Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagevendor-distribution-compromisebreach-disclosure-notificationthird-party-vendor-breach

F5 Breach Involving Nation-State Attackers and Theft of Source Code

Updated 3mo agoFirst seen Oct 29, 20253 sources

F5 confirmed that a nation-state threat actor gained persistent access to its internal systems, resulting in the theft of BIG-IP source code, customer configuration data, and information on 44 vulnerabilities. The company stated that only a small number of customers were affected, all of whom have since applied emergency updates, and emphasized that the stolen data was not sensitive and that customer operations experienced minimal disruption. F5 has responded by expanding its bug bounty program and partnering with CrowdStrike to enhance endpoint detection and response (EDR) capabilities for BIG-IP systems, while external cybersecurity firms IOActive and NCC Group found no critical flaws in the stolen code.

Despite F5's assurances that the incident is contained and the impact is limited, some independent researchers have raised concerns about the company's transparency and the true extent of operational control and reputational damage. The breach, discovered in August and disclosed in October, also triggered a federal emergency directive. F5 maintains that the incident has not significantly affected its business outlook, projecting up to 4% revenue growth in fiscal 2026, but scrutiny continues regarding the adequacy of its response and communication with stakeholders.

Share:
F5 Breach Involving Nation-State Attackers and Theft of Source Code
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Oct 29, 20258mo ago

F5 expands bug bounty and adds CrowdStrike EDR to BIG-IP

Following the breach, F5 said it expanded its bug bounty program and partnered with CrowdStrike to add endpoint detection and response capabilities to BIG-IP systems. These steps were presented as part of its post-incident security improvements.

Federal emergency directive issued in response to F5 breach

The incident prompted a federal emergency directive, indicating government concern over the potential downstream risk from the compromise. The reference does not specify the issuing agency or exact date.

Oct 1, 20259mo ago

F5 publicly discloses breach and says customer impact is limited

In October 2025, F5 confirmed that a nation-state cyberattack had compromised its systems but said the impact was limited and affected only a small number of customers. CEO François Locoh-Donou stated the stolen data was not sensitive and customer operations saw minimal disruption.

Aug 1, 202511mo ago

F5 applies emergency updates and begins incident response

After detecting the breach, F5 said it contained the incident by deploying emergency updates and launching recovery efforts. IOActive and NCC Group assisted the response, while F5 continued scanning for additional issues.

F5 discovers nation-state intrusion into its systems

F5 said it discovered in August 2025 that a nation-state attacker had obtained persistent access to its environment. The intrusion led to theft of BIG-IP source code, customer configuration data, and information related to 44 vulnerabilities.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

5 LINKEDOpen in app
Affected products
1 linked
Big-Ip
Organizations
4 linked
NCC GroupCrowdStrikeF5IOActive
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.