Finance Giant Apollo Hit by Social Engineering Attack
Asset management giant Apollo Global Management confirmed it was a victim of a large-scale wave of cyberattacks targeting the financial sector. The company disclosed that attackers accessed personal data.
What Happened
Apollo Global Management, one of the world's largest asset management firms, officially announced on Friday that it was impacted by a series of social engineering attacks that have shaken the financial sector last month. According to a data breach notification filed by the company in California, attackers gained unauthorized access to some of the firm's cloud platforms between July 6 and July 10.
This disclosure makes Apollo the first victim to formally admit that sensitive personal data was compromised in the wave of attacks targeting private equity firms, law firms, financial rating agencies, and medical technology companies. The identity and scope of the actors behind these attacks, which are being watched with concern in the financial world, remain a subject of investigation. Apollo did not specify when or how it became aware of the intrusion and has not yet responded to requests for comment.
Data Compromised
According to Apollo's statement, an ongoing investigation determined on August 12 that attackers had accessed significant personal data. The compromised information includes highly sensitive data:
- Full names
- Dates of birth
- Contact information (phone number, email address, etc.)
- Home addresses
- Social Security numbers (SSNs)
The combination of such data poses a serious risk for identity theft and fraud. The company has not yet disclosed the number of individuals affected but stated that it has thus far found no evidence that the stolen data has been posted online or used for identity theft or fraud. Nevertheless, the possibility that such data could be used by cybercriminals in the future raises concerns.
How the Attack Happened
While Apollo did not name the group responsible for the attack, an attribution made by Google earlier this month points to the threat group "BlackFile" as being behind the ongoing campaign. BlackFile is known to be affiliated with a larger cybercrime network known as "The Com." The group recently restructured its extortion operations under four different brands: Redact, Pink, Helix, and Falcon, which reportedly share infrastructure.
The attack method relies on social engineering and voice-phishing techniques that target the human element rather than a technical vulnerability. BlackFile and its affiliates are known to contact victims by phone or other communication channels, impersonating IT support staff. After gaining trust, they persuade the victims to take steps necessary to provide access to sensitive information or infiltrate systems. Following these attacks, the group typically threatens its victims with ransom demands starting around $3 million. It has been observed that these amounts are often negotiated down to less than $1 million.
Google researchers also noted that some of the group's recent victims have been subjected to threatening messages and harassment tactics such as "swatting" (making a false report to send police to a victim's address). These tactics, frequently adopted by The Com's subgroups, are designed to exert psychological pressure on the victims.
Who Was Affected
The main institution confirmed to have had its data breached in this attack is Apollo Global Management, which managed $1.05 trillion in assets as of the end of June. The scale of the company highlights the potential impact of the attack and the seriousness of cybersecurity risks in the financial sector.
However, Apollo was not the only target of this wave of attacks. Researchers previously told CyberScoop that some of Apollo's largest competitors, including giants like Blackstone and Bain Capital, were also targeted with similar malicious infrastructure. However, it is not yet clear whether their systems were breached. BlackFile and its affiliates' activities are not limited to finance. Since the beginning of the year, they have impacted organizations in many different sectors, including healthcare, technology, transportation, logistics, wholesale, retail, and hospitality.
What You Can Do
Apollo will be directly notifying individuals affected by the data breach. However, if you believe you might be a potential victim of this type of data breach or wish to be proactive in general, you can take the following steps:
- Monitor Your Accounts: Regularly check your bank accounts, credit card statements, and other financial accounts for any suspicious activity.
- Watch Your Credit Reports: Regularly check your credit reports from the three major credit bureaus (Equifax, Experian, TransUnion) to look for suspicious accounts opened in your name. Consider placing a fraud alert or credit freeze.
- Be Wary of Phishing Attempts: Your compromised personal information could be used to create more convincing phishing emails or vishing calls targeting you. Be extremely skeptical of unsolicited requests for personal information.
What the Company Says
In the data breach notification, Matthew Breitfelder, Global Head of Human Capital at Apollo, summarized the steps the company took: "Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation."
The company's investigation is ongoing, and the full scope of the incident and the number of people affected are expected to become clearer in the coming days. This breach once again demonstrates how vulnerable even the most sophisticated financial institutions can be to human-focused social engineering attacks.
Source
https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.