoon foothold means they can disrupt your operations when China decides the time is right. Hunt for LOTL techniques now.
Lazarus Group HIGH
DPRK — Reconnaissance General Bureau (RGB)

DPRK's cybersecurity unit: funds nuclear and ballistic missile programs. Linked to 2014 Sony Pictures attack, 2017 WannaCry global outbreak (~$8B in damages), 2022 Ronin bridge hack ($625M crypto). CISA advisory AA22-108A documents Hidden Cobra targeting defense contractors via browser exploitation and weaponized LinkedIn job offer lures.

M&A supply chain infiltration Browser exploitation Weaponized documents LinkedIn job offer lures AppleWorm / HardyBall

★ CISA: Defense contractors considering M&A are specifically targeted by Lazarus. Vet acquisition targets' cybersecurity posture as carefully as their financial posture.

CoreRecon says: If your company is considering acquisitions or M&A in the defense sector, Lazarus is specifically looking for those vulnerabilities. The Ronin bridge hack proved they'll go after anything that funds the regime.
LockBit HIGH
Russian RaaS — Most active ransomware group targeting U.S. orgs

Ransomware-as-a-service. Despite Operation Cronos takedown (Feb 2024) and LockBit's own internal data leaked (April 2025), the ecosystem is resilient — successor group SuperBlack uses LockBit Black as foundation. Extorted ~$91M from 1,700+ U.S. organizations since 2020. Boeing case: $200M ransom demanded and refused; 43GB of engineering specs, supplier data, internal comms published.

RaaS (core + affiliates) Compromised credentials Public-facing service exploitation VMware ESXi / Veeam Backup/systemdisable

★ CISA: LockBit is the most active RaaS operation targeting U.S. organizations. Defense contractors handling ITAR/CUI are among the highest-value targets.

CoreRecon says: Boeing — one of the largest corporate cybersecurity budgets in the world — was successfully exploited and had 43GB published. This is not a failure of Boeing's security team. It's a demonstration of how sophisticated LockBit affiliates have become. ITAR-controlled technical data or CUI makes you a priority target.

Phase 2 is not optional.
The hard deadline is November 10, 2026.

Phase 1
Nov 10, 2025 – Nov 9, 2026
Level 1 self-assessment and Level 2 self-assessment required at award; C3PAO Level 2 in some high-priority contracts.
Self-assessment only for most contracts. Primes already checking SPRS scores in subcontract solicitations. Start your gap assessment now.
Phase 2 — HARD DEADLINE
Nov 10, 2026 – Nov 9, 2027
Level 2 C3PAO assessment becomes a condition of award. No cert = no award.
This is not self-assessment. A C3PAO must validate every one of your 110 controls. With 80,000+ organizations needing Level 2 and ~80 C3PAOs, the queue is already forming.
Phase 3
Nov 10, 2027 – Nov 9, 2028
Level 2 C3PAO required at option exercise; Level 3 DIBCAC assessments begin.
Option exercises now require valid CMMC Level 2 certification. Level 3 requires government-led DIBCAC assessment. Plan for Level 3 if your contracts warrant it.
Phase 4
After Nov 9, 2028
Full CMMC implementation for all DoD contracts.
All contracts, all levels, full enforcement. By this point, CMMC Level 2 compliance is table stakes for any DoD work — not a competitive advantage, a baseline requirement.

SPRS Score Breakdown — 14 Control Families, 110 Controls

Control Family Controls Point Impact if Unimplemented Realistic Score Impact
Access Control (AC)22−2 to −5 per control−15 to −25 pts
Audit and Accountability (AU)9−3 to −5 per control−8 to −12 pts
Configuration Management (CM)9−3 per control−8 to −15 pts
Identification and Authentication (IA)11−3 per control−10 to −18 pts
Incident Response (IR)3−3 to −5 per control−3 to −9 pts
Media Protection (MP)9−3 per control−6 to −12 pts
Personnel Security (PS)2−1 per control−1 to −2 pts
Physical Protection (PE)6−1 to −3 per control−3 to −6 pts
Risk Assessment (RA)3−3 per control−3 to −9 pts
Security Assessment (CA)4−3 per control−3 to −6 pts
System and Communications Protection (SC)16−3 to −5 per control−10 to −20 pts
System and Information Integrity (SI)7−3 per control−6 to −12 pts
Awareness and Training (AT)3−1 to −3 per control−2 to −5 pts
Maintenance (MA)6−1 to −3 per control−3 to −6 pts
Realistic Texas defense manufacturer score110Realistic score: 60–85 (significant compliance gap)

A score of 60–85 is not unusual for a Texas defense manufacturer with active NIST 800-171 work underway. The gap between a score of 85 and 110 is the difference between a conditional certification (revocable within 180 days of C3PAO assessment) and a final certification that protects your contract eligibility for 3 years.

