← BACK TO FEED
TAG

unc66713 articles

Apollo Global Got Social Engineered. SSNs Walked Out the Door.

Apollo Global Management suffered a data breach between July 6–10 after attackers used social engineering tactics to gain unauthorized access to its cloud systems, stealing sensitive personal information including names, Social Security numbers, dates of birth, and home addresses. The breach is consistent with a broader campaign targeting private equity and financial firms, with Google previously warning that an extortion-focused group called UNC6671 was posing as IT staff to harvest employee credentials. Apollo has notified law enforcement, engaged cybersecurity experts, and is offering affected individuals 24 months of credit monitoring, though key details — such as the number of people affected and which cloud platforms were compromised — remain undisclosed.

25 Aug 2026

Meet Ransom Busters: The Ransomware Affiliate Posing as Your Rescuer While Charging $60K for the Privilege

A ransomware affiliate known as **Ransom Busters** is targeting victim organizations with unsolicited emails, claiming to have hacked ransomware groups' servers and offering to delete stolen data in exchange for fees of $20,000–$60,000. Cybersecurity firm GuidePoint found strong technical evidence — including shared tools, identical passwords, and the same attacker hostname across multiple incidents — suggesting the group is itself a ransomware affiliate rather than any legitimate third party, essentially running a secondary extortion scheme against victims already attacked by groups like DragonForce. Experts warn that paying such actors provides no guarantee data will be deleted and should be treated as a scam. The article also highlights the **broader ransomware landscape**, which is growing more fragmented and sophisticated, with 93 active groups recorded in Q2 2026, 2,139 organizations listed on data leak sites, and average ransom payments surging 176% to nearly $1.9 million — driven largely by data exfiltration-focused extortion rather than traditional encryption attacks.

19 Aug 2026

Levi Strauss Hit by Social Engineering Attack, Corporate Data Walked Out the Door

Levi Strauss & Co disclosed a cyberattack in an SEC filing, revealing that social engineering was used to compromise three employees' company-issued computers, resulting in corporate data being accessed and exfiltrated. The company says it has contained the incident and evicted the attackers, with no customer data or business operations appearing to have been affected. The investigation is ongoing, and unconfirmed reports suggest the hacking group UNC6671, known for voice phishing campaigns, may have been responsible.

10 Aug 2026