8-KLeadership ChangesRegulation FDOther Events

F5, INC. 8-K Report, Cybersecurity Incident (Oct 15, 2025)

Filed October 15, 2025For Securities:FFIV

Summary

F5, Inc. (FFIV) has disclosed a material cybersecurity incident where a sophisticated nation-state threat actor gained unauthorized access to certain Company systems, including its BIG-IP product development environment. While containment efforts are believed to be successful and no evidence of new unauthorized activity has been observed, the investigation is ongoing. The exfiltrated files included portions of the Company's BIG-IP source code and information on undisclosed vulnerabilities, though F5 states it's not aware of any active exploitation of these vulnerabilities or modifications to its software supply chain. In parallel, F5 announced the immediate resignation of director Michael Montoya from its Board. However, Mr. Montoya has been appointed Chief Technology Operations Officer, tasked with leading an enterprise-wide security strategy. The Board size has been reduced to ten members as a result. The Company is actively working with law enforcement and is implementing further security measures, while evaluating the potential financial and operational impact of the incident.

Key Highlights

  • 1Sophisticated nation-state actor gained unauthorized access to F5 systems, including BIG-IP product development environment.
  • 2Containment actions are believed to be successful, with no new unauthorized activity observed since initiation.
  • 3Exfiltrated data includes portions of BIG-IP source code and information on undisclosed vulnerabilities; no awareness of active exploitation or supply chain modification.
  • 4Director Michael Montoya resigned from the Board but was appointed Chief Technology Operations Officer to lead security strategy.
  • 5The Board size has been reduced from eleven to ten members.
  • 6F5 is cooperating with federal law enforcement and government partners, and is implementing enhanced security measures.
  • 7The Company is actively evaluating the potential financial and operational impact of the incident.

Frequently Asked Questions

The threat actor gained unauthorized access to certain Company systems, including the BIG-IP product development environment and an engineering knowledge management platform. While the company has no evidence of access to CRM, financial, support case management, or iHealth systems, some exfiltrated files contained configuration or implementation information for a small percentage of customers.

Yes, portions of the Company's BIG-IP source code were exfiltrated. However, F5 states they have no evidence of modification to their software supply chain, including source code, and build/release pipelines, an assessment validated by independent cybersecurity firms. NGINX source code was not accessed or modified.

As of the filing date, the incident has not had a material impact on the Company's operations. F5 is currently evaluating the potential impact on its financial condition or results of operations. Further updates will depend on the ongoing investigation and remediation efforts.

Michael Montoya resigned from the F5 Board of Directors but was immediately appointed as Chief Technology Operations Officer. This move signals a strategic focus on enhancing enterprise-wide security, with Mr. Montoya reporting directly to the CEO to build and operate the company with security at its core.