identity theft4 articles
Apollo Global Got Social Engineered. SSNs Walked Out the Door.
Apollo Global Management suffered a data breach between July 6–10 after attackers used social engineering tactics to gain unauthorized access to its cloud systems, stealing sensitive personal information including names, Social Security numbers, dates of birth, and home addresses. The breach is consistent with a broader campaign targeting private equity and financial firms, with Google previously warning that an extortion-focused group called UNC6671 was posing as IT staff to harvest employee credentials. Apollo has notified law enforcement, engaged cybersecurity experts, and is offering affected individuals 24 months of credit monitoring, though key details — such as the number of people affected and which cloud platforms were compromised — remain undisclosed.
Heights Finance Breach Exposes Data of 1.2 Million Borrowers
Consumer lender Heights Finance Holdings suffered a data breach in early May when hackers accessed a third-party cloud-based storage platform, compromising the personal and financial information of over 1.2 million individuals. Stolen data includes names, Social Security numbers, bank account details, and other sensitive information belonging to current and former borrowers. Heights has secured the platform, notified federal law enforcement, and is offering affected individuals 24 months of free credit monitoring and identity protection services.
Belgian eID Software Had Holes Big Enough to Sign Away Your Life
Security researcher James Arnott discovered critical vulnerabilities in Belgium's Connective eID software, used by over two million people across major banks and government agencies, which failed to verify which websites could communicate with the application. The flaws allowed malicious websites to silently read card details, trick users into revealing their PINs via spoofed prompts, forge legally binding electronic signatures, and even execute remote code on victims' machines without any special permissions. Nitro Software Belgium fully patched the vulnerabilities 146 days after the initial report and awarded a $200 bug bounty, with no CVEs assigned.
EY Breach Exposes Client Tax Data Including SSNs and Card Numbers
Ernst & Young (EY) has begun notifying clients of a data breach involving a third-party service management platform used for tax-related work, with hackers gaining access between March 28 and April 12 after the incident was discovered on April 23. The compromised data includes sensitive personal and financial information such as names, addresses, Social Security numbers, and credit/debit card numbers. EY states it is unaware of any misuse of the data and is offering affected clients two years of free credit monitoring and identity protection services.