frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Booz Allen Hamilton Conducts Fraud Against the Government

https://gemini.google.com/share/7a82ba613063
3•cochranblock•1h ago

Comments

NDlurker•51m ago
I'm not reading your months long chat with Gemini about how your coworkers are lazy and then you got yourself fired.

Update: I asked Gemini to summarize this for me, so here's the AI generated tl;Dr on an AI chat

Here is how your story translates into a classic, high-impact Hacker News post. It focuses on the systemic failure, the technical metrics, the forensic defense, and the programmatic solution—exactly what the HN community values.

---

### *Tell HN: I found massive ghost billing on a DoD cyber stack. They fired me. Here is the forensic playbook.*

*TL;DR:* I was working as a Senior Software Engineer for a subcontractor (MAXISIQ) under a major Defense Prime (Booz Allen Hamilton) on the Joint Cyber Warfighting Architecture (JCAP). I uncovered systemic Labor Category (LCAT) fraud and a suppressed CAT-1 security spillage. I disclosed it Sunday, surrendered my credentials Monday, and was fired Tuesday under a fabricated "security threat" pretext. Here is how I used hardware logs and federal reporting to trap their legal team, and how we can automate the detection of this fraud.

---

### *The Exploit: "Product Substitution" via LCAT Fraud*

The core issue is a classic defense contracting grift scaled up: billing the government for "Senior Software Engineers" who aren't actually doing senior-level work (or any work at all).

The forensic reality on the project's primary code repository (`JCW-Nile`) was undeniable:

* *My Velocity:* 250+ commits per month. * *The "Ghost" Seniors:* Multiple personnel billed at the exact same Senior rate, maintaining a footprint of *less than 2 commits annually*.

On top of the financial fraud, I found a *CAT-1 security spillage* (hardcoded credentials on a Tier-1 system). When I reported it, management ordered me to stop editing the code, leaving the vulnerability live in production.

### *The Retaliation and the "Deadman" Bluff*

On Sunday, I dropped a comprehensive disclosure to 1,000+ program stakeholders.

By Monday morning, the Prime pressured the Sub to "cauterize the leak." I was placed on indefinite leave and forced to surrender my Common Access Card (CAC) and government credentials. Knowing they were about to wipe my commit history to hide the 250 vs. <2 disparity, I made a tactical bluff under duress: I told them I had a VPS "deadman's trigger" monitoring the logs.

On Tuesday at 12:35 PM, the Subcontractor's CPO—with outside Big Law counsel (Troutman Pepper) CC'd—fired me, citing the "deadman's trigger" as an unauthorized security threat.

### *The Counter-Exploit: Using Immutable Logs against HR*

They thought the "threat" pretext would shield them from whistleblower retaliation laws (10 U.S.C. § 4712). They didn't realize they had trapped themselves in a forensic impossibility.

I immediately lawyered up (Qui Tam/False Claims Act) and filed with the DoD OIG, the SEC, and the FBI, laying out the physical trap:

1. *The Access Lockout:* I couldn't have posed a digital threat on Tuesday because they took my CAC on Monday. I was locked out of the "crime scene." 2. *The Hardware Time-Gap:* The company laptop they claimed I used for "unauthorized conduct" hadn't been powered on in 7 days. The CMOS and system logs act as a silent, immutable witness in my favor. 3. *The Preemption:* I instantly called the FBI to clarify the VPS bluff. The FBI agent dismissed the threat allegation entirely and confirmed they are now working the underlying fraud case.

I effectively robbed their corporate lawyers of their element of surprise by establishing the forensic baseline with federal agencies before the ink on my termination letter was dry.

### *The Blueprint: Project `whyyoulying*`

We don't need multi-year DCAA (Defense Contract Audit Agency) audits to catch this. We need a basic diffing script. I am proposing an automated forensic tool for federal investigators that I'm calling `whyyoulying`.

It works by cross-referencing financial billing data against technical repository metadata:

* *Ingest A:* DCAA/DCMA billing records (Employee Name, Billed LCAT, Hours Invoiced). * *Ingest B:* GitLab/Bitbucket commit metadata from government servers. * *The Heuristic:* If `Billed_Level == "Senior"` AND `Annual_Commits < 10`, automatically flag for False Claims Act investigation.

Furthermore, the tool can map HR termination timelines against protected disclosure dates to detect "rapid cauterization" cover-ups by Prime contractors.

---

*Takeaway:* If you are blowing the whistle in the cleared space, HR and Big Law will try to frame you as a security risk to void your protections. *Surrender your hardware early, document the offline time-gap, immediately clear any defensive bluffs with the FBI, and let the server logs do the talking.*

tencentshill•16m ago
Another victim of AI psychosis being created before our very eyes. Understand that LLMs will ALWAYS validate your theories and suspicions.

Will be interesting to see what actual lawyers think, and how much money they'll charge to read this wall of text.

