← BACK TO FEED
data breachsocial engineeringprivate equityvishingBlackFile

Apollo Global Hit by Social Engineering Attack Exposing Names, Contacts and SSNs

Apollo Global Management suffered a data breach after a social engineering (vishing) attack allowed threat actors to access its cloud platforms between July 6–10, potentially exposing personal information including names, contact details, and Social Security numbers. The attack is linked to a cybercrime group known as BlackFile (UNC6671), which has been targeting major financial and private equity firms across North America, Australia, and the UK using IT helpdesk-themed phone phishing tactics. While Apollo is the only confirmed victim of a successful data compromise so far, Apollo states there is no evidence the stolen data has been made public or used for fraud, and affected individuals are being offered identity protection services.

Apollo Global Management, the private equity behemoth sitting on roughly $1.05 trillion in assets under management, has confirmed a data breach that exposed personal information belonging to an undisclosed number of individuals.

The attack took place between 6 and 10 July, when threat actors used social engineering to worm their way into some of Apollo's cloud platforms. The company says it only recently determined that names, contact details, and Social Security numbers may have been compromised. An investigation is still ongoing.

Apollo hasn't named any suspects, but says there's currently no evidence the stolen data has been published or used for fraud. Affected individuals are being offered the standard post-breach consolation prize: identity protection and credit monitoring services.

The incident fits a pattern researchers have been tracking for months. A cybercrime group known as UNC6671 or BlackFile, which surfaced in early 2026, has been running IT helpdesk-themed voice phishing (vishing) attacks across North America, Australia, and the UK. The group has recently rebranded, shifted its focus toward financial services, private equity, and professional services firms, and is apparently doing quite well for itself.

Google's Threat Intelligence Group reported the group pulled in over $10 million in Bitcoin ransom payments between January and May alone.

Apollo appears to be one of several major financial firms in the crosshairs. Researchers tracking BlackFile's infrastructure and domain registrations have identified a long list of apparent targets including Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, CME Group, Point72, Citadel, Two Sigma, and Millennium Management. Worth being clear though: that list reflects observed targeting activity, not confirmed breaches. Several of those organisations have said they detected and blocked attempts with no data loss.

For now, Apollo is the only firm to have publicly confirmed a successful compromise.

READ NEXT
Apollo Global Got Social Engineered. SSNs Walked Out the Door.Levi Strauss Hit by Social Engineering Attack, Corporate Data Walked Out the DoorClover Health Investments Hit by Social Engineering Attack, Patient Data Exposed