cyber
confidence high
sentiment negative
materiality 0.75
F5 discloses nation-state cyber breach; BIG-IP source code exfiltrated; director resigns for new role
F5, INC.
- Nation-state threat actor exfiltrated BIG-IP source code and undisclosed vulnerability details; access since August 2025.
- No evidence of active exploitation or software supply chain modification; containment efforts successful.
- Configuration or implementation info for a small % of customers exfiltrated; affected customers will be contacted.
- Director Michael Montoya resigned from board (no disagreement), appointed Chief Technology Operations Officer, reporting to CEO.
- F5 released security updates for BIG-IP, F5OS, BIG-IP Next, BIG-IQ, and APM clients; customers advised to update.