FEDERALItem 1.05 · mandatoryHackingTechnologyInformationComputer HardwareNation-stateNation State SuspectedTargetedData ExfiltratedMulti-Stage ChainLateral Movement ObservedCustomer Data InvolvedDOJ-Delayed FilingDelayed DiscoveryIPMETADATALowContained
F5, Inc.
bd_ace14406ea2d32b7 · schema v1 · pii pii-v1
Full breach record for F5, Inc. →F5, Inc. disclosed on October 15, 2025 that on August 9, 2025 it learned a sophisticated nation-state threat actor had gained long-term persistent access to certain systems, including its BIG-IP product development environment and engineering knowledge management platform. Files were exfiltrated containing portions of BIG-IP source code, information on undisclosed vulnerabilities, and configuration/implementation data for a small percentage of customers. DOJ granted an Item 1.05(c) disclosure delay on September 12, 2025.
SEC clockMateriality determined Oct 15, 2025 → Filed Oct 15, 20250d ✓ SEC 4-day OK10 weeks discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1048695/000104869525000149/ffiv-20251015.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Oct 15, 2025
- Raw hash
- 39dfa87256b517e55a0d5edd618f657a0b020c966bade096326775d747c7695c
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- F5, Inc.norm: f5
- SEC CIK
- 0001048695
- Domain
- f5.com
Victim entity
- Name
- F5, Inc.norm: f5
- SEC CIK
- 0001048695
- Domain
- f5.com
- Industry
- Technology - Application Delivery / Security
- Industry
- TechnologyllmNAICS 334118 · Computer Terminal and Other Computer Peripheral Equipment Manufacturing
Incident
- Discovered
- Aug 9, 2025
- Materiality determined
- Oct 15, 2025
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IPMETADATA
- Attack vector
- Unauthorized Access· nation-state
- MITRE ATT&CK
- T1078 Valid AccountsT1041 Exfiltration Over C2 Channel
- Threat actor
- Nation-stateExternalEspionage
- Regulator citations
- U.S. Department of Justice determined a delay in public disclosure was warranted pursuant to Item 1.05(c) of Form 8-KActively engaged with federal law enforcement and government partners
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 0d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Oct 15, 2025→ Filed: Oct 15, 20250d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.