
Charlotte, United States: Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it failed to comply with cybersecurity requirements under a U.S. Department of Defense contract, the U.S. Department of Justice announced on September 1, 2026.
According to the DOJ, the allegations concern cybersecurity requirements that applied to a Honeywell aerospace business unit while it was operating as part of Honeywell International Inc. The government alleged that the company failed to meet required cybersecurity standards while performing work under a Department of Defense contract and nevertheless submitted claims for payment.
The alleged conduct took place between April 2020 and December 2023. The cybersecurity requirements at issue included provisions based on the National Institute of Standards and Technology’s Special Publication 800-171, which establishes security requirements for protecting controlled unclassified information in nonfederal systems and organizations.
The DOJ said the settlement resolves allegations that Honeywell was liable under the False Claims Act because of the alleged failure to comply with the cybersecurity requirements. The department’s announcement did not say that a cyberattack occurred as a result of the alleged deficiencies, nor did it state that government information was actually stolen or exfiltrated.
The matter originated from a whistleblower lawsuit filed by Rachel Tenney, a former Honeywell employee, under the provisions of the False Claims Act that allow private individuals to bring lawsuits on behalf of the government. The lawsuit is captioned United States on behalf of Rachel Tenney v. Honeywell International Inc., Civil Action No. 3:22-cv-129, in the U.S. District Court for the Western District of North Carolina.
Under the settlement, Tenney will receive $375,823. The False Claims Act allows private individuals, known as relators, to bring certain cases on behalf of the United States and potentially receive a share of the government’s recovery.
The case was investigated and resolved through a coordinated effort involving the Justice Department’s Civil Division, its Commercial Litigation Branch, the U.S. Attorney’s Office for the Western District of North Carolina and the Defense Criminal Investigative Service.
The DOJ said Assistant Attorney General Brett A. Shumate of the Civil Division emphasized that government contractors handling defense information are required to follow applicable cybersecurity standards. Shumate said the Justice Department would continue investigating potential violations of cybersecurity requirements to protect critical information.
Russ Ferguson, U.S. Attorney for the Western District of North Carolina, said cybersecurity requirements imposed on federal contractors are intended to protect government systems and prevent unauthorized access to government information. He said companies that obtain and profit from federal contracts have an obligation to protect sensitive government information.
The Honeywell case also involves an important corporate change that occurred after the period covered by the allegations. Honeywell Aerospace became a standalone public company on June 29, 2026. Before that date, the aerospace business operated as a segment of Honeywell International Inc., which was headquartered in Charlotte, North Carolina.
Honeywell Aerospace is now headquartered in Phoenix, Arizona, and provides aerospace products and solutions to government and commercial customers.
The allegations against Honeywell relate to conduct occurring before the aerospace business became an independent public company. The DOJ’s September 1 announcement therefore identifies the aerospace company as the entity agreeing to the settlement while explaining the corporate structure that existed during the period of the alleged conduct.
The alleged cybersecurity non-compliance began in April 2020 and continued through December 2023, according to the Justice Department. The whistleblower litigation was filed as a 2022 civil action, meaning the lawsuit was already pending before Honeywell Aerospace became a standalone company in June 2026.
The settlement announced in September 2026 brings the False Claims Act allegations to a resolution without a trial or judicial finding that Honeywell was liable for the alleged violations.
The DOJ specifically stated that the claims resolved by the settlement are allegations only and that there has been no determination of liability. Honeywell’s agreement to pay the settlement should therefore not be described as an admission of wrongdoing or as a finding that the company violated the law.
The $2.04 million resolution announced on September 1, 2026, therefore concerns alleged non-compliance with cybersecurity obligations under a Defense Department contract during the April 2020-December 2023 period, rather than a reported aircraft safety incident, aviation accident or confirmed cyberattack.



















