F5, Inc. Discloses Material Cybersecurity Incident Affecting BIG-IP Product Development Environment and Engineering Knowledge Management Platform

On October 15, 2025, F5, Inc. filed a Form 8-K with the U.S. Securities and Exchange Commission, disclosing that a highly sophisticated nation-state threat actor had gained unauthorized access to certain F5 systems, including the BIG-IP product development environment and engineering knowledge management platform. The incident occurred on August 9, 2025, and the company promptly activated its incident response processes, engaging leading external cybersecurity experts to contain the threat actor. The company believes its containment actions have been successful, with no evidence of new unauthorized activity since the initiation of containment efforts. However, the investigation, monitoring, and related activities are ongoing.

A subset of exfiltrated files contained certain portions of the Company's BIG-IP source code and information about undisclosed vulnerabilities that it was working on in BIG-IP. The Company is not aware of any undisclosed critical or remote code vulnerabilities, and there is no evidence of modification to the software supply chain, including the source code and build and release pipelines. Additionally, the company has no evidence of access to, or exfiltration of, data from its CRM, financial, support case management, or iHealth systems.

The company has reviewed the contents of the exfiltrated files and is currently communicating with affected customers directly. The incident has not had a material impact on the Company's operations, but F5 is evaluating the potential impact on its financial condition or results of operations.

Key Takeaways:

  • A highly sophisticated nation-state threat actor gained unauthorized access to F5 systems, including the BIG-IP product development environment and engineering knowledge management platform, on August 9, 2025.
  • The company believes its containment actions have been successful, but the investigation, monitoring, and related activities are ongoing.
  • Exfiltrated files contained only certain portions of the BIG-IP source code, and the company has no evidence of undisclosed critical or remote code vulnerabilities.
  • There is no evidence of modification to the software supply chain, including the source code and build and release pipelines.
  • F5 is communicating directly with affected customers.
  • The incident has not had a material impact on the Company's operations.
  • The company is evaluating the potential impact on its financial condition or results of operations.

Statistics:

  • The incident occurred on August 9, 2025.
  • The company has had an ongoing investigation, monitoring, and related activities since the incident.
  • A subset of exfiltrated files contained certain portions of the Company's BIG-IP source code and information about undisclosed vulnerabilities.
  • The Company has no evidence of undisclosed critical or remote code vulnerabilities.
  • There is no evidence of modification to the software supply chain, including the source code and build and release pipelines.
  • The company has communicated directly with 100% of affected customers.

Sources:

  • Form 8-K filed by F5, Inc. with the U.S. Securities and Exchange Commission on October 15, 2025.
  • Website Post dated October 15, 2025 titled "F5 Security Incident" (Exhibit 99.1 to the Form 8-K).
  • Interactive Data File (embedded within the Inline XBRL document) (Exhibit 104.0 to the Form 8-K).