HomeSecurityF5 - Data Breach: Hackers Stole BIG-IP Source Code

F5 – Data Breach: Hackers Stole BIG-IP Source Code

F5 , a leading provider of security and application delivery solutions, disclosed a major data breach on October 14 , 2025. The company announced that a sophisticated state- sponsored threat actor had gained long-term access to its internal systems , extracting sensitive files including BIG-IP source code and details of previously undisclosed vulnerabilities.

F5 - Data Breach

While F5 stressed that no critical exploits or active attacks on customers have been detected, the breach highlights vulnerabilities in even the most secure development environments. The intrusion, discovered in August 2025, involved persistent access to F5’s BIG-IP product development environment and knowledge management platforms .

See also: T-Mobile: Interception of customer call and message data

According to the company's official statement, the attacker downloaded files containing proprietary source code for the leading BIG-IP software, which supports millions of business applications worldwide.

Additionally, the stolen data included information about vulnerabilities that F5 was actively investigating and patching. However, the company stressed that these were not critical remote code execution vulnerabilities and there was no evidence of exploitation.

F5: Violation details

The investigation (with the help of cybersecurity firms CrowdStrike and Mandiant), found no evidence of tampering with the software supply chain.

See also: Chinese hackers exploit Geo-Mapping Tool for prolonged presence on networks

F5 - Data Breach: Hackers Stole BIG-IP Source Code

Independent audits by NCC Group and IOActive confirmed this conclusion, ruling out modifications that could have introduced backdoors into customer deployments. The breach also did not impact key areas such as the NGINX source code, F5 Distributed Cloud Services , and DDoS protection systems Silverline.

However, some customers were affected. A small subset of files exported from the knowledge platform contained configuration details for certain BIG-IP implementations.

F5 plans to notify affected users immediately after reviewing the data. Fortunately, no customer records from CRM, financial systems, support portals or the iHealth monitoring tool were compromised, limiting broader privacy risks.

See also: NoName057(16) attacks public works procurement platform

F5 - Data Breach: Hackers Stole BIG-IP Source Code

F5 acted immediately to mitigate the threat, changing credentials, strengthening access controls , and deploying advanced monitoring tools. No further unauthorized activity has been noted since the threat was mitigated.

To protect users, the company released urgent fixes for BIG-IP, F5OS, BIG-IP Next for Kubernetes, BIG-IQ, and APM clients in the October 2025 Security Advisory. Customers are urged to apply these updates immediately, even if there are no known exploits.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS