Incident · 8-K Item 1.05
F5 discloses nation-state access to BIG-IP source code and vulnerability data
Compiled 2026-09-27 from public records. By the cisonews.net Desk.
F5, the application delivery and security vendor, disclosed on October 15, 2025 that a highly sophisticated nation-state threat actor had held long-term, persistent access to some of its systems, including the development environment for its BIG-IP products. The company learned of the access on August 9, 2025; the filing followed a Justice Department decision on September 12 to delay public disclosure.
What was accessed
F5 said files taken included portions of BIG-IP source code and details of undisclosed vulnerabilities it was working on. It said it knew of no undisclosed critical or remote code vulnerabilities and no active exploitation, and had no evidence of changes to its software supply chain. Some knowledge-base files held configuration details for a small percentage of customers.
The delay
That puts 67 days between F5 learning of the access and the filing.
Status
F5 reported no material effect on operations and was still evaluating the financial impact. The filing does not name the actor or give the date the access began.
Sources
- 2025-10-15 · AF5, Inc., Form 8-K (SEC EDGAR), published October 15, 2025
Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.
See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.