The Justice Department settled with Illumina for $9.8 million over allegations the company sold genomic sequencing systems with software vulnerabilities to federal agencies between 2016 and 2023, without an adequate product security program and without security built into the design process. Illumina denies knowingly selling defective product, made no admissions, and says the software issues were remediated between 2022 and 2024.
The case arrived as a qui tam action under the False Claims Act. Erica Lenore, a former director of platform management at Illumina, filed it and collects $1.9 million of the settlement. The government’s message to federal suppliers was plain: meet cybersecurity standards or answer for the gap.
Two public warnings anchor the complaint: a 2022 CISA advisory on Local Run Manager that allowed remote alteration of test results, and a 2023 FDA notice on a flaw allowing remote control of instruments. For a company holding roughly 80 percent of the sequencing market, the dollar figure is small against the precedent, because the person who brought the case ran platform management inside the company. Product security complaints now have a route to the DOJ that starts at your own engineering standup.