Cyber Insights: F5 Cyber Attack

Concise Cybersecurity Intelligence for Decision-Makers

F5 Image

Download Our Cyber Insights Document on the F5 Breach  

On 15 October 2025, F5 Networks disclosed a serious security incident in which a highly sophisticated, nation-state affiliated threat actor gained persistent access to its product development environment. During this breach, the attacker exfiltrated sensitive files from F5’s internal systems—files that included portions of source code for the widely-used BIG-IP appliance line and documentation on as-yet unpatched vulnerabilities. 

Though F5 reports there is no confirmed evidence of software supply-chain tampering or active exploitation of the stolen code, the incident has triggered alarm across critical-infrastructure, government and enterprise networks due to the scale of exposure and the risk of custom exploit development. 

For organisations that rely on F5 devices, the implications are clear: the compromise of a vendor’s core infrastructure represents a systemic risk, not just to that vendor but to its entire downstream ecosystem. This incident underscores the urgent need for proactive incident response planning, third-party risk management frameworks and resilient cyber defence programmes. Download our summary of this major cyber incident to understand exactly what happened and what the repercussions of this breach mean for the impacted organisations. 

 

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of CMA Cyber Insights on the F5 Breach

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs About the F5 Cyber Attack

  • 1. What happened in the F5 cyber attack?
    A sophisticated nation-state-affiliated threat actor gained long-term access to F5’s internal product development environment. The attacker exfiltrated sensitive files containing portions of BIG-IP source code and information about previously undisclosed vulnerabilities being investigated by F5.
  • 2. When did F5 disclose the cyber attack?
    F5 publicly disclosed the security incident on 15 October 2025. The company had been investigating and containing the intrusion with support from external cybersecurity specialists, law enforcement agencies and government partners.
  • 3. What information was stolen in the F5 breach?
    The stolen information included parts of the BIG-IP source code and details relating to vulnerabilities that had not yet been publicly disclosed. The exposure could potentially help attackers study the product’s internal workings and develop more targeted attacks against F5 environments.
  • 4. Who was responsible for the F5 cyber attack?
    F5 described the attacker as a highly sophisticated, nation-state-affiliated threat actor. However, the company did not publicly attribute the incident to a specific country, government or named threat group.
  • 5. Was F5’s software supply chain compromised?
    F5 stated that it found no evidence that the attacker modified its source code, build systems, release processes or distributed software. Independent reviews also found no evidence of tampering with F5’s software supply chain.
  • 6. Why does the F5 breach create risks for other organisations?
    BIG-IP products are widely deployed across government, critical infrastructure and large enterprises to manage and secure important application traffic. Access to source code and vulnerability information could help attackers identify weaknesses, develop customised exploits or target organisations running outdated and poorly configured F5 systems.
  • 7. What should organisations using F5 products do?
    Organisations should inventory all F5 products, install the latest vendor-provided security updates and investigate their environments for suspicious activity. Management interfaces should not be exposed to the public internet and should be protected through network segmentation, access controls and continuous monitoring.
  • 8. What does the CMA Cyber Insights document cover?
    The CMA Cyber Insights document examines how the F5 breach occurred, what information was exposed and why the incident presents a systemic risk to downstream organisations. It also outlines practical lessons for vulnerability management, third-party risk, incident response and resilient cyber defence.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.