Commvault says it's time to rethink resiliency as AI crooks leave victims in a 'dark, dead' state
Commvault says AI-driven attacks are moving past file encryption into full VM and hypervisor wipeouts, forcing a rethink of recovery planning.
Intelligence analysis by GPT-5.4 Mini

Commvault says frontier AI is helping attackers find more bugs faster and hit disclosed flaws within minutes. The company argues businesses must test whether they can really restore cleanly after an attack, not just assume backups are enough.
The story says hackers are now acting like vandals who not only break the locks, but also smash the whole building. Commvault says companies need to practice rebuilding from safe copies in a separate room, because fixing everything can take days.
Analysis
What Commvault is warning about
Commvault CTO Brian Brockway says AI-enabled attackers are now causing damage that goes well beyond encrypting files. In the cases he described, victims lose control of entire VM environments, including hypervisors, and end up in a “dark, dead” state where core infrastructure has to be rebuilt from scratch.
Why backup alone is not enough
The company’s main point is that backup plans need to be treated like software systems themselves: they must be tested, isolated, and designed for real recovery conditions. Commvault recommends checking whether critical systems can be restored cleanly, whether recovery environments are separated from compromised production systems, and whether recovery plans cover the most important applications and dependencies.
Brockway says air-gapping is only the starting point. He argues organizations should keep immutable copies of critical data separate from production identity, network, and management planes, then pressure-test recovery time and recovery point targets against realistic attack scenarios.
AI changes the workload
Commvault also says frontier models are increasing the volume of vulnerability findings and shrinking the time between disclosure and exploitation. Brockway says that flood of signals creates extra remediation work, pulls engineers off planned releases, and can overwhelm downstream teams.
To cope, he says organizations need prioritized restoration order for systems they cannot operate without, such as identity, billing, operational databases, and cloud services. He also says newer AI-era dependencies like data pipelines, model repositories, vector databases, and agentic workflows have to be included in recovery plans.
The practical message
Commvault’s advice is to rehearse recovery in isolated cleanroom environments before an incident happens, so teams can quickly clone and restore the application stack instead of discovering gaps during a real crisis.
Key points
- AI-enabled attackers are increasingly going after full virtual infrastructure, not just files.
- Commvault says recovery plans must be tested, isolated, and able to restore systems cleanly.
- Air-gapped, immutable backups are presented as a baseline, not a complete answer.
- The company argues that identity, billing, databases, and cloud services must be restored in priority order.
- AI is also flooding teams with vulnerability findings and increasing remediation workload.
If companies follow this advice, they may recover faster after a serious attack and avoid rebuilding from scratch under pressure. Better isolation and cleanroom testing could also make backup systems more trustworthy when a real incident happens.
If companies keep treating backups as enough on their own, a wipeout of virtual machines and hypervisors could leave them unable to restart quickly. The added AI-driven vulnerability noise could also pull engineers away from planned work and slow defenses when time matters most.