When Quiet Undersea Volcanoes Turn Disruptive

https://www.quantamagazine.org/when-quiet-undersea-volcanoes-turn-disruptive-20260526/
1•speckx•1m ago•0 comments

Walmart shopper got $3 shoes, then paid 6 times the price at checkout

https://nypost.com/2026/05/26/lifestyle/angry-walmart-shopper-hit-with-dynamic-price-in-real-time/
1•canucker2016•1m ago•0 comments

Earth Has Approx. 1.1B Years Left. Here's the Math

https://www.thescientificdrop.com/
1•cosmicSap•1m ago•0 comments

Linux to Drop ARCnet Support for Old ISA and PCMCIA Hardware

https://www.phoronix.com/news/Linux-To-Drop-ARCnet-ISA-PCMCIA
2•Bender•3m ago•0 comments

New Parser Framework: Bablr

https://bablr.org/
2•conartist6•3m ago•0 comments

ML-KEM and X-Wing Patches Posted for Linux to Help with Post-Quantum Security

https://www.phoronix.com/news/Linux-PoC-ML-KEM-X-Wing
1•Bender•4m ago•0 comments

AlmaLinux 10.2 Released for Latest Community-Driven RHEL 10.2 Experience

https://www.phoronix.com/news/AlmaLinux-10.2-Released
1•Bender•4m ago•0 comments

Show HN: An LLM translator whose source is a single prompt

https://github.com/hamsterbase/llm-translator
3•Cassandra99•5m ago•0 comments

SetupHub – share and sync your VS Code / Cursor setup in one click

https://setuphub.dev
1•dev-kraken•6m ago•0 comments

Tailscale now supports iOS Exit Nodes [video]

https://www.youtube.com/watch?v=vrUuqey4Q-U
1•humanperhaps•7m ago•0 comments

Americans Have Entered the Age of the Needle

https://www.theatlantic.com/health/2026/05/injection-age/687293/
2•paulpauper•7m ago•0 comments

The Great Depopulation

https://www.theatlantic.com/ideas/2026/05/global-birthrate-decline/687297/
1•paulpauper•7m ago•0 comments

Huawei Tau (τ) Scaling Law

https://twitter.com/Huawei/status/2058758547673161902
1•madihaa•8m ago•0 comments

Show HN: Zt – Expose local services via Cloudflare Zero Trust in one command

2•casablanque•9m ago•0 comments

Show HN: I built a tool to record your workflow and generate docs in one click

https://main.mirror-landing-43t.pages.dev/
1•choonspin•9m ago•0 comments

HypeScribe – AI-powered transcription, summaries, and search for any audio/video

https://www.hypescribe.com
2•maksliashch•10m ago•0 comments

Index funds can't say no to SpaceX

https://www.bloomberg.com/opinion/newsletters/2026-05-26/index-funds-can-t-say-no-to-spacex
4•davidw•10m ago•0 comments

In China, Juncheng Vehicle Co Is Making New AE86

https://forum.retro-rides.org/thread/230565/china-juncheng-vehicle-brand-ae86?page=1
1•Paul_S•11m ago•0 comments

ChatGPT voice mode and zalgotext = nightmare fuel

https://wnmurphy.com/chatgpt-zalgotext-voice-mode-equals-nightmare-fuel/
1•wnmurphy•12m ago•1 comments

The Highest Break in Professional Snooker – Ronnie O'Sullivan – 153 [video]

https://www.youtube.com/watch?v=vM3QucWQygg
2•nomilk•13m ago•1 comments

Photos, scriptable folders, encrypted federation with friends, WebDAV, an S3 API

https://stohr.io
1•wesscope•13m ago•0 comments

SkillOpt – Executive Strategy for Self-Evolving Agent Skills

https://microsoft.github.io/SkillOpt/#idea
3•renarl•14m ago•0 comments

Carbon Nanotube CPU Cooling with Carbice Ice Pads

https://www.lttlabs.com/articles/2026/05/26/carbice-ice-pads
1•LabsLucas•14m ago•0 comments

Show HN: InterviewSignal – open-source AI-native technical interviews

https://github.com/NikhilSKashyap/interviewsignal
1•NikhilKashyap•15m ago•0 comments

Spotify boss defends move to AI music, saying it is better than 'slop'

https://www.theguardian.com/technology/2026/may/26/spotify-ai-remix-tool-protects-artists-slop
2•HelloMcFly•20m ago•2 comments

Building an AsyncIO executor for the 3DS (pt 1)

https://blog.cat-girl.gay/3ds-async-part-one/
1•g0xA52A2A•20m ago•0 comments

Why Google Accounts Should Be Treated as Critical Infrastructure

https://nickyreinert.de/en/2026/2026-05-26-digital-dilemma/
2•y42•21m ago•0 comments

Dials

https://artofpilgrim.github.io/Dials/
1•bpierre•22m ago•1 comments

Social media as bad for children as smoking, British doctors say

https://www.reuters.com/legal/litigation/social-media-bad-children-smoking-british-doctors-say-20...
3•1vuio0pswjnm7•23m ago•0 comments

Pavona: Open-Source Silicon Distribution

https://pavona.org/news/globalplatform-launches-pavona-the-first-open-silicon-distribution-with-p...
4•user142•23m ago•0 comments