Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk
Over 269,000 F5 devices are exposed to the public internet daily, as reported by The Shadowserver Foundation. This exposure follows F5's disclosure of a sophisticated attack by nation-state actors that compromised its development environment and stole…
Over 269,000 F5 devices are exposed to the public internet daily, as reported by The Shadowserver Foundation. This exposure follows F5's disclosure of a sophisticated attack by nation-state actors that compromised its development environment and stole source code and vulnerability details related to BIG-IP products.
Approximately 134,000 exposed IPs are located in the United States, posing significant risks to organizations that rely on F5's application delivery controllers for secure network operations.
The breach, detected in August 2024, involved long-term unauthorized access, highlighting vulnerabilities in F5's infrastructure. This could potentially increase risks for exposed devices.
Cybersecurity experts warn that the stolen information may allow attackers to craft targeted exploits, potentially leading to remote code execution or data exfiltration on unpatched systems.
Federal agencies, including CISA, have issued emergency directives due to the volume of internet-facing F5 hardware, which increases the threat landscape for sectors such as finance, government, and critical infrastructure.
F5 Networks confirmed on October 15, 2025, that advanced persistent threat actors infiltrated its BIG-IP development systems, exfiltrating proprietary source code and vulnerability data not yet publicly disclosed or patched.
The incident, involving nation-state hackers, targeted engineering platforms and may compromise the integrity of future product releases.
Over 269,000 F5 devices are exposed to the public internet daily, as reported by The Shadowserver Foundation.
While no direct evidence suggests customer networks have been breached, access to undisclosed vulnerabilities, potentially zero-days, necessitates immediate inventorying and updating of all BIG-IP instances.
CISA's Emergency Directive 26-01 mandates federal agencies to harden public-facing F5 devices and remove unsupported hardware, indicating the breach's national security implications.
The compromise affects products like BIG-IP iSeries, rSeries, F5OS-A, and BIG-IQ. Recent quarterly patches address related CVEs, including CVE-2025-61955 and CVE-2025-60013.
Security firms emphasize monitoring for exploitation attempts, noting the potential for credential theft and lateral movement in affected environments.
The Shadowserver Foundation's Device Identification Report scans and identifies approximately 269,000 F5 device IPs daily, accessible from the internet, with the majority located in the US.
This visibility makes these devices prime targets for scanning and exploitation, especially after the breach, when attackers may leverage stolen insights for precision strikes.
Organizations are urged to apply F5's October 2025 security notifications, which include fixes for multiple modules in BIG-IP and F5OS platforms.
The Shadowserver report provides daily IP feeds for proactive scanning, urging users to cross-reference with internal logs for indicators of compromise.
This exposure calls for robust network segmentation and regular vulnerability assessments. With nation-state actors involved, the cybersecurity community expects increased exploit activity, making device visibility and rapid patching essential.
Based on reporting by Cyber Security News.
