Apollo Global Management confirms major data breach
Private equity firm Apollo confirms data breach amid hacking wave
TechCrunch reports that Apollo Global Management, a private equity giant overseeing $938 billion in assets, has acknowledged a security incident in which attackers extracted personal information from its cloud infrastructure.
The intrusion took place between July 6 and July 10. The attackers employed social engineering tactics, impersonating IT help desk personnel to deceive employees into providing passwords and multi-factor authentication codes through fake login pages. The compromised data includes names, dates of birth, home addresses, and Social Security numbers.
Apollo's human resources chief Matthew Breitfelder disclosed the breach in a notification to California's attorney general. The filing did not clarify whether the affected individuals are Apollo staff or employees of companies Apollo owns.
This incident is part of a broader extortion campaign aimed at financial and private equity firms. Google's threat researchers had previously flagged the threat actors — known by aliases Falcon, Helix, Pink, and Redact. Other targeted organizations include Blackstone, Bridgewater, and Bain Capital. According to Google, some victims have paid ransoms as high as $750,000.
The breach underscores a rising trend of sophisticated social engineering attacks against the financial sector, with adversaries increasingly adept at impersonating internal IT support to defeat multi-factor authentication.