News: 1765545909

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Uncle Sam sues ex-Accenture manager over Army cloud security claims

(2025/12/12)


The US is suing a former senior manager at Accenture for allegedly misleading the government about the security of an Army cloud platform.

Danielle Hillmer, 53, of Chantilly, Virginia, is accused of deceiving auditors over the capabilities of a service the government commissioned in 2017.

Although it is only referred to as Company A in the court documents, Hillmer claimed to work for Big Four consulting firm Accenture during the stated timeline, according to a now-deleted LinkedIn account.

[1]

The US alleges that between March 2020 and November 2021, Hillmer obstructed federal auditors and falsely represented the security of the company's cloud platform, which was used by other government customers beyond the [2]Army .

[3]

[4]

The platform in question is described as Nonappropriated Fund Integrated Financial Management System (NIFMS) – a cloud-based payroll, pension, and benefits system in lay terms.

According to the [5]indictment [PDF] unsealed this week, Hillmer specifically made efforts to represent the NIFMS platform as having enabled security controls that met the FedRAMP High baseline, and the Department of Defense's (DoD) Impact Levels 4 and 5.

[6]

The Federal Risk and Authorization Management Program ( [7]FedRAMP ) standardizes security assessments, and systems must have a "high" baseline to store federal information.

The DoD has its own risk management framework with Impact Levels 4 and 5 representing the highest levels of security. IL4 requires systems to meet different criteria, ranging from FedRAMP Moderate, FedRAMP High, and DoD-specific controls, while IL5 is the highest level available for unclassified information.

Accenture's contract was worth around $30 million in total, the court documents showed, and required a DoD Impact Level 4 assessment in order to fulfill it.

[8]

Hillmer allegedly filed an application to the Joint Authorization Board responsible for administering FedRAMP to raise the platform's compliance level from Moderate to High. The US claimed Accenture would have used this to gain DoD IL5 accreditation.

This application allegedly contained various falsehoods and misleading statements about the platform's security.

"Among other things, Hillmer knew the platform had not implemented required security controls related to access control, [9]incident response , and continuous monitoring, including auditing, logging, monitoring, and alerting," the indictment reads.

"Hillmer also knew customer environments were not managed, monitored, governed, and secured as represented in the platform's system security plan."

Hillmer allegedly did this despite the numerous voices from inside the company, and those from outside cybersecurity consultants, informing her that the platform was not compliant with FedRAMP High requirements.

[10]US extradites Ukrainian woman accused of hacking meat processing plant for Russia

[11]Feds bust nefarious plot to ship Nvidia H200s to China and hurt US

[12]Fired techie admits sabotaging ex-employer, causing $862K in damage

[13]Selling your identity to North Korean IT scammers isn't a sustainable side hustle

According to a timeline of events outlined in the legal files, Hillmer filed the application on March 10, 2020, noting that the company required FedRAMP High due to the Army contracts it secured, and promised that the relevant controls would be implemented by April 2020, and operational by August.

In June 2020, an outside consultant told Hillmer that more than 100 security controls had not been implemented, and in various cases, a solution had not been identified.

She allegedly approved a Readiness Assessment Report in July, knowing the system was not compliant, and spent the following months hiding known issues from officials.

In September 2020, the US claims Hillmer explicitly stated that all FedRAMP High controls were in place and needed to secure the accreditation by January 1, 2021, due to the Army contract wins.

These misrepresentations continued into September 2021, the US claims, and at least six government departments planned to use the platform, which could have landed Accenture contract wins worth around $250 million.

An Accenture spokesperson told The Register : "As previously disclosed in our public filings, we proactively brought this matter to the government's attention following an internal review.

"We have cooperated extensively with the government's investigation and continue to do so. We remain dedicated to operating with the highest ethical standards as we serve all our clients, including the federal government."

It told the Securities and Exchange Commission (SEC) the same in a [14]Form 10-K [PDF] filed on October 12, 2023. It stated that the Justice Department had initiated civil and criminal proceedings against "one or more employees," and it was fully complying with its investigation. ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aTxKJ8naMCe6Qb6YOSlJ_wAAAUY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.theregister.com/2025/09/05/us_army_enlists_ai_startup/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTxKJ8naMCe6Qb6YOSlJ_wAAAUY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aTxKJ8naMCe6Qb6YOSlJ_wAAAUY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://storage.courtlistener.com/recap/gov.uscourts.dcd.287563/gov.uscourts.dcd.287563.1.0.pdf

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aTxKJ8naMCe6Qb6YOSlJ_wAAAUY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2025/08/11/fedramp_government_cloud_software_approvals/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aTxKJ8naMCe6Qb6YOSlJ_wAAAUY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2025/03/10/incident_response_advice/

[10] https://www.theregister.com/2025/12/10/pro_russia_hacktivist_charged/

[11] https://www.theregister.com/2025/12/09/feds_bust_nefarious_plot_to/

[12] https://www.theregister.com/2025/11/20/it_contractor_sabotage/

[13] https://www.theregister.com/2025/11/17/doj_north_korean_it_scam/

[14] https://www.accenture.com/content/dam/accenture/final/capabilities/corporate-functions/marketing-and-communications/marketing---communications/document/Accenture-2023-10-K.pdf

[15] https://whitepapers.theregister.com/



Ok, I'll bite

The Man Who Fell To Earth

What was her position that allowed her the ability to dig this grave?

Scapegoat?

IGotOut

Unless this person was very high up, there is zero chance top brass were unaware of what they were selling.

Re: Scapegoat?

Dinanziame

It's Accenture who reported the situation to the government "following an internal review." So either somebody reported her to the top brass and they threw her to the wolves, or the top brass knew all along and eventually decided it was too risky and threw her to the wolves.

Accenture

DarkwavePunk

I'm going to be vague for "reasons", but seeing Accenture in this pickle is not surprising. Allegedly. In my opinion.

"If you don't want your dog to have bad breath, do what I do: Pour a little
Lavoris in the toilet."
-- Comedian Jay Leno