F5 confirmed that a nation-state threat actor gained persistent access to its internal systems, resulting in the theft of BIG-IP source code, customer configuration data, and information on 44 vulnerabilities. The company stated that only a small number of customers were affected, all of whom have since applied emergency updates, and emphasized that the stolen data was not sensitive and that customer operations experienced minimal disruption. F5 has responded by expanding its bug bounty program and partnering with CrowdStrike to enhance endpoint detection and response (EDR) capabilities for BIG-IP systems, while external cybersecurity firms IOActive and NCC Group found no critical flaws in the stolen code.
Despite F5's assurances that the incident is contained and the impact is limited, some independent researchers have raised concerns about the company's transparency and the true extent of operational control and reputational damage. The breach, discovered in August and disclosed in October, also triggered a federal emergency directive. F5 maintains that the incident has not significantly affected its business outlook, projecting up to 4% revenue growth in fiscal 2026, but scrutiny continues regarding the adequacy of its response and communication with stakeholders.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Following the breach, F5 said it expanded its bug bounty program and partnered with CrowdStrike to add endpoint detection and response capabilities to BIG-IP systems. These steps were presented as part of its post-incident security improvements.
The incident prompted a federal emergency directive, indicating government concern over the potential downstream risk from the compromise. The reference does not specify the issuing agency or exact date.
In October 2025, F5 confirmed that a nation-state cyberattack had compromised its systems but said the impact was limited and affected only a small number of customers. CEO François Locoh-Donou stated the stolen data was not sensitive and customer operations saw minimal disruption.
After detecting the breach, F5 said it contained the incident by deploying emergency updates and launching recovery efforts. IOActive and NCC Group assisted the response, while F5 continued scanning for additional issues.
F5 said it discovered in August 2025 that a nation-state attacker had obtained persistent access to its environment. The intrusion led to theft of BIG-IP source code, customer configuration data, and information related to 44 vulnerabilities.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
reporter.deepspecter.com
Open sourcedeepspecter.medium.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.