Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Commvault Metallic Breach 2025: How a Zero-Day in…
Breach analysis Incident: 7 Mar 2025

Commvault Metallic Breach 2025: How a Zero-Day in Commvault’s Azure Environment Exposed Customers’ Microsoft 365 App Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
On this page

On 7 March 2025 Commvault disclosed that a nation-state threat actor had been active in its Microsoft Azure environment, after Microsoft began notifying the company on 20 February 2025. Commvault later said the attacker "may have accessed a subset of app credentials" that customers of Metallic, its Microsoft 365 backup service, use to let Commvault into their Microsoft 365 tenants. Those app credentials are client secrets for Entra ID application registrations: non-human identities with standing access to customer mail, files and directory data. The attacker got in by exploiting CVE-2025-3928 in the Commvault Web Server as a zero-day. Commvault said a "small number" of customers shared with Microsoft were affected and that backup data it stores was not accessed. In May 2025 CISA warned that the activity may be part of a wider campaign against SaaS providers whose cloud apps run with default settings and elevated permissions.

Key takeaways

  • Microsoft began notifying Commvault on 20 February 2025 of unauthorised activity by a nation-state actor in Commvault's Azure environment; Commvault went public on 7 March 2025.
  • The attacker may have obtained the client secrets Commvault's Metallic service uses to authenticate to customers' Microsoft 365 tenants, according to Commvault and CISA.
  • Entry was through CVE-2025-3928, a Commvault Web Server flaw (CVSS 8.7) that allowed webshells to be planted; CISA added it to its exploited vulnerabilities catalogue on 28 April 2025.
  • Commvault says a small number of customers were affected and no backup data it stores was accessed. It rotated the app credentials and told customers to rotate their own.
  • The identity lesson: a SaaS vendor's app secret into your tenant is your identity, held by someone else, so its scope, location limits and rotation are your problem too.

At a glance

OrganisationsCommvault (Metallic Microsoft 365 backup SaaS); a small number of Commvault customers that are also Microsoft customers
WhenMicrosoft notifications from 20 February 2025; Commvault advisory 7 March 2025; Commvault updates in April and May 2025; CISA advisory update 22 May 2025
AttackerAn unnamed nation-state threat actor, according to Commvault, citing Microsoft
Entry pointZero-day exploitation of CVE-2025-3928 in the Commvault Web Server within Commvault's Azure environment
Identities abusedClient secrets (app credentials) for the Entra ID application registrations Metallic uses to access customers' Microsoft 365 environments
ImpactPossible access to a subset of customer app credentials and, through them, to customers' Microsoft 365 tenants; Commvault reports no unauthorised access to backup data it stores
CategoryNHI. Incident class: confirmed NHI breach (SaaS provider's app secrets for customer tenants obtained by a nation-state actor)

What happened

Metallic is Commvault's software-as-a-service backup product for Microsoft 365. To back up a customer's Microsoft 365 data, it uses an application registered in Entra ID that the customer has granted permission to read that data, authenticated by an app credential such as a client secret. Commvault's guidance distinguishes customers using its own application from SaaS customers with custom, single-tenant applications. Either way, the secret is a non-human identity with standing access to the customer's tenant, and it sits in the vendor's infrastructure.

According to Commvault's customer update, Microsoft began notifying it on 20 February 2025 "regarding unauthorized activity by a nation-state threat actor" based on what Microsoft could see in Azure. Commvault published its first advisory on 7 March. It said it had rotated the affected credentials and strengthened monitoring. By May its position was that the actor "may have accessed a subset of app credentials" that some Commvault customers use to authenticate their Microsoft 365 environments. The Hacker News reported that the intruders had exploited CVE-2025-3928 as a zero-day. CSO Online describes it as a Commvault Web Server flaw scored 8.7 that let attackers create and run webshells. CISA added it to the Known Exploited Vulnerabilities catalogue on 28 April 2025, with a federal patch deadline of 19 May.

Commvault has consistently said the activity affected "a small number of customers we have in common with Microsoft" and that there was "no unauthorized access to customer backup data that Commvault stores and protects". It published indicators of compromise, including five IP addresses, and asked customers to rotate the Microsoft 365 app credentials used by Commvault, revalidate app registration permissions and apply Conditional Access policies to single-tenant apps.

On 22 May 2025 CISA updated its advisory. It said threat actors may have accessed client secrets for Metallic's Microsoft 365 backup service, which could give them access to customers' Microsoft 365 environments, and that the activity may be part of a broader campaign against SaaS companies' cloud applications with default configurations and elevated permissions. Its mitigations focused on the service principals themselves: monitor Entra audit logs for credential changes, restrict sign-ins to Commvault's IP ranges, and rotate secrets. James Maude of BeyondTrust summed up the third-party problem for CSO Online: "their breach becomes your breach."

