Cyberattack at Security Provider F5
Cybersecurity provider, F5 Inc. suffered a nation-state cyberattack where source code ended up exfiltrated from its networking product suite, BIG-IP, this past August and per Department of Justice approval, delayed notification of the hack until Wednesday.
“On August 9, 2025, F5, Inc. learned that a highly sophisticated nation-state threat actor had gained unauthorized access to certain company systems,” the company said in 8-K report to the Securities and Exchange Commission (SEC) filed Wednesday, October 15. “The company promptly activated its incident response processes, and has taken extensive actions to contain the threat actor. To support these activities, the company engaged leading external cybersecurity experts.”
In the SEC report, F5 said, “during the course of its investigation, the company determined that the threat actor maintained long-term, persistent access to certain F5 systems, including the BIG-IP product development environment and engineering knowledge management platform,” the company said. “Through this access, certain files were exfiltrated, some of which contained certain portions of the Company’s BIG-IP source code and information about undisclosed vulnerabilities that it was working on in BIG-IP.”
Industries
Impacts
IT
