Commvault, a leading provider of data protection solutions, says a nation-state threat actor who breached its Azure environment didn't gain access to customer backup data. Listed on NASDAQ since March 2006, Commvault is included in the S&P MidCap 400 Index and provides cyber resilience services to over 100,000 organizations. As the company first revealed on March 7, 2025, Commvault discovered the incident after being notified by Microsoft on February 20 of suspicious activity within its Azure environment. A follow-up investigation into the breach found that the incident only affected a small number of Commvault customers and had not impacted the company's operations. "Importantly, there has been no unauthorized access to customer backup data that Commvault stores and protects, and no material impact on our business operations or our ability to deliver products and services," Danielle Sheer, the company's Chief Trust Officer, said in a Wednesday update. "We are working closely with two leading cybersecurity firms and are coordinating with the appropriate authorities, including the FBI, Cybersecurity and Infrastructure Security Agency (CISA), and others." In a support document containing indicators of compromise, Commvault advises customers to apply a Conditional Access policy to all Microsoft 365, Dynamics 365, and Azure AD single-tenant App registrations to protect their data against similar attack attempts. It also recommended to regularly monitor sign-in activity to detect...
Commvault says recent breach didn't impact customer backup data
BleepingComputer
·Sergiu Gatlan
·Published Apr 30, 2025
·Updated
Affected Software
2 affected components
Commvault data protection solutions
Microsoft Azure
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a recent breach of Commvault's Azure environment and clarifies that customer backup data was not compromised.
2
What security implications are discussed in the article?
The article emphasizes that despite a breach by a nation-state threat actor, customer data remained secure and unaffected.
3
What company experienced the security breach?
Commvault, a provider of data protection solutions, experienced the security breach.
4
What technology platform was involved in the security incident?
The breach involved Commvault's environment hosted on Microsoft Azure.
5
How did Commvault respond to the breach concern?
Commvault reassured customers that their backup data was not accessed during the breach.