$1T investment giant Apollo breached after social engineering attack
Hackers spent four days inside the org's cloud platforms after apparently talking their way in
Apollo Global Management, a $1T investment firm, has admitted to a social engineering attack that compromised its cloud systems, resulting in unauthorized access to personal data. The breach, disclosed in a notification to California's attorney general, occurred between July 6 and July 10. While the exact number of affected individuals remains undisclosed, Apollo confirmed that the stolen information included names, dates of birth, contact details, home addresses, and Social Security numbers.
The company has not found evidence of the data being publicly posted or used for identity theft or fraud. Affected individuals are being offered 24 months of credit monitoring and identity protection services. Apollo's global head of human capital, Matthew Breitfelder, stated that the company promptly notified law enforcement, engaged cybersecurity experts, enhanced security protocols, and launched an investigation upon detecting the incident.
This breach follows reports that UNC6671, a cybercriminal group known for extortion, was targeting private equity firms and financial-sector companies, including Apollo, Blackstone, Bridgewater, and Bain Capital. While the company has not attributed the breach to UNC6671, the notification highlights the incident as part of a series of similar attacks on financial services firms.
Google revealed that UNC6671 targets employees by impersonating colleagues or IT support staff, leading them to fraudulent login pages to steal credentials and multi-factor authentication codes. The breach highlights the increasing trend of cybercriminals targeting employees rather than attempting to breach corporate defenses directly.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.