The math is simple.
The stakes are not.

Cost Category Amount Source
Average cost of a data breach — industrial sector (global) $5.00M IBM Cost of a Data Breach Report 2025 (604 orgs, 17 industries)
Average cost of a data breach — U.S. organizations (all sectors) $10.22M IBM Cost of a Data Breach Report 2025 (record high, +9% YoY)
Average cost of a data breach — financial services $5.56M IBM Cost of a Data Breach Report 2025
DIB-specific breach cost range (medium contractor) $5M–$15M+ IBM industrial benchmark + DIB regulatory/legal costs
Breach lifecycle — global average 241 days IBM Cost of a Data Breach Report 2025
Supply chain / third-party breach cost $4.91M IBM Cost of a Data Breach Report 2025
Ransomware attack cost — industrial sector $4.76M Sophos State of Ransomware Report 2024
DoD contract loss — no CMMC L2 cert 100% 32 CFR Part 170 / 48 CFR DFARS rule (condition of award)
C3PAO assessment cost — mid-size contractor $20K–$100K+ Industry benchmarks; C3PAO market pricing
SPRS fraud — FCA penalty per claim $28,619 31 U.S.C. § 3729 (2025 adjusted) + treble damages
Aerojet Rocketdyne FCA settlement $9M DOJ, July 2022
Penn State FCA settlement $1.25M DOJ, October 2024
Raytheon/Nightwing FCA settlement $8.4M DOJ, May 2025
MORSECORP FCA settlement $4.6M DOJ, March 2025
Georgia Tech FCA settlement $875K DOJ, September 2025

If a Texas defense contractor earns $5M/year from DoD contracts, losing those contracts due to CMMC non-compliance costs $5M annually — compounding. The cost of achieving CMMC Level 2 compliance with a managed security provider is a fraction of one year's lost contract revenue.

Three tiers. One path
to CMMC Level 2.

Feature Sentinel Fortress Recommended Command
Price $89/endpoint/month $2,500+/month
Best for Subcontractors, small manufacturers, Level 1 self-assessment only Defense primes, large manufacturers, full DFARS/NIST compliance, co-managed SOC
CMMC Level Level 1 readiness (17 controls) CMMC Level 2 + Level 3 preparation
Endpoint protection ✓ EDR, AV, patch mgmt ✓ Full EDR, network, OT security, SIEM
24/7 SOC Business hours monitoring Dedicated or co-managed SOC
SPRS score assessment Basic score calculation Full SPRS + DIBCAC pre-assessment
CMMC documentation SSP template, basic POA&M Complete CMMC evidence package
C3PAO readiness Pre-assessment preparation Full C3PAO assessment support
Incident response Tier 1 triage, escalation path Full IR retainer, forensics
DFARS 252.204-7012 coverage Basic Full compliance + DCMA audit support
SDVOSB flow-through Basic Subcontract structure optimization
TX SB 2610 safe harbor ✓ Included ✓ Included

Questions defense contractors
actually ask.

Phase 2 enforcement begins November 10, 2026. C3PAO third-party assessments become a condition of award for applicable contracts. No valid CMMC Level 2 certification means no award — this is not self-assessment. 32 CFR Part 170 (effective December 16, 2024) and 48 CFR acquisition rule (effective November 10, 2025) work together to make this contractually binding. Phase 1 (Nov 2025–Nov 2026) allows self-assessment for most contracts. Phase 2 closes that loophole.
DOJ's Civil Cyber-Fraud Initiative has produced over $26M in settlements specifically from cybersecurity compliance fraud in the DIB — Aerojet Rocketdyne ($9M, 2022), Penn State ($1.25M, 2024), Raytheon/Nightwing ($8.4M, 2025), MORSECORP ($4.6M, 2025), Georgia Tech ($875K, 2025). FCA penalties are up to $28,619 per false claim plus treble damages. A senior official who signs an inaccurate SPRS affirmation faces personal FCA exposure. Every settlement has involved a whistleblower.
CoreRecon is an SDVOSB. FAR 19.14 and DFARS 252.219-7012 require defense primes to meet small-business subcontracting goals (typically 20–25% of total subcontract dollars). Awarding a subcontract to an SDVOSB counts toward that goal. Primes with Fort Worth F-35, Bell V-280, or McKinney Raytheon contracts can flow cybersecurity subcontract awards through CoreRecon to meet their SDVOSB set-aside goals — while getting CMMC Level 2 compliance. No other Texas MSSP has this certification.
Four primary actors: APT41 (China, dual espionage/financial mission, targets defense IP for Made in China 2025), Volt Typhoon (China, pre-positioning for destructive operations in conflict, specifically named Texas in CISA advisory AA24-038A), Lazarus Group (DPRK, M&A supply chain infiltration, funds nuclear/missile programs), LockBit (Russian RaaS, most active extortion group targeting U.S. orgs, extorted ~$91M from 1,700+ U.S. organizations). Boeing's $200M LockBit ransom demand and 43GB data publication demonstrates the stakes.
A realistic score for a Texas defense manufacturer actively working on NIST 800-171 is 60–85 out of 110. The gap between 85 and 110 is the difference between conditional certification (revocable within 180 days of C3PAO assessment) and final certification (3-year validity). A score below 60 indicates significant gaps and high-risk SPRS submission. SPRS scoring: start at 110, deduct 1, 3, or 5 points per unimplemented control. 14 control families, 110 total controls.
IBM Cost of a Data Breach Report 2025: industrial sector average $5M globally, U.S. organizations average $10.22M (record high, +9% YoY). Supply chain/third-party breaches average $4.91M. Ransomware attacks in industrial sector average $4.76M total cost. For a DIB contractor, add regulatory and legal costs: DCMA audit findings, DFARS corrective action, FCA penalties ($28,619 per false claim + treble damages), and contract loss — 100% of new DoD awards requiring CMMC Level 2. The cost of achieving compliance is a fraction of one year's lost contract revenue.

