Skip to main content
Back to overview
Medium

F5 Networks hit by nation-state actor, CISA issues emergency directive for BIG-IP patches

U.S.

Key points

  • F5 Networks suffered a breach by a sophisticated nation-state threat actor.
  • BIG-IP source code and undisclosed vulnerability details were stolen.
  • Breach discovered on August 9, 2025, public disclosure delayed until October 15, 2025.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Hacking

Nation State Or Named Threat Actor actor profile

03

Potential impact

Data Exposure

Impact remains under assessment

Published
Oct 22, 2025
Updated
Jun 25, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Nation State Or Named Threat Actor actor profile

Watch internet-facing systems, credential abuse and exploit activity.

  • Actor profile: Nation State Or Named Threat Actor

Business impact

Potential business exposure
Impact area
Unknown

Mentioned entities

F5 NetworksCISABIG-IPU.SU.S. Department of Justice. InAgencyFederal Civilian Executive BranchF5 BIG-IP

Quick context

Questions about this signal

What happened in this signal?

U.S. cybersecurity firm F5 Networks disclosed a breach of its systems by a sophisticated nation-state threat actor, resulting in the theft of BIG-IP source code and details on undisclosed vulnerabilities. The company learned of the breach on August 9, 2025, but delayed public disclosure at the request of the U.S. Department of Justice. In response to the ongoing threat, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an emergency directive (ED 26-01) on October 16, 2025, requiring Federal Civilian Executive Branch agencies to inventory F5 BIG-IP products, ensure networked management interfaces are not publicly accessible, and apply F5's new updates by October 22, 2025. CISA warned that the stolen data provides the threat actor with a 'technical advantage to exploit F5 devices and software,' posing an 'imminent threat to federal networks.'

When was this signal reported?

Shadow Tier lists Oct 22, 2025 as the signal date.

Which organization is connected to this signal?

F5 is the organization connected to this public signal.

Explore F5
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence