Skip to main content

Hackers tied to the Chinese government are believed to be behind a major breach at U.S.-based cybersecurity provider F5, according to two sources briefed on the ongoing investigation. The incident, first disclosed by U.S. officials on Wednesday, has triggered urgent efforts to secure federal networks using F5 technologies.

The sources said the attackers infiltrated F5’s systems for more than a year, stealing files including segments of source code and information on software vulnerabilities. The Cybersecurity and Infrastructure Security Agency (CISA) warned that the attack poses a significant threat to both public and private organizations, calling for immediate security updates.

CISA Acting Director Madhu Gottumukkala said the vulnerabilities “extend to any organization using this technology” and could lead to “catastrophic compromises” of critical infrastructure. F5 has not commented on the attribution, while the company earlier said it had contained the breach with help from cybersecurity firms including CrowdStrike and Mandiant.

A spokesperson for China’s Embassy in Washington, Liu Pengyu, denied the accusation, saying China “consistently opposes and combats hacking” and objected to what it described as politically motivated claims.

The breach underscores rising cyber tensions between the United States and China, as suspected state-backed hacking groups continue to target Western technology and defense networks.