Key Takeaways
- Apollo Global Management confirmed a social‑engineering breach that gave attackers access to its cloud platforms from July 6‑10, 2024.
- The compromised data includes names, dates of birth, contact information, home addresses, and Social Security numbers.
- Apollo has found no evidence that the data has been posted publicly or used for fraud, but it is offering affected individuals 24 months of credit‑monitoring and identity‑theft protection.
- The incident mirrors a recent wave of credential‑harvesting attacks targeting private‑equity firms, notably the UNC6671 (“BlackFile”) group, which uses phone‑based impersonation and spoofed login pages.
- While Apollo has not directly attributed the breach to UNC6671, its disclosure notes the similarity to attacks on other financial‑services firms and highlights the growing threat of employee‑focused social engineering.
Background of the Disclosure
Apollo Global Management revealed the breach in a filing with California’s Attorney General on August 12, 2024. The filing described the event as a “social engineering incident” that resulted in unauthorized access to certain cloud platforms. The company stated that the intrusion occurred over a four‑day window, from July 6 through July 10, and that its investigation concluded on the date of the filing that specific personal data had potentially been compromised. Apollo did not disclose which cloud services were affected, the exact method used by the attackers, or the total number of individuals impacted.
Data Exposed in the Incident
According to Apollo’s investigation, the information that may have been accessed includes full names, dates of birth, contact details (such as email addresses and phone numbers), home addresses, and Social Security numbers. This combination of data is particularly valuable for identity theft because it enables attackers to open financial accounts, file fraudulent tax returns, or conduct other forms of fraud in the victims’ names. The firm emphasized that, to date, there is no indication that the stolen data has been leaked online or actively used for fraudulent purposes.
Response Measures Offered to Affected Individuals
In an effort to mitigate potential harm, Apollo is providing 24 months of complimentary credit‑monitoring and identity‑protection services to anyone whose information may have been exposed. The company also reported that it promptly notified law enforcement, enlisted external cybersecurity and forensic experts, strengthened its internal security protocols, and launched a thorough investigation. Matthew Breitfelder, Apollo’s global head of human capital, outlined these steps in the breach notification, underscoring the firm’s commitment to protecting affected individuals and tightening defenses against future incidents.
Context Within a Wider Attack Trend
The Apollo breach fits into a broader pattern of cyber‑attacks that target employees rather than attempting to breach technical defenses directly