$1T investment giant Apollo breached after social engineering attack
Apollo Global Management, the $1 trillion investment firm, has disclosed that hackers gained unauthorised access to some of its cloud platforms between 6 and 10 July after a successful social engineering attack. The company reported the breach to California's attorney general, confirming that intruders spent four days inside its systems and accessed personal data including names, dates of birth, contact details, home addresses and Social Security numbers. Apollo has not disclosed how many people are affected or which systems were compromised, but says there is no evidence so far that the stolen data has been leaked or misused.
The incident follows a warning from Google that a financially motivated extortion group known as UNC6671, or "BlackFile", has been targeting private equity and financial firms by phoning employees on personal devices while posing as colleagues or IT staff, then directing them to fake login pages to harvest credentials. Reuters had previously named Apollo, alongside Blackstone, Bridgewater and Bain Capital, as a target of this campaign, though it was unclear at the time whether any attempts had succeeded. Apollo has not formally attributed the breach to UNC6671 but noted its incident was "similar to other financial services firms". Affected individuals are being offered 24 months of free credit monitoring and identity protection.
- Apollo Global Management hit by social engineering breach, 6-10 July
- Names, addresses and Social Security numbers potentially exposed
- Attack mirrors a wider campaign targeting private equity firms