← BACK TO FEED
data breachsocial engineeringprivate equityUNC6671identity theft

Apollo Global Got Social Engineered. SSNs Walked Out the Door.

Apollo Global Management suffered a data breach between July 6–10 after attackers used social engineering tactics to gain unauthorized access to its cloud systems, stealing sensitive personal information including names, Social Security numbers, dates of birth, and home addresses. The breach is consistent with a broader campaign targeting private equity and financial firms, with Google previously warning that an extortion-focused group called UNC6671 was posing as IT staff to harvest employee credentials. Apollo has notified law enforcement, engaged cybersecurity experts, and is offering affected individuals 24 months of credit monitoring, though key details — such as the number of people affected and which cloud platforms were compromised — remain undisclosed.

Apollo Global Management, the $1 trillion investment firm, has confirmed attackers talked their way into its cloud infrastructure and walked off with sensitive personal data including Social Security numbers. The disclosure, filed with California's attorney general, describes a "social engineering incident" running from July 6 to 10 that gave unauthorised parties access to "certain cloud platforms."

Apollo is staying tight-lipped on which platforms were hit, how the attackers got in, and how many people are affected. What it has confirmed is that names, dates of birth, contact details, home addresses, and Social Security numbers were all potentially in scope. The investigation reached that conclusion on August 12.

The company says it has found no evidence of the stolen data appearing publicly or being used for fraud. Affected individuals are being offered two years of credit monitoring. Standard breach-response playbook, executed on schedule.

The timing is awkward. Weeks before this disclosure, Google published a warning about a financially motivated threat group called UNC6671, also going by the name BlackFile, which had been targeting private equity firms and other financial sector outfits. Reuters named Apollo, Blackstone, Bridgewater, and Bain Capital as firms in the group's crosshairs. At the time it was unclear whether any attacks had actually succeeded. Apollo's filing answers that question, at least for itself.

Apollo hasn't officially attributed the breach to UNC6671, but its notification does something interesting: it explicitly frames the incident as part of a broader pattern, noting that "similar to other financial services firms, Apollo recently experienced a social engineering incident." Draw your own conclusions.

According to Google's research, UNC6671's method is straightforward and unpleasantly effective. Attackers phone employees on their personal numbers, impersonate colleagues or IT support, then direct them to fake login pages designed to harvest credentials and MFA codes. Once inside, they extract corporate data and demand payment to keep it quiet. Some ransoms have reportedly hit $750,000.

Apollo isn't alone in being burned by this approach. Earlier this month Levi Strauss disclosed that social engineers had compromised three employees' company-issued machines and stolen corporate data. Going after humans rather than hammering at technical defences is, apparently, working just fine.

What remains unclear in Apollo's case is whose Social Security numbers were exposed. Employees? Investors? Former staff? The company isn't saying, which makes it rather difficult for anyone to assess how worried they should be. People with any connection to Apollo have good reason to keep an eye on their credit files regardless.

READ NEXT
Levi Strauss Hit by Social Engineering Attack, Corporate Data Walked Out the DoorHeights Finance Breach Exposes Data of 1.2 Million BorrowersClover Health Investments Hit by Social Engineering Attack, Patient Data Exposed