Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagethird-party-vendor-breachbreach-disclosure-notificationpersistence-method

F5 Breach Exposes BIG-IP Source Code and Undisclosed Vulnerabilities

Updated 2mo agoFirst seen Oct 15, 202541 sources

F5, a leading provider of application security and delivery technology, confirmed that it suffered a significant cybersecurity breach attributed to a highly sophisticated nation-state threat actor. The company first detected unauthorized access to its systems on August 9, 2025, and immediately initiated incident response protocols, including engaging external cybersecurity experts such as CrowdStrike and Mandiant. Investigations revealed that the attackers maintained long-term, persistent access to critical F5 environments, specifically the BIG-IP product development environment and the engineering knowledge management platform. During this period, the threat actors exfiltrated files containing portions of the BIG-IP source code and information about vulnerabilities that had not yet been publicly disclosed or patched. Additionally, some configuration and implementation information for a limited number of customers was also stolen, though F5 stated that affected customers would be notified directly. The breach did not impact F5’s software supply chain, as independent reviews found no evidence of malicious modifications to source code, build, or release pipelines. There was also no indication that the attackers accessed or tampered with the NGINX product line, Distributed Cloud Services, Silverline systems, or customer data in CRM, financial, or support case management systems. F5 emphasized that, as of the latest investigation, there is no evidence that the stolen vulnerability information has been used in active exploitation or that the private information has been publicly disclosed. The company’s containment measures, implemented promptly after discovery, have been effective, with no signs of further unauthorized activity since their deployment. The U.S. Department of Justice authorized F5 to delay public disclosure of the breach due to national security concerns, as permitted under SEC rules. The UK National Cyber Security Centre highlighted the risk that attackers could use the stolen source code to identify additional vulnerabilities and develop targeted exploits. F5’s flagship BIG-IP product is widely used by major enterprises, including 48 of the Fortune 50, raising concerns about the potential impact of the breach. The company continues to monitor for any signs of exploitation and is working closely with law enforcement and cybersecurity partners. F5 has reassured customers that the breach did not compromise the integrity of its software updates or supply chain. The incident underscores the ongoing threat posed by nation-state actors to critical technology providers and the importance of rapid detection and response to sophisticated intrusions.

Share:
F5 Breach Exposes BIG-IP Source Code and Undisclosed Vulnerabilities
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Oct 24, 20258mo ago

Researchers identify Brickstorm backdoor in the F5 intrusion

On October 24, 2025, reporting said researchers had identified the Brickstorm backdoor as part of the F5 attack chain. The malware reportedly enabled stealthy long-term access, encrypted outbound communications, proxying, and concealed exfiltration traffic.

Oct 18, 20258mo ago

Bloomberg reports hackers had been inside F5 since 2023

On October 18, 2025, Bloomberg reported that the attackers had been lurking in F5's systems since 2023, extending the understood dwell time of the compromise. This added a major escalation to the incident's scope and persistence.

Oct 16, 20258mo ago

Media reporting links the breach to China-aligned actors

By October 16, 2025, reporting said U.S. officials privately suspected a China-linked threat actor was responsible for the F5 intrusion. Subsequent analysis and media coverage associated the activity with UNC5221 and the broader Silk Typhoon ecosystem, though F5's public disclosure did not name an actor.

GreyNoise observes increased scanning for BIG-IP after disclosure

Threat intelligence reporting said internet scanning for BIG-IP devices spiked after F5's announcement, suggesting attackers and researchers were rapidly operationalizing the newly disclosed risk. The activity heightened concern that stolen code and vulnerability intelligence could soon be weaponized.

Researchers publish internet exposure estimates for BIG-IP devices

Following the disclosure, security researchers and vendors reported that hundreds of thousands of BIG-IP instances were exposed or identifiable on the internet, underscoring the scale of potential downstream risk. Counts reported in coverage ranged above 262,000 exposed systems and over 600,000 hosts behind exposed instances.

Oct 15, 20258mo ago

CERT-EU and Canada issue advisories on F5 vulnerabilities

Government cybersecurity bodies outside the U.S., including CERT-EU and Canada's cyber center, published alerts on October 15, 2025, warning organizations about the F5 incident and associated vulnerabilities. These advisories urged rapid patching and defensive review of affected deployments.

CISA orders federal agencies to mitigate F5 device risk

CISA issued Emergency Directive 26-01 on October 15, 2025, warning that the stolen source code and vulnerability information posed a significant threat to federal networks. The directive required agencies to identify exposed F5 devices, remove public management access where applicable, and apply mitigations on an accelerated timeline.

F5 releases security updates and hardening guidance

F5 published patches for multiple affected product lines and issued mitigation, hardening, and threat-hunting guidance. The company also rotated credentials and strengthened internal security controls in response to the breach.

F5 publicly discloses nation-state breach in SEC filing

On October 15, 2025, F5 disclosed that a highly sophisticated nation-state actor had breached its internal systems and maintained long-term access. The company said it had no evidence of software supply-chain tampering and no known active exploitation of the stolen undisclosed vulnerabilities at the time of disclosure.

Attackers exfiltrate BIG-IP source code and undisclosed vulnerability data

During the intrusion, the threat actor stole portions of BIG-IP source code, information on previously undisclosed BIG-IP vulnerabilities, and some configuration or implementation files affecting a small percentage of customers.

Aug 9, 202511mo ago

DOJ delays F5's public disclosure for national security reasons

After detecting the breach, F5 postponed public notification at the request of the U.S. Department of Justice. Multiple reports said the delay was tied to national security concerns.

F5 detects the intrusion in its internal environment

F5 identified the security incident on August 9, 2025, discovering a sophisticated nation-state compromise affecting internal systems tied to BIG-IP development and engineering knowledge resources.

Jan 1, 20233y ago

Nation-state hackers begin long-term intrusion into F5 systems

Attackers gained persistent access to F5's corporate network, including the BIG-IP development environment and an engineering knowledge management platform. Later reporting said the compromise may have begun as early as 2023 and remained undetected for an extended period.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

132 LINKEDOpen in app
Affected products
12 linked
Big-IpF5osSilverlineNginxNginxAdobe Experience ManagerWindows 10Visual Studio CodeFirefoxBig-Ip Next For KubernetesBig-IqAdaptive Security Appliance (Asa)
Organizations
74 linked
F5UNC5221ResecurityCISAGoogleCrowdStrikeU.S. Department of JusticeCisco SystemsNational Cyber Security CentrePalo Alto NetworksNCC GroupIOActiveBloombergTrend MicroMozillaPositive TechnologiesArctic WolfBarracuda NetworksSeqriteGreyNoiseBrickstormProsperThe Wall Street JournalBleepingComputerNebulockGladinetMangoBinanceElasticPowerschoolCapitaTeam Cymruncsc_hungaryAxiosFlashpointTenableWatchGuard TechnologiesSANS InstituteHeritage Provider NetworkSilk TyphoonBackblazeLastPassCloudflareCandiruKasperskyDatadogQianxinNSO GroupSolarWindsImmuniWebiVerifyFortinetVolt TyphoonPRC-linked actorReutersBroadcomSalt TyphoonMicrosoft CorporationAdobeWizWatchTowrCanadian Centre for Cyber SecuritysecWordfenceSonicwallFirst WapAdversisLocalMindVUSecHyperliquidRed Lion ControlsZorin GroupKyntraMuniOS
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.