Timeline

DateEvent
20 February 2025Microsoft begins notifying Commvault of unauthorised activity by a nation-state actor in its Azure environment.
7 March 2025Commvault publishes its first security advisory and says it has rotated affected credentials.
28 April 2025CISA adds CVE-2025-3928 to the Known Exploited Vulnerabilities catalogue.
1 May 2025The Hacker News reports Commvault's confirmation that the flaw was exploited as a zero-day.
4 May 2025Commvault publishes a customer security update saying the actor may have accessed a subset of app credentials.
19 May 2025Federal patch deadline for CVE-2025-3928 under CISA's catalogue.
22 May 2025CISA updates its advisory and warns of a wider campaign against SaaS cloud applications.

How it happened: the identity attack path

  1. A vendor holds the keys. Metallic needs standing access to each customer's Microsoft 365 tenant, so app secrets for privileged Entra ID application registrations were stored in Commvault's Azure environment.
  2. Zero-day into the vendor. A nation-state actor exploited CVE-2025-3928 in the Commvault Web Server, which allowed webshells to be planted.
  3. Reach the secrets. From inside Commvault's environment, the actor may have accessed a subset of the client secrets customers' tenants trust.
  4. Authenticate as the backup app. A client secret lets its holder request tokens as the backup application, with whatever Microsoft 365 permissions the customer granted it, from any location unless Conditional Access limits it.
  5. Detected by the platform. Microsoft spotted the activity in Azure and notified Commvault, which rotated credentials and asked customers to rotate theirs.

Impact

  • Confirmed: a nation-state actor operated in Commvault's Azure environment, and a small number of shared Commvault and Microsoft customers were affected, according to Commvault.
  • Credentials exposed: a subset of the app credentials customers use for Metallic Microsoft 365 backup may have been accessed, according to Commvault and CISA.
  • Not affected, per Commvault: customer backup data stored by Commvault, and Commvault's business operations.
  • Potential: access to affected customers' Microsoft 365 mail, files and directory data through the backup application's permissions. No public account says what, if anything, was taken from customer tenants.
  • Wider: CISA's warning that SaaS providers' cloud apps with default configurations and high privileges are being targeted as a class.

What this means for NHI governance

This is a textbook third-party NHI breach. The most valuable thing in Commvault's environment, from an attacker's view, was not Commvault's own data but the app secrets that open its customers' tenants. Each customer had granted a backup application read access to its Microsoft 365 data, and the secret behind that grant lived outside the customer's control. The same structure sits behind the Salesloft Drift breach and the Gainsight Salesforce OAuth breach, where tokens held by an integration vendor opened customers' CRM tenants.

Customers cannot stop a vendor being breached, but they decide how much the vendor's credential can do and from where. CISA's mitigations are all identity controls on the service principal: limit sign-ins to the vendor's IP ranges, alert on credential changes, rotate secrets and review admin-consented permissions. Our SaaS and OAuth App Governance Guide and Third-Party Access Guide cover how to inventory and constrain these grants.

Recommendations

  • Rotate vendor-held app secrets. If a SaaS vendor that holds a client secret for your tenant reports an incident, rotate that secret immediately and set a regular rotation schedule. See our Leaked Credential Response Playbook.
  • Restrict where service principals can sign in. Use Conditional Access for workload identities to limit vendor applications to the vendor's published IP ranges. See our Cloud Workload Identity Guide.
  • Review admin-consented permissions. Check every app registration and enterprise application with tenant-wide consent and remove permissions the vendor does not need. See our SaaS and OAuth App Governance Guide.
  • Alert on credential changes to service principals. New secrets or certificates added to a vendor's application are a sign of takeover. Monitor Entra audit logs for them. See our ITDR Guide.
  • Prefer certificates or federation over client secrets. Where the vendor supports it, use certificate credentials or workload identity federation instead of shared secrets.
  • Ask vendors how they protect your credentials. Include secret storage, rotation and incident notification for tenant credentials in third-party risk reviews. See our Third-Party Access Guide.

Frequently asked questions

What happened in the Commvault Metallic breach?

A nation-state actor exploited CVE-2025-3928 as a zero-day in Commvault's Azure environment and may have accessed a subset of the app credentials customers of Commvault's Metallic Microsoft 365 backup service use to connect it to their tenants. Microsoft alerted Commvault from 20 February 2025, and Commvault disclosed the activity on 7 March 2025.

Was Commvault customer backup data stolen?

Commvault says its investigation found no unauthorised access to customer backup data that it stores and protects. The risk is to customers' live Microsoft 365 environments, which the exposed app credentials could reach with the permissions granted to the backup application.

What should Commvault Metallic customers do?

Commvault and CISA advise rotating the Microsoft 365 app credentials used by Commvault, revalidating application permissions, applying Conditional Access to single-tenant apps, restricting sign-ins to Commvault's IP ranges and reviewing Entra audit and sign-in logs against the published indicators.

Salesloft Drift breach 2025 · Gainsight Salesforce OAuth breach 2025 · Microsoft Midnight Blizzard breach · SaaS and OAuth App Governance Guide · Third-Party Access Guide

How NHI Mgmt Group can help

Most organisations do not know how many vendor applications hold standing access to their Microsoft 365 or SaaS tenants, or what those apps can do. We help teams inventory third-party non-human identities, cut their permissions and build rotation and monitoring around them. See our NHI Foundation Level Training Course.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org