Know your SPRS score before DoD asks.

Every day you delay is another day your competitors who have their score locked in are ahead. CoreRecon's SPRS Calculator gives you the accurate 110-control gap assessment — not a marketing estimate.

Free assessment · No obligation · Veteran-led team that speaks DoD · SDVOSB certified

Primary Sources

  1. DOJ Press Release 22-726: "Aerojet Rocketdyne Agrees to Pay $9 Million to Resolve False Claims Act Allegations" (July 8, 2022). E.D. California.
  2. DOJ Settlement Agreement: Penn State / U.S. ex rel. Decker v. Pennsylvania State University (E.D. Pa., Oct 22, 2024). $1.25M.
  3. DOJ Civil Division Press Release (March 26, 2025): "MORSECORP Inc. Agrees to Pay $4.6 Million to Settle Cybersecurity Fraud." D. Massachusetts.
  4. DOJ Civil Division Press Release (May 1, 2025): "Raytheon Companies and Nightwing Group Pay $8.4M." D. Massachusetts.
  5. DOJ Civil Division Press Release (Sept 30, 2025): "Georgia Tech Research Corporation Agrees to Pay $875,000." N.D. Georgia.
  6. DOJ FY2025 False Claims Act Fact Sheet (January 2026).
  7. DOJ Indictment: United States v. Dmitry Yuryevich Khoroshev (LockBit administrator).
  8. DOJ Civil Cyber-Fraud Initiative announcement (October 6, 2021). Deputy AG Lisa Monaco.
  9. CISA AA23-144A: "PRC State-Sponsored Cyber Actors Live Off the Land To Evade Detection." CISA, NSA, FBI, May 2023.
  10. CISA AA24-038A: "PRC State-Sponsored Actors Compromise and Maintain Persistent Access to U.S. Critical Infrastructure." CISA, NSA, FBI, Feb 2024.
  11. CISA AA20-275A: "Chinese State-Sponsored Cyber Operations." NSA/CISA/FBI, October 2020.
  12. IBM Cost of a Data Breach Report 2025. Ponemon Institute. 604 organizations, 17 industries, March 2024–February 2025.
  13. 32 CFR Part 170: CMMC Program Rule (effective December 16, 2024).
  14. 48 CFR Parts 204, 212, 217, 252: DFARS acquisition rule (effective November 10, 2025).
  15. NIST SP 800-171 Rev 2: "Protecting Controlled Unclassified Information in Nonfederal Systems." February 2020.
  16. FAR 19.14: Small Business Subcontracting Program.
  17. DFARS 252.219-7012: Small Business Subcontracting Plan Requirements.
  18. Cloudskope: "Boeing LockBit 2023." cloudskope.com/breaches/boeing-lockbit-2023.
  19. BleepingComputer: "Defense contractor Hensoldt confirms Lorenz ransomware attack" (December 2021).
  20. Forescout: "SuperBlack Ransomware Uses LockBit Black as Foundation" (March 2025).
  21. Mandiant: "APT41: China's Dual-Purpose Cyber Powerhouse" (Google Cloud Threat Intelligence, 2024).
  22. DOJ: "Seven International Cyber Defendants, Including APT41 Actors" (September 2020).
  23. FBI Director Wray Congressional Testimony: "China's Hackers Positioning on American Infrastructure" (House Select Committee, 2024).
  24. SEC Form 8-K: Boeing Cybersecurity Incident Disclosure (November 2023).
★ SDVOSB Certified
NIST 800-171 Aligned
CMMC Phase 2 Ready
24/7 SOC Coverage
Texas-Based Team
FAR 19.14 / DFARS 252.219-7012 Flow-Through Capable