Government

Gene Sequencing Giant Illumina Settles for $9.8M Over Product Vulnerabilities

Illumina will pay $9.8 million to settle accusations that products provided to the US government were affected by cybersecurity flaws.

Illumina will pay $9.8 million to settle accusations that products provided to the US government were affected by cybersecurity flaws.

Gene sequencing giant Illumina has agreed to pay $9.8 million to settle accusations that products provided to the US government were affected by cybersecurity vulnerabilities, the Justice Department announced last week.

Illumina has been accused that between 2016 and 2023 it sold to federal agencies genomic sequencing systems that were affected by vulnerabilities. 

The company allegedly also lacked a proper security program and the means to identify and address such vulnerabilities.

The government said Illumina failed to incorporate cybersecurity into the lifecycle of its products, failed to allocate sufficient resources to product security, failed to patch design features introducing vulnerabilities, and falsely claimed that its software adhered to cybersecurity standards.

The cybersecurity agency CISA issued an advisory to notify organizations about vulnerabilities in Illumina products, specifically the Local Run Manager, in 2022. The agency warned at the time that the flaws could be exploited by a remote, unauthenticated attacker to take over the product.

In 2023, both CISA and the FDA issued notifications over vulnerabilities in the Universal Copy Service (UCS) component used by several of Illumina’s genetic sequencing instruments, warning that the security holes could allow remote hacking.

Advertisement. Scroll to continue reading.

The $9.8 million settlement resolves a lawsuit filed under the whistleblower provisions of the False Claims Act by a former Illumina employee, who will receive $1.9 million of the amount. 

SecurityWeek has reached out to the company for comment and will update this article if it responds.

Related: Settlement Reached in Investors’ Lawsuit Against Meta CEO Mark Zuckerberg and Other Company Leaders

Related: Raytheon, Nightwing to Pay $8.4 Million in Settlement Over Cybersecurity Failures

Related: Google Agrees to $1.3 Billion Settlement in Texas Privacy Lawsuits

Related Content

Privacy & Compliance

A settlement has been reached in the class action brought by investors against Meta over the Cambridge Analytica incident, but details have not been...

Privacy & Compliance

Google has agreed to a $1.375 billion settlement with Texas in lawsuits over location and private browsing tracking, and biometric data collection.

Compliance

The US government says defense contractor Raytheon and Nightwing agreed to pay $8.4 million to settle False Claims Act allegations.

Compliance

US defense contractor MORSE Corp has agreed to pay $4.6 million to settle allegations over its cybersecurity failures. 

Data Breaches

Infosys McCamish System has agreed to pay $17.5 million to settle six class action lawsuits filed over a 2023 data breach.

Compliance

US military health benefits program administrator HNFS to pay $11 million in settlement over its false claims of cybersecurity compliance.

Compliance

The Penn State university has agreed to pay $1.25 million to settle alleged failure to meet cybersecurity requirements for DoD and NASA contracts.

Compliance

AT&T has agreed to pay $13 million in a settlement with the FCC over a 2023 data breach at a third-party vendor’s cloud environment.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version