$1T investment giant Apollo breached after social engineering attack
Hackers spent four days inside the org's cloud platforms after apparently talking their way in
Apollo Global Management, a $1 trillion investment firm, announced a breach in its cloud systems after attackers used social engineering tactics to gain unauthorized access. The incident occurred between July 6 and July 10, and the company has not disclosed the exact number of individuals affected or the specific cloud platforms compromised.
The potentially exposed information includes names, dates of birth, contact details, home addresses, and Social Security numbers. Apollo has found no evidence of the data being publicly distributed or used for identity theft or fraud. Affected parties are being offered 24 months of credit monitoring and identity protection services.
Upon discovering the breach, Apollo immediately notified law enforcement, hired outside cybersecurity and forensic experts, strengthened their security measures, and initiated an investigation. This breach comes in the wake of Google's warning that the UNC6671 extortion group, also known as BlackFile, was targeting private equity firms and other financial institutions, including Apollo, Blackstone, Bridgewater, and Bain Capital.
Google reported that UNC6671 has been impersonating colleagues and IT support staff, directing employees to counterfeit login pages in order to steal credentials and multi-factor authentication codes. Once inside, the attackers pilfer corporate data and threaten to expose it unless a ransom is paid.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.