
Illumina Inc., a major biotechnology firm based in San Diego, has agreed to pay $9.8 million to settle allegations brought by the U.S. Department of Justice that it sold genomic sequencing systems to federal agencies despite known cybersecurity vulnerabilities.
The DOJ accused Illumina of failing to implement adequate cybersecurity measures in its products between 2016 and 2023. According to the government, the company knowingly delivered systems containing software flaws, neglected to properly monitor its products for security issues, and misrepresented compliance with federal cybersecurity standards.
The allegations were pursued under the False Claims Act, which enables the government to seek damages from contractors accused of defrauding federal programs. The case was initiated by a whistleblower who had served as a senior executive at Illumina, and is part of a broader trend of DOJ actions targeting cybersecurity lapses among government vendors.
A Justice Department news release stated that Illumina failed to incorporate cybersecurity into the design, development, installation, and post-market surveillance of its software. It also claimed that the company underfunded teams responsible for product security and falsely certified compliance with national cybersecurity benchmarks.
Despite denying the allegations, Illumina agreed to the settlement to avoid the prolonged costs and uncertainties of litigation. In a statement, the company emphasized that the concerns involved software issues that were addressed and resolved for customers between 2022 and 2024. Illumina also said it has made significant investments to improve its cybersecurity practices.
“Companies that sell products to the federal government will be held accountable for failing to adhere to cybersecurity standards and protecting against cybersecurity risks,” said Assistant Attorney General Brett A. Shumate of the DOJ’s Civil Division. He added that the case highlights the importance of safeguarding genetic data and the government’s commitment to holding contractors to strict cybersecurity requirements.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543