Confirmed compromise of F5 network
The NCSC is advising organisations to follow the guidance issued by F5 and to install the latest security updates.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening

F5 has issued a statement reporting a compromise of its systems, and data exfiltration. This data is reported to include a portion of its BIG-IP source code and vulnerability information.
This access could enable a threat actor to:
Successful exploitation of the impacted F5 products could enable a threat actor to access embedded credentials and Application Programming Interface (API) keys, move laterally within an organisation’s network, exfiltrate data, and establish persistent system access.
There is currently no indication that any customer networks have been impacted via the compromise of the F5 network.
While there is currently no suggestion that nginx has been affected, instances should always be updated to a latest version as per NCSC vulnerability management guidance.
Affected F5 products:
If you use F5 products, you should take the following priority actions:
The NCSC provides a range of free guidance, services and tools that help to secure systems.


