Data Breach
Commvault Data Breach
0 records exposed • February 2025
Nation-state hackers found a bug in Commvault backup software and used it to access companies' Microsoft 365 backups stored in the cloud.
What Happened
Commvault disclosed a nation-state actor exploited a zero-day to access customer Microsoft 365 backup data through their cloud environment.
Attack method: Zero-day vulnerability
What Data Was Exposed
Customer M365 data, Backup metadata
Is your business exposed?
What to Do If You're Affected
- 1.
Review Commvault advisory and patch immediately
- 2.
Audit M365 backup access logs
- 3.
Enable additional Commvault security features
Lessons for Businesses
- • Backup systems are attractive targets
- • Cloud backup providers need strong security
- • Nation-states target enterprise software
Related Breaches
Is your business exposed?
Check if your company data is circulating on the dark web
Free scan • No credit card required