Desk live·
ForensicPost
Nation-state/Analysis/File 25-1103

Two Security Vendors in Two Months, by State Actors

SonicWall in September, F5 in October, both attributed to state-sponsored actors. Security vendors are being targeted for position rather than for data, and the position is upstream of everyone.

Constructed geometry · not a chart of case data
TargetSecurity vendors
ActorState-sponsored
D. Kennedy12 min readConfidence: medium2 sources reviewed

Two incidents at security vendors within two months, both attributed to state-sponsored actors: SonicWall’s configuration backup service at 25-0917, and F5’s source code and undisclosed vulnerability data at 25-1015.

Neither actor was after the vendor. Both were after what the vendor holds about everybody else.

The Material Taken Was Different, The Objective Was Identical

From SonicWall: the network topology and credentials of an entire customer base. From F5: the vulnerability backlog for appliances sitting in front of a large share of enterprise and government applications.

In both cases the value is access to third parties. The vendor is an intermediate objective, and the customer base is the target set.

Why This Is A Rational Allocation Of A State Capability

Compromising a thousand organisations individually is expensive, slow and generates a thousand opportunities for detection. Compromising the vendor that sits in front of them produces the same reach with one operation.

It is the concentration argument this database makes constantly about suppliers, applied by an adversary with the patience for long-term access rather than by one looking for a quick extortion payment.

The Customer Has Almost No Visibility

An organisation running one of these appliances cannot inspect the firmware, cannot audit the vendor’s internal network, and cannot know whether its configuration backup has been read.

It learns when the vendor discloses. Which is why the disclosure quality difference this desk noted at 25-1015 — a specific statement about what was taken versus a claim nobody confirms — is not a public-relations question. For the customer it is the entire basis on which they can act.

How we reported this

This is an analysis file built on the two incidents cited and the sources listed below. Attribution in both cases is as characterised by the companies and by agency reporting; no government is named by this desk. Corrections: corrections@forensicpost.com.

Sources
  1. Nation-state hackers breached sensitive F5 systems, stole customer dataCybersecurity Dive
  2. SonicWall 2025 state-sponsored cloud backup breach: incident overviewAviatrix
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary