F5 Breach
F5 confirmed that attackers had long term access to its internal systems, stealing source code and research into vulnerabilities for its BIG-IP product line. Those same products sit inside networks of more than four in five Fortune 500 companies.
What happened
The intrusion began more than a year ago and was only discovered recently.
F5 says the attackers, believed to be a nation-state group, accessed its development systems and took internal data, including:
- Source code for BIG-IP and other traffic management products
- Documentation on vulnerabilities that had not yet been disclosed
There’s no sign the attackers modified any software or gained access to customer-facing platforms. But the risk comes from what they learned.
Last week, the CISA issued an emergency directive urging U.S. agencies to patch F5 systems immediately. That move alone shows the level of concern.
Why this isn’t a regular attack
Most people never notice F5 systems, but they run quietly behind much of the internet. Their products manage traffic, keep applications steady and filter what moves through corporate networks.
When attackers take code from that layer, it reveals how those systems are built and defended. The stolen vulnerability research makes this even more serious, giving attackers insight into where the weak points might be. Even if everything is patched now, that knowledge can be used months from today in ways that are hard to predict.
What’s been seen so far
Researchers have already noticed signs of probing activity (automated scans that search the internet for specific devices/ weaknesses before an attack begins).
- Internet-wide scans targeting F5 devices began spiking in September
- Many exposed systems are still unpatched or outdated
This means that someone likely knew this was coming and went looking early.
What to do now
If your business environment includes F5 appliances or services, treat this as a priority check.
- Identify every F5 asset, including BIG-IP, BIG-IQ, and F5OS systems
- Apply all current patches and updates
- Review configurations and logs for unexpected admin actions or changes
- Strengthen segmentation so that if one system is compromised, it can’t move laterally
- Communicate with your vendors and partners. Shared infrastructure means shared exposure
This event will probably unfold slowly, the way SolarWinds did. It’s worth preparing now rather than waiting for the next update.
My view
This breach doesn’t surprise me. Our defences are only as strong as the tools we depend on.
F5 also isn’t the first major vendor to be targeted this way, and it won’t be the last. Every organisation needs to rethink how much trust it places in third-party systems.
Ask the simple questions: who maintains the infrastructure we rely on, what access do they have and how would we know if something went wrong? This level of visibility can separate the resilient from the reactive.



