Insight

Unrelated Relators: DOJ Launches FOCUS Initiative as Data-Driven FCA Filings Surge

Client Alerts

Traditionally, a Department of Justice (“DOJ” or the “Department”) False Claims Act (“FCA”) investigation starts with someone with inside knowledge within a company, perhaps a disgruntled former employee, an internal tip, and a qui tam complaint put together by a plaintiff’s firm that has been working with the putative whistleblower for months. That still happens. But the source of fraud allegations is growing more complex and varied. Today, qui tam filings increasingly come from individuals and companies that comb through publicly available data looking for fraud, often without any firsthand knowledge of the target. Nearly half of all whistleblower complaints now come from these outsiders — and DOJ is seeking to cultivate them.

On April 30, 2026, DOJ announced the Fraud Oversight through Careful Use of Statistics (“FOCUS”) initiative. A formal effort led by the Civil Fraud Section within DOJ’s Civil Division, FOCUS aims to identify and prioritize the most effective data miners, meaning entities that analyze public government datasets for signs of fraud even though they have no insider access and often no prior contact with the target. Since 2024, data miners have accounted for more than 45 percent of all qui tam filings. In Fiscal Year 2025 (“FY 2025”) alone, DOJ received nearly 1,300 qui tam complaints, blowing past the previous record of 980 set in FY 2024. Data miners are on track to help break that record again in FY 2026. According to DOJ, it has already received more than 780 qui tam complaints in FY 2026 — a huge sum by any measure, especially considering DOJ’s statutory responsibility to investigate each such qui tam complaint for purposes of determining whether to intervene.

With FOCUS, DOJ is signaling that it wants to work more strategically with data miners, prioritizing the ones whose tools actually find fraud. Announcing the initiative, Assistant Attorney General Brett A. Shumate of the Department’s Civil Division said FOCUS “reflects our commitment to ensuring that the Civil Division is engaging with the strongest and most effective partners in the war against fraud.” The initiative also tells us something about how DOJ will evaluate new qui tam filings going forward.

More Complaints, But Not Necessarily Better Ones

The surge in qui tam filings has forced DOJ to be more selective and judicious given the Department’s necessarily limited resources to conduct investigations and litigation. Still, DOJ is frequently using data analytics to initiate FCA cases on its own, without relying on a relator. The Department pointed to pandemic-era Small Business Administration (“SBA”) loan cases as an example: of the roughly 840 settlements and judgments totaling more than $850 million involving such loans, over three-quarters came from DOJ-initiated matters, not qui tam complaints. DOJ has an advantage because it can access non-public information, such as data held by SBA and other agencies. But the bigger takeaway is this: More filings does not mean better filings. 

FOCUS outlines how DOJ will assess data-driven qui tam complaints to encourage participation by data miners that exhibit “rigor and diligence.” According to the Department, the best data miners combine strong predictive analytics with a real understanding of the relevant legal requirements. Their submissions could be said to have more in common with the ideal traditional insider-based whistleblower complaints from DOJ’s perspective.

DOJ’s FOCUS initiative also reminds would-be filers that fraud allegations are subject to a heightened pleading standard in federal court. Under Federal Rule of Civil Procedure 9(b), allegations must state the circumstances of the fraud with particularity. DOJ encourages data miners to consider alternative explanations for the conduct they flag, which strengthens inferences of knowledge and falsity and demonstrates that they understand program eligibility requirements and regulatory frameworks well enough to accurately describe alleged violations.

To encourage collaboration, DOJ invited both established and new data miners to meet with the Civil Fraud Section to discuss their methods and explain how their data signals reliably indicate fraud. Deputy Assistant Attorney General Brenna E. Jenny of the Commercial Litigation Branch of the Department’s Civil Division put it this way: “Participants should be prepared to explain what differentiates their approach, how they validate their findings, and why their methodology provides a reliable basis for identifying high‑quality, actionable False Claims Act matters.”

What This Means for Contractors

DOJ’s announcement makes official what contractors have known for a while as FCA enforcement efforts have increased: FCA exposure is no longer limited to traditional insiders. Public procurement databases and contract award records are broadly accessible, and even partially accessible government datasets, such as information about SBA loans or Centers for Medicare and Medicaid Services (CMS) claims data, can be leveraged by anyone with the analytical tools to process it. A relator need not be a direct insider to file a complaint — indirect or tangential access to information can be enough — and several areas of government contracting are particularly exposed.

Cybersecurity compliance for Department of Defense/War contracts is at the top of that list. In recent years, DOJ has settled numerous cases premised on alleged false statements involving NIST SP 800-171 security controls concerning government data. Contractor cybersecurity representations and Supplier Performance Risk System (SPRS) scores, while not publicly available, may still become relevant data points if disclosed through other channels. A sophisticated data miner, whether working as a consultant, prime contractor, subcontractor, or in another role adjacent to the target, who understands the regulatory framework could potentially identify discrepancies between a contractor’s certifications and other available indicators, even without working directly for the company in question. While a claim based solely upon such information may face challenges, any contractor handling controlled unclassified information (CUI) or performing defense work should be aware that its public certification history could become a data point in a future FCA analysis.

