July 03, 2026 | Posted By: Sean Estes
There is a comforting assumption many business owners make when they hear that a federal agency is scaling back: less government attention means less legal risk. Recent developments suggest the opposite may be true. As federal regulators step back from certain types of fraud enforcement, the risk has not disappeared. It has moved, often into the hands of private parties whose motivations and methods look nothing like those of a government agency. For businesses that contract with the government, import goods, or operate across borders, understanding who is now driving enforcement matters as much as understanding the rules themselves.
The Government Stepped Back, But the Risk Did Not
In May 2025, the Department of Justice issued a new white collar enforcement plan that reoriented its resources toward a narrower set of priorities, including fraud against government programs, money laundering tied to cartels, and trade and customs fraud. The DOJ later created a National Fraud Enforcement Division focused on government program fraud. You can read the DOJ’s own description of its priorities through its Criminal Division materials.
On paper, a more focused enforcement agenda might seem to reduce a company’s overall exposure. In practice, the areas the government deprioritizes do not simply go unenforced. Other actors move in. With the False Claims Act, those actors are private whistleblowers. With anti-bribery enforcement abroad, they are foreign prosecutors. Either way, your business can face scrutiny from someone other than the regulator you were watching.
How the False Claims Act Became a Private Enforcement Engine
The False Claims Act allows a private individual, called a relator, to file suit on behalf of the government against a company that has defrauded a federal program. These are known as qui tam cases. If the case succeeds, the whistleblower can collect between 15 and 30 percent of whatever the government recovers. That financial incentive is powerful, and it operates independently of whether any agency considers the underlying conduct a priority.
The numbers tell the story. The DOJ recovered a record 6.8 billion dollars under the False Claims Act in fiscal year 2025, the largest single-year total in the law’s history. More striking is where those recoveries came from. Whistleblowers filed a record 1,297 new qui tam actions, more than five every business day, and cases the government declined to join still accounted for more than a third of all recoveries. In other words, private parties are increasingly carrying these cases entirely on their own, all the way through trial. Two of the year’s largest verdicts, including a $1.6 billion judgment involving prescription drug claims, came from cases the government did not join. You can review the DOJ’s summary of these recoveries in its official press release.
For a company, this changes the calculus. You are no longer facing only a government investigator who weighs policy priorities and resource constraints. You may be facing a former employee, a competitor, or a data analyst who has reviewed publicly available records and stands to gain financially from your liability.
The New Risk Areas: Customs and Cybersecurity
Two areas illustrate where this exposure is growing fastest, and both fall outside the traditional healthcare and defense contracting cases that long dominated False Claims Act litigation.
The first is customs and tariff fraud. As trade rules have shifted repeatedly since 2025, private relators have moved aggressively into this space, often armed with publicly available import data. The DOJ has previewed a 54.4 million dollar customs fraud settlement, which it described as the largest of its kind under the statute. For any business that imports goods across changing tariff regimes, an inaccurate customs declaration is no longer just a regulatory concern. It is a potential whistleblower lawsuit.
The second is cybersecurity. Even as some regulators have pulled back from cybersecurity disclosure enforcement, the False Claims Act has filled the gap. Federal contractors that certify they meet cybersecurity requirements but fail to implement adequate controls face real exposure. The DOJ reported more than $ 52 million in cybersecurity fraud settlements across nine cases in a single year, a figure that more than tripled in each of the prior two years. Many of these cases began not with a regulator, but with an internal whistleblower. We have written before about the False Claims Act’s expanding role in cybersecurity enforcement, and the trend has only accelerated.
What This Means for Your Compliance Strategy
The old approach to compliance treated enforcement as something that flowed from the top down, from an agency with known priorities. That model no longer fully describes reality. A company can be in a sector where the relevant regulator has gone quiet and still face substantial liability, because the people who can bring a case against it are not regulators at all.
This has practical consequences for how businesses should think about risk. Certifications submitted to the government, whether regarding cybersecurity, pricing, customs classifications, or program eligibility, deserve careful attention, as each can serve as the basis for a whistleblower claim. Internal reporting channels matter too. Employees who feel ignored are often the ones who eventually file suit. And because anti-retaliation provisions protect employees who raise concerns, how a company responds to an internal complaint can create its own separate liability.
Proactive legal guidance is the most reliable protection. Reviewing your certifications, contracts, and compliance practices before a problem surfaces is far less costly than defending a lawsuit after one does. This is precisely the kind of work that ongoing business counsel is built to address, and it is a core part of what our business law practice provides to companies of every size.
Talk With Us
If your business contracts with the government, imports goods, or makes regulatory certifications of any kind, the shifting enforcement landscape is worth a serious conversation. The risk is not always where you expect it, and the people empowered to pursue it have every reason to look closely.
To discuss your situation in a confidential evaluation, contact Hoyer Law Group through our contact page or call us at (844) 531-0082. We help businesses understand their exposure and build practices that prevent costly litigation before it begins.
This blog is for general informational purposes only and does not constitute legal advice. For advice specific to your situation, please consult a qualified attorney.