Apollo Global Hit by Social Engineering Attack Exposing Names, Contacts and SSNs
Apollo Global Management, the private equity behemoth sitting on roughly $1.05 trillion in assets under management, has confirmed a data breach that exposed personal information belonging to an undisclosed number of individuals.
The attack took place between 6 and 10 July, when threat actors used social engineering to worm their way into some of Apollo's cloud platforms. The company says it only recently determined that names, contact details, and Social Security numbers may have been compromised. An investigation is still ongoing.
Apollo hasn't named any suspects, but says there's currently no evidence the stolen data has been published or used for fraud. Affected individuals are being offered the standard post-breach consolation prize: identity protection and credit monitoring services.
The incident fits a pattern researchers have been tracking for months. A cybercrime group known as UNC6671 or BlackFile, which surfaced in early 2026, has been running IT helpdesk-themed voice phishing (vishing) attacks across North America, Australia, and the UK. The group has recently rebranded, shifted its focus toward financial services, private equity, and professional services firms, and is apparently doing quite well for itself.
Google's Threat Intelligence Group reported the group pulled in over $10 million in Bitcoin ransom payments between January and May alone.
Apollo appears to be one of several major financial firms in the crosshairs. Researchers tracking BlackFile's infrastructure and domain registrations have identified a long list of apparent targets including Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, CME Group, Point72, Citadel, Two Sigma, and Millennium Management. Worth being clear though: that list reflects observed targeting activity, not confirmed breaches. Several of those organisations have said they detected and blocked attempts with no data loss.
For now, Apollo is the only firm to have publicly confirmed a successful compromise.