Key Takeaways
- Attackers accessed some Apollo Global Management cloud platforms between July 6 and July 10, exposing personal information that included Social Security numbers.
- Apollo Global Management has found no evidence so far that the compromised data was published online or used for fraud or identity theft.
- The incident highlights the growing use of voice phishing and IT-support impersonation against financial institutions and other data-rich businesses.
Apollo Global Management has confirmed that attackers gained unauthorized access to some of its cloud platforms during a broader social engineering campaign targeting financial institutions and professional-services businesses.
The unauthorized access occurred between July 6 and July 10, according to a data breach notification Apollo Global Management filed in California. Apollo Global Management did not disclose how attackers entered the cloud environments, when the intrusion was discovered, or how many people were affected.
Apollo Global Management determined on Aug. 12 that the exposed information included names, dates of birth, contact details, home addresses, and Social Security numbers. That combination creates a durable identity risk because several of those data points are difficult or impossible for an affected person to change.
Apollo Global Management reported no evidence that the information has been published online or used for identity theft or fraud, though the firm noted this does not guarantee the copied data has been deleted or will not surface later.
“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” the global head of human capital at Apollo Global Management wrote in the disclosure notice.
While Apollo Global Management did not identify the attacker, Google attributed the wider campaign earlier in August to BlackFile, a threat group affiliated with The Com. BlackFile recently divided its extortion activity among four brands using shared infrastructure: Redact, Pink, Helix, and Falcon.
BlackFile and its affiliates reportedly impersonate IT support personnel in voice-phishing and other social engineering attacks. Once access has been obtained, the attackers move toward data theft and extortion rather than relying on a conventional malware-first intrusion. Demands often begin around a notable sum and are typically negotiated to less than $350,000 (source).
Sophisticated security technology remains vulnerable when an attacker successfully persuades an employee or support agent to reset credentials, enroll a new authentication method, or approve access. By leveraging acquired personal or organizational details to sound legitimate, attackers turn identity verification into a critical operational risk point rather than a standard help-desk routine.
Apollo Global Management reported $696 billion in assets under management at the end of June, placing it among the world’s largest private equity businesses (source). Private equity operations frequently hold highly sensitive employee, investor, portfolio-company, and transaction data across interconnected cloud services.
Researchers previously told CyberScoop that malicious infrastructure also targeted Blackstone and Bain Capital, although it remains unclear whether either firm was compromised. The broader campaign has reached healthcare, technology, transportation, logistics, wholesale, retail, and hospitality organizations since the beginning of 2024. Google researchers have also described threatening messages and swatting incidents involving some recent victims.
This incident aligns with broader threat trends in the financial sector. An ENISA finance-sector assessment recorded 488 publicly reported incidents affecting European financial entities from January 2023 through June 2024, including 432 cyberattacks and 30 coordinated campaigns. Banks represented roughly 46% of these incidents, accounting for 301 cases.
A Deloitte review of the threat landscape highlighted similar financial sector exposure, while the European Central Bank has formally addressed cybersecurity as a material concern for financial infrastructure and operations.
For security leaders, the practical response extends beyond basic phishing awareness training. Implementing stronger help-desk verification, tightly controlled account recovery, phishing-resistant authentication, active monitoring for unusual cloud sessions, and rapid revocation of suspicious credentials can reduce exposure. Incident plans aligned with the NIST Cybersecurity Framework or ISO/IEC 27001 can also help clarify responsibilities across security, legal, human resources, and communications teams.
Apollo Global Management’s investigation remains ongoing. The eventual impact will depend on the number of people affected, the specific cloud resources accessed, and whether the stolen information appears in criminal markets or later extortion activity. The disclosure provides public confirmation that this ongoing campaign has successfully moved beyond attempted targeting to compromise highly sensitive personal data.
⬇️