F5, INC.
Oct 2025 · Graded Verified · Technology and Software · Government record
Incident summary
F5, INC.Oct 2025
$26.5M
Spent responding & recovering
Direct expense
The stolen files were not customer records but F5's blueprints: BIG-IP source code and the vulnerabilities it had not yet patched, taken from the vendor whose appliances sit at the edge of 48 of the Fortune 50. Reporting ties the intrusion to a China-nexus group that held persistent access for at least a year before F5 noticed. When the vendor guarding everyone's front door keeps its unfixed flaws in one place, the perimeter and the arsenal are the same building.
Verified: the linked document states this figure.
SEC 8-K, Item 1.05
Initial attack type not disclosed · Impact data theft confirmed · Actor China-nexus group
Quantified 113 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The categorized loss on the record carries its own source.
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.