Honeywell whistleblower gets $375,000 for flagging allegations with Charlotte ties
A defense contractor with deep ties to Charlotte has agreed to pay more than $2 million to settle allegations that it failed to comply with cybersecurity standards on a U.S. Department of Defense contract, federal authorities announced this week.
Read more Union County Public Schools ranks No. 1 for student proficiency in NC — again
At the time of the investigation, Honeywell Aerospace operated as a business segment of Charlotte-based Honeywell. The aerospace unit was spun off on June 29 as an independent public company that now is headquartered in Phoenix. Honeywell announced in 2025 that it would spin off three of its operations, including its aerospace tech business.
The settlement stems from a whistleblower lawsuit filed on behalf of the government by former Honeywell employee Rachel Tenney, who will receive $375,823 of the settlement proceeds, according to the Justice Department.
“The settlement does not include any admission of wrongdoing,” Honeywell Aerospace said Wednesday in a statement to The Charlotte Observer. Because the allegations were against the Honeywell aerospace business unit before the spinoff, “it was in the best interest of Honeywell Aerospace to resolve this matter without further litigation,” the two-month-old company said.
Honeywell Aerospace said it complies with all applicable cybersecurity requirements and laws, and its contractual and regulatory obligations.
The aerospace unit submitted claims for payment from April 2020 through December 2023 despite failing to implement required cybersecurity protocols on one of its networks, according to the Department of Defense. The payment amount for the company’s claims was not specified in the complaint filed by Tenney on behalf of the government.
However, the complaint said the Department of Defense and civilian federal agencies awarded Honeywell “tens of millions of dollars in contracts” in services related to the company’s use of quantum computers to research and develop new technologies to strengthen national security, including intelligence and law enforcement.
“The importance of this technology in counterintelligence (resilience to spying) cannot be overstated,” the complaint stated.
Tenney, who worked as a senior IT project management specialist for Honeywell from 2019 to August 2021, repeatedly raised concerns with management following the massive 2020 SolarWinds cyberattack. SolarWinds, a Texas-based management software company, is widely used in the federal government to monitor network activity on federal systems, according to the U.S. Government Accountability Office.
Tenney warned that Honeywell had not taken necessary precautions to protect its systems, according to court documents.
Instead of addressing her warnings, Tenney was reprimanded and subjected to “hostile and threatening treatment” before being escorted out of the company’s Minnesota office in August 2021, her complaint alleged.
The unsealed, redacted complaint filed in March 2022 painted a stark picture of Honeywell Aerospace’s network security.
Read more Grand jury indicts man who filmed himself assaulting woman in Dilworth
It alleged that Honeywell promised to “wall off” sensitive government secrets from external threats but failed to implement even basic cybersecurity safeguards.
Because Honeywell also failed to report cyber incidents, the complaint alleged that sensitive national security data became “easy pickings for even beginner hackers.” Scientists reportedly shared development data for advanced technologies on a system known as the “Gray Network.”
The complaint further alleged that Honeywell prioritized commercial growth over national security obligations.
“Government business played second fiddle to Honeywell’s ambitions to grow its quantum computing commercial business, so when the SolarWinds attack occurred in early 2020, the Gray Network was a sitting duck for attackers,” the complaint stated.
Russian government-affiliated hackers who breached SolarWinds implanted malware that allowed them to access, steal, alter and delete customer data. The breach affected as many as 18,000 customers, including Fortune 500 companies, federal agencies and defense contractors like Honeywell.
“Honeywell has placed in jeopardy our collective national security and the victims of this fraud are ordinary Americans, including taxpayers,” the complaint stated, adding that the company knowingly submitted false claims for payment while putting national security at risk.
Federal officials emphasized the responsibility defense contractors hold in securing sensitive information.
“Government contractors that obtain defense information in administering their contracts must follow required cybersecurity standards,” Brett Shumate, Assistant Attorney General for the Justice Department’s Civil Division, said in a statement.
Russ Ferguson, the U.S. Attorney for the Western District of North Carolina, echoed that sentiment. “Companies that seek and profit off of government contracts have an obligation to ensure sensitive data is protected,” Ferguson said.
The investigation was a joint effort by the Civil Division’s Commercial Litigation Branch, the Defense Criminal Investigative Service and the U.S. Attorney’s Office for the Western District of North Carolina.
At the time the complaint was filed, Honeywell employed over 100,000 people and provided quantum computing-related contracted services to the Department of Defense.
Read more Historic Charlotte building demolished in a day, clears path for data center