Overview
- The company said attackers maintained prolonged access to its BIG-IP development environment and engineering knowledge platform.
- Stolen files included portions of BIG-IP source code, details on unannounced vulnerabilities, and configuration data for a small share of customers.
- F5 reported independent reviews found no changes to source code or build pipelines and no supply-chain compromise.
- The company said it has seen no evidence of active exploitation and is notifying affected customers while hardening defenses.
- DOJ approved a temporary delay in public disclosure under SEC Form 8-K Item 1.05(c), and F5 said operations remain unaffected and other product lines were not impacted.