Hackers Breach F5 and Stole BIG-IP Source Code and Undisclosed Vulnerability Data
F5 Networks has confirmed a security breach involving a sophisticated nation-state actor, leading to the exfiltration of proprietary BIG-IP source code and confidential vulnerability information.
F5 Networks has confirmed a security breach involving a sophisticated nation-state actor, leading to the exfiltration of proprietary BIG-IP source code and confidential vulnerability information.
The breach, detected in August 2025, targeted F5's product development and engineering platforms. Immediate mitigation measures were initiated to protect customers and restore confidence.
Persistent Access in Development Environments
F5's advisory indicates that the attacker maintained prolonged access to the BIG-IP product development environment and engineering knowledge management system. Although files containing core BIG-IP source code and undisclosed vulnerabilities were taken, F5 reports no critical remote-code-execution flaws were included, nor evidence of active exploitation.
Independent reviews by NCC Group and IOActive confirmed that the software supply chain, including build and release pipelines, remains uncompromised. There is no indication of tampering with NGINX, F5 Distributed Cloud Services, or Silverline platforms. Customer CRM, financial, support-case, and iHealth systems were not accessed; however, some exfiltrated files contained configuration and implementation details related to certain customers. Affected organizations will be contacted directly.
Urgent Updates and Hardening Recommendations
F5 has released updated versions for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients. Customers are advised to deploy these patches promptly. Additional guidance includes:
The breach, detected in August 2025, targeted F5's product development and engineering platforms.
Threat-hunting guide to enhance detection and monitoring in BIG-IP deployments. Best practices for system hardening with automated checks via the F5 iHealth Diagnostic Tool. Instructions for streaming BIG-IP events into customer SIEMs for enhanced visibility.
F5’s global support team is available to assist with updates, hardening steps, and customer inquiries through MyF5 support cases or direct contact.
Strengthening Defenses and Rebuilding Trust
F5 has taken extensive measures to enhance both its enterprise and product security infrastructures. Access credentials have been updated, automated inventory and patch-management tools improved, and network-security architecture upgraded. The product development environment now includes more stringent security controls and continuous monitoring.
F5 is collaborating with CrowdStrike to deploy Falcon EDR sensors and Overwatch Threat Hunting to BIG-IP. Early-access deployments will provide customers with a free Falcon EDR subscription to improve detection and response capabilities.
Ongoing code reviews and penetration tests, supported by NCC Group and IOActive, aim to identify and address vulnerabilities proactively. F5 Networks underscores the importance of customer trust and is committed to transparency and collaboration with the security community. Updates and resources will be provided on F5's advisory page.
Based on reporting by GBHackers.
