F5 Breach Involving Nation-State Attackers and Theft of Source Code
F5 confirmed that a nation-state threat actor gained persistent access to its internal systems, resulting in the theft of BIG-IP source code, customer configuration data, and information on 44 vulnerabilities. The company stated that only a small number of customers were affected, all of whom have since applied emergency updates, and emphasized that the stolen data was not sensitive and that customer operations experienced minimal disruption. F5 has responded by expanding its bug bounty program and partnering with CrowdStrike to enhance endpoint detection and response (EDR) capabilities for BIG-IP systems, while external cybersecurity firms IOActive and NCC Group found no critical flaws in the stolen code.
Despite F5's assurances that the incident is contained and the impact is limited, some independent researchers have raised concerns about the company's transparency and the true extent of operational control and reputational damage. The breach, discovered in August and disclosed in October, also triggered a federal emergency directive. F5 maintains that the incident has not significantly affected its business outlook, projecting up to 4% revenue growth in fiscal 2026, but scrutiny continues regarding the adequacy of its response and communication with stakeholders.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
F5 expands bug bounty and adds CrowdStrike EDR to BIG-IP
Following the breach, F5 said it expanded its bug bounty program and partnered with CrowdStrike to add endpoint detection and response capabilities to BIG-IP systems. These steps were presented as part of its post-incident security improvements.
Federal emergency directive issued in response to F5 breach
The incident prompted a federal emergency directive, indicating government concern over the potential downstream risk from the compromise. The reference does not specify the issuing agency or exact date.
F5 publicly discloses breach and says customer impact is limited
In October 2025, F5 confirmed that a nation-state cyberattack had compromised its systems but said the impact was limited and affected only a small number of customers. CEO François Locoh-Donou stated the stolen data was not sensitive and customer operations saw minimal disruption.
F5 applies emergency updates and begins incident response
After detecting the breach, F5 said it contained the incident by deploying emergency updates and launching recovery efforts. IOActive and NCC Group assisted the response, while F5 continued scanning for additional issues.
F5 discovers nation-state intrusion into its systems
F5 said it discovered in August 2025 that a nation-state attacker had obtained persistent access to its environment. The intrusion led to theft of BIG-IP source code, customer configuration data, and information related to 44 vulnerabilities.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
F5 Is Misleading the Market — The Breach Is Nowhere Near Contained
deepspecter.medium.com
Open sourceF5 Is Misleading the Market — The Breach Is Nowhere Near Contained
reporter.deepspecter.com
Open sourceF5 investigates nation-state cyberattack, says impact remains limited
scworld.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