Small business certifications carry similar risks. Contractors who win work through SBA programs like 8(a), HUBZone, SDVOSB, or WOSB have publicly visible certifications and contract awards. An enterprising data miner could, in theory, compare a contractor’s certification status against contract values, employee counts, or affiliate relationships in public databases. Size standard violations and affiliation issues are common targets for FCA complaints, and the relevant data points are often just a few clicks away. Still, proving an FCA violation requires establishing that the company or individual acted with knowledge, which may include reckless disregard. Evidence of a company’s state of mind is often hard to locate, which could inhibit such suits.

Buy American Act and Trade Agreements Act compliance follows the same pattern. Country-of-origin requirements are enforced through certifications in contracts. While contracts are unlikely to be publicly available, data miners may seek to cross-reference customs data, supplier information, and, where possible, contract terms to allege that the contractor’s products do not actually meet domestic sourcing requirements.

The FOCUS pre-filing meeting process, in which data miners brief DOJ’s Civil Fraud Section on their methodologies and demonstrate how their data signals reliably indicate fraud, adds yet another wrinkle. If a data miner has already built credibility with DOJ, its approach may be familiar to the Department before any complaint is filed. That could help DOJ prioritize certain investigations over others and move more quickly to an intervention decision in cases with favored relators. Target companies, who are not served with the sealed complaint when filed and may not learn of its existence until a DOJ investigation is well underway, will need to be especially efficient in such cases to investigate the allegations under privilege and to identify potential defenses and strategies for resolution.

Still, not all complaints are created equal. As DOJ emphasized, Rule 9(b)’s pleading standard is demanding. A complaint built entirely on inferences from public data, without specific false claims, identified individuals, or concrete facts linking statistical patterns to actual fraudulent submissions, is still vulnerable to dismissal.

What Contractors Should Do Now

Start with compliance documentation. Good records that capture not just what decisions were made but why, and that show real-time engagement with regulatory requirements, directly address the knowledge element that data miners cannot get from the outside. But to be effective in rebutting fraud allegations, this documentation has to exist before a complaint is filed, not after.

Contractors should also do their own risk assessments by looking at publicly available data on their contracts, including contract prices and, to the extent available, subcontracting and compliance certifications. Compare these against industry peers. If something looks off internally, it might look off externally too. Internal reviews can help identify risks and, if issues come up, provide a basis for timely self-disclosure.

When a data-miner complaint is filed, as in other qui tam cases, DOJ’s intervention decision is the key moment. DOJ has acknowledged that data-miner qui tam complaints can fall short, and it says it wants to filter for quality. That gives defense counsel a framework for early engagement. Arguments that a complaint is analytically weak, legally underdeveloped, or based on a misunderstanding of the regulations are often strongest before DOJ invests significant resources in an investigation.

FOCUS confirms that data-driven FCA enforcement is here for the foreseeable future. It also shows that DOJ recognizes that the quality of data-miner complaints is uneven. Contractors who have not assessed the risks from their public data footprint, or who lack solid compliance documentation, may already have heightened FCA exposure. The good news for companies: There is still time to strengthen controls and reduce that risk. But the time to act is now.


This information is provided by Vinson & Elkins LLP for educational and informational purposes only and is not intended, nor should it be construed, as legal advice.

Discover our latest:

Insights

CLE Events

Sixth Annual Navigating the Annual Meeting and Reporting Season 

Join leading practitioners and industry voices for a timely discussion of the legal, regulatory, and governance developments shaping the next proxy season.

November 11, 2026

November 11, 2026 • 1-minute read

Navigating Series Background Decorative Image

Events

Jenny Speck to Speak at 18th Annual OPIS RFS, RINs & Biofuels Forum

Partner Jenny Speck will speak on the panel “Credit Where Credit is Due: Finalizing 45Z” at the 18th Annual OPIS …

October 13, 2026

October 13, 2026 • 1-minute read

Events

Alex Canizares to Speak at The Coalition for Common Sense in Government Procurement’s Compliance Training Conference

On October 7, Alex Canizares will be speaking on a panel titled “Compliance and the Civil False Claims Act” as …

October 7, 2026

October 7, 2026 • 1-minute read

Events

Peter Bergan to Moderate Panel at TMT Finance USA 2026

Partner Peter Bergan will moderate a panel at TMT Finance USA 2026 on October 6 titled “How is Datacenter Powered …

October 6, 2026

October 6, 2026 • 1-minute read

CLE Events

Texas Reincorporation 101: Recent Developments and Key Considerations for Boards

Join Vinson & Elkins and FTI Consulting for a webinar on the growing trend of companies reincorporating to Texas.

October 1, 2026

October 1, 2026 • 1-minute read

News & Achievements
V&E

Get in Touch

Thoughts or questions? Send us a note, and we’ll connect you with the right person.

The ESG GC: How Your Role as Chief Legal Officer is Integral To Your Company’s ESG Efforts Background Image