ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

F5 confirms breach linked to nation-state hackers who stole BIG-IP source code and vulnerability data

U.S. cybersecurity company F5 confirmed Wednesday that it suffered a major cyberattack by a highly sophisticated nation-state threat actor that gained long-term access to parts of its network, stealing files containing portions of BIG-IP’s source code and details of undisclosed vulnerabilities.


According to a regulatory filing with the U.S. Securities and Exchange Commission, the Seattle-based company discovered the breach on August 9, 2025, but delayed public disclosure at the request of the U.S. Department of Justice. F5 said the attackers maintained persistent access to its systems for an extended period and infiltrated both its BIG-IP product development environment and internal knowledge management platform.


The company said there is no evidence that the stolen data has been used maliciously or that its CRM, financial, support case management, or iHealth systems were accessed. However, some exfiltrated files contained configuration or implementation information tied to a small number of customers. Those customers will be contacted directly after the company completes its review.


“We have taken extensive actions to contain the threat actor,” F5 stated. “Since beginning these activities, we have not seen any new unauthorized activity, and we believe our containment efforts have been successful.”


While F5 has not officially named the country responsible, individuals familiar with the investigation told Bloomberg that the intrusion was carried out by state-backed hackers from China. The attackers reportedly maintained access to F5’s network for at least 12 months and used a malware strain known as BRICKSTORM, which has been linked to a China-nexus espionage group tracked as UNC5221.


Following the disclosure, the U.S. Cybersecurity and Infrastructure Security Agency issued an emergency directive (ED 26-01) ordering all Federal Civilian Executive Branch agencies to identify and secure F5 BIG-IP products. Agencies must apply the latest patches by October 22, 2025, and submit a complete inventory and mitigation report by October 29. CISA warned that the stolen source code and vulnerability information could enable attackers to identify zero-day flaws and develop targeted exploits.


F5 has since engaged Google Mandiant and CrowdStrike to support its remediation efforts. The company has rotated credentials and signing certificates, strengthened access controls, improved network monitoring tools, and added new security layers to its product development environment. It has also released updated software for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients, urging customers to install the updates immediately.


Experts say the theft of both source code and undisclosed vulnerability data could significantly reduce the time needed for attackers to develop exploits. “This provides the ability for threat actors to exploit vulnerabilities that have no public patch,” said Michael Sikorski, Chief Technology Officer of Unit 42 at Palo Alto Networks.


In a public statement, F5 expressed regret for the breach and reaffirmed its commitment to transparency and customer protection. “Your trust matters,” the company said. “We truly regret that this incident occurred and the risk it may create for you. We are committed to learning from this incident and sharing those lessons with the broader security community.”


The F5 breach is the latest in a string of high-profile cyberattacks targeting global corporations. In recent months, companies including Jaguar Land Rover, Asahi Group, and Harrods have all disclosed major incidents involving data theft and operational disruption.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543