- Security Incident: Apollo Global Management confirmed unauthorized access to its cloud platforms occurring between July 6 and July 10, 2024.
- Compromised Data: The breach exposed sensitive personal identifiable information (PII), including Social Security numbers and dates of birth, affecting a massive financial entity with over $938 billion in assets.
Social Engineering Leads to Apollo Data Breach
Private equity giant Apollo Global Management has confirmed a significant security incident involving unauthorized access to its cloud infrastructure. The breach took place over a four-day window in early July 2024. Unlike many high-profile cyberattacks that rely on software vulnerabilities, this incident was facilitated through a “vishing” (voice phishing) attack. This method of social engineering allowed attackers to bypass technical safeguards by manipulating individuals into providing access credentials.
The company, which manages over $938 billion in assets, reported that the attackers successfully reached its cloud platforms. This event coincides with a period of increased activity against large financial institutions. Security researchers often see similar tactics when hackers target security experts or corporate employees to gain a foothold in secure networks.
Stolen Information and Impacted Individuals
During the period of unauthorized access, several categories of sensitive data were extracted from Apollo’s systems. The confirmed list of stolen information includes:
- Full names
- Dates of birth
- Home addresses
- Contact information
- Social Security numbers
The exposure of Social Security numbers and other PII represents a significant risk for the affected individuals. In response to the disclosure, Apollo is offering 24 months of complimentary credit monitoring and identity protection services through Cyberscout. Users concerned about the security of their digital footprints may find it helpful to review a security guide to identify signs of unauthorized account access.
The Global Threat Environment for Private Equity
The incident at Apollo follows an explicit warning from the Google Threat Intelligence Group (GTIG). Researchers have been tracking a cybercrime collective known as UNC6671, which also operates under various brand names such as Redact, Pink, Helix, and Falcon. This group has been identified as a primary threat to the financial services sector.
Apollo is not the only firm in the crosshairs of these actors. The hacking wave has targeted several other major financial institutions, including Blackstone, Bain Capital, and KKR. While these firms have faced similar threats, Apollo is among the first to formally confirm the exposure of personally identifiable information through official channels, such as the California Dept. of Justice breach notification system.
The focus on private equity firms comes at a time when the industry is facing increased scrutiny across multiple fronts. For instance, regulatory bodies are closely monitoring institutional security standards alongside broader oversight of major investment firms. The targeting of firms with nearly a trillion dollars in assets under management suggests that threat actors are prioritizing high-value financial targets for their social engineering campaigns.
Remediation and Identity Protection
Apollo Global Management has stated that the breach was contained to the cloud platforms accessed during the July window. The firm has shifted its focus to mitigating the impact on those whose data was compromised. The provision of identity protection services is intended to provide a layer of defense against potential identity theft resulting from the stolen Social Security numbers and contact details.
As the financial industry continues to address these persistent threats, the use of vishing highlights a vulnerability that technical patches alone cannot resolve. The reliance on human interaction remains a primary target for groups like UNC6671 as they attempt to infiltrate the world’s largest investment platforms.
