Apollo Global Data Breach: Personal Information and SSNs Exposed – Veri Sızıntısı
Veri Sızıntısı
Veri Sızıntısı
Free on Google Play
Open

Investment Giant Apollo Global Rocked by Data Breach

Private equity firm Apollo Global Management, which manages over a trillion dollars in assets, confirmed that sensitive personal data was leaked following a social engineering attack in July. The cybercrime group known as BlackFile, which targets the financial sector, is believed to be behind the attack.

A digital lock symbolizing cybersecurity and data breach over the Apollo Global Management logo.

What Happened

Apollo Global Management, one of the largest players in the financial world with approximately $1.05 trillion in assets under management, has announced that it has been the victim of a serious cyberattack. According to a data breach notification sent to affected individuals, attackers gained unauthorized access to some of the company's cloud platforms between July 6 and July 10. The attack is believed to have been carried out by a sophisticated cybercrime gang targeting financial institutions.

Following the discovery of the incident, Apollo immediately launched an internal investigation and worked with cybersecurity experts to determine the scope and impact of the breach. While the investigation is ongoing, initial findings indicate that the attackers used social engineering tactics to achieve their objectives. This development once again highlights how even companies with the most robust digital defense systems can be compromised through human factor vulnerabilities. The group behind the attack is thought to be UNC6671, or BlackFile as it has been rebranded, which emerged in early 2026 and has recently focused its activities on the financial and private equity sectors. This group is known for its vishing (voice phishing) attacks, specifically impersonating IT helpdesk staff.

Data Exposed

According to the official statement from Apollo Global Management, the data compromised by the cyberattackers includes highly sensitive personal information. Based on information confirmed in the initial phase of the investigation, the leaked data includes:

  • Full Names: A fundamental piece of information for identity verification and other fraudulent activities.
  • Contact Information: Data such as phone numbers and email addresses can be used to launch more sophisticated phishing and vishing attacks against the victims.
  • Social Security Numbers (SSNs): This is perhaps the most critical type of data. In the U.S., an SSN is a key that can be used for identity theft, opening new credit accounts, filing fraudulent tax returns, and many other illegal activities.

The company stated that it has found no evidence that the leaked data has been shared on public platforms or used for fraudulent purposes so far. However, this does not mean the data will not be sold or used on underground forums in the future. Such sensitive data is highly valuable to cybercriminals and is often sold in identity theft packages on the dark web. The number of individuals affected has not yet been disclosed by the company.

How the Attack Occurred

According to information in the source article, the attack was carried out using a sophisticated social engineering method. This method involves IT helpdesk-themed voice phishing (vishing) attacks, which have become a signature of the BlackFile cybercrime group. Vishing is a type of phishing conducted over the phone. Attackers try to deceive employees by pretending to be from the company's IT department or a trusted technical support provider.

In this scenario, it is likely that the attackers called Apollo employees, claiming there was an urgent technical issue or a system update was needed. Under this pretext, they may have asked employees to share their login credentials (username and password), multi-factor authentication codes, or to install remote access software on their computers. By exploiting a moment of carelessness or an employee's willingness to help, the attackers gained access to certain systems within the company's cloud infrastructure. This attack vector, which targets human psychology rather than technical vulnerabilities, can bypass even the most advanced firewalls and antivirus software.

Who Is Affected

Apollo Global Management has not provided a clear number on how many individuals or which groups (employees, clients, investors) were affected by the data breach. The company has only stated that it is directly notifying the individuals whose personal information was compromised.

However, this attack is just one part of a broader cybercrime campaign. The BlackFile group is known to target numerous organizations across North America, Australia, and the UK. Researchers and cybersecurity reports, based on the group's phishing infrastructure and domain registrations, indicate a target list of giants in the finance and investment world. Besides Apollo, this list includes private equity and investment firms such as Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, and CME Group, as well as hedge funds like Point72, Citadel, Two Sigma, and Millennium Management. It is important to note that while these companies were targeted, none other than Apollo have been publicly confirmed to have been breached. In fact, many of the named entities have stated that they successfully detected or blocked the attempts and have found no evidence of data theft.

What You Can Do

If you have received a notification from Apollo Global Management that you were affected by the data breach, or if you are concerned about this possibility, you should act immediately to protect your identity and financial information:

  • Freeze Your Credit Reports: The leak of your Social Security Number (SSN) maximizes the risk of identity theft. Contact the three major credit bureaus in the U.S. (Equifax, Experian, TransUnion) to freeze your credit reports for free. This prevents fraudsters from opening new credit cards or loan accounts in your name.
  • Set Up a Fraud Alert: You can add a fraud alert to your credit reports. This alert requires creditors to take extra steps to verify your identity when a new credit application is made.
  • Use the Services Offered by the Company: Be sure to sign up for the free identity protection and credit monitoring services offered by Apollo. These services will alert you to suspicious activity in your name and provide support in the event of identity theft.
  • Monitor Your Accounts: Regularly check all your bank, credit card, and investment accounts. If you see any transactions you do not recognize, contact the relevant financial institution immediately.
  • Be Wary of Phishing Attacks: Since your contact information has been leaked, you may be targeted with an increase in phishing emails or vishing calls. Be extremely cautious of unsolicited calls and emails that ask for your information or direct you to click on suspicious links.

What the Company Is Saying

Apollo Global Management has issued a statement confirming the incident and outlining the steps being taken for affected individuals. The company stated that upon discovering the event, they launched a comprehensive investigation involving cybersecurity experts. "While the investigation is ongoing, we have determined that the attackers may have accessed certain personal information," the statement read. The company emphasized that there is no evidence that the compromised information has been misused or made public. To minimize potential harm to victims, identity protection and credit monitoring services are being offered to all affected individuals, as noted in the company's official notification.

Source

https://www.securityweek.com/personal-information-exposed-in-apollo-global-data-breach/

This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.

Weekly Newsletter

Curated data breach news delivered to your inbox every week.

Argus

Scheduled Maintenance Notice

August 29, 2026, 00:00 – 05:00 (UTC+3)

A scheduled maintenance will be performed for infrastructure security updates and performance improvements. The following services will be temporarily unavailable during this period.

  • Breach Search
  • Argus LiveStream
  • API Services
  • HUBOne Account Management

Your data is safe — this maintenance is solely for security updates and system optimization.