Apollo Global Management reveals cloud data breach
Apollo disclosed a social engineering attack that accessed cloud platforms July 6–10, possibly exposing names, contact information and Social Security numbers. Affected individuals are offered identity protection and credit monitoring.
Apollo Global Management disclosed a social engineering attack that allowed unauthorized access to some of its cloud platforms between July 6 and July 10. The firm’s notice to affected individuals said names, contact information and Social Security numbers may have been exposed. Impacted people have been offered identity protection and credit monitoring services while an internal investigation continues.
Apollo has not identified the attackers and reported no evidence that the potentially compromised information was published or used for fraud. The company did not disclose how many people were affected. Apollo manages about $1.05 trillion in assets.
Security researchers have linked the intrusion to a cybercrime group tracked as UNC6671, also known as BlackFile. The group uses phone-based social engineering, commonly called vishing, to impersonate IT helpdesk staff and trick employees into providing credentials, multi-factor authentication codes or remote access.
Researchers say the group has operated across North America, Australia and the U.K. and recently broadened its targets to include private equity, financial services and professional services firms. Observed phishing infrastructure, domain registrations and reported intrusion attempts have tied the group’s activity to a number of major investment and financial organizations.
Names researchers have associated with the campaign include Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital and CME Group, as well as hedge funds such as Point72, Citadel, Two Sigma and Millennium Management. Those listings reflect observed targeting; public disclosures so far confirm a successful data compromise only in Apollo’s case, and several listed organizations have reported detecting or blocking attempts without evidence of data theft.
A threat intelligence team reported more than $10 million in Bitcoin payments to infrastructure linked to the campaign between January and May. Vishing attacks typically seek access to cloud systems that store employee and client records. Firms that handle such data commonly offer credit monitoring and identity protection while conducting forensic reviews. Regulators and impacted individuals are awaiting results from Apollo’s ongoing investigation.








