Commvault, a NASDAQ-listed data protection solutions provider serving over 100,000 organizations, has confirmed that a recent security breach by a nation-state threat actor did not compromise any customer backup data.
The incident, first disclosed on March 7, 2025, was initially detected after Microsoft alerted Commvault to suspicious activity in its Azure environment on February 20. Subsequent investigation revealed that only a small number of customers were affected, with no impact on the company’s operations.
“Importantly, there has been no unauthorized access to customer backup data that Commvault stores and protects, and no material impact on our business operations or our ability to deliver products and services,” stated Danielle Sheer, Commvault’s Chief Trust Officer.
The company is collaborating with cybersecurity firms and coordinating with authorities including the FBI and CISA to address the breach.
## Security Recommendations
Commvault has issued several recommendations to customers to protect against similar attacks:
– Apply Conditional Access policies to Microsoft 365, Dynamics 365, and Azure AD single-tenant App registrations
– Monitor sign-in activity regularly to detect access attempts from unauthorized IP addresses
– Rotate and sync client secrets between Commvault and Azure portal every 90 days
– Report any unauthorized access immediately to Commvault Support
The attackers exploited a now-patched zero-day vulnerability (CVE-2025-3928) in Commvault Web Server software that allowed remote authenticated attackers with low privileges to plant webshells on target servers.
CISA has added this vulnerability to its Known Exploited Vulnerabilities Catalog, requiring federal agencies to secure their Commvault software by May 19, 2025, in accordance with Binding Operational Directive 22-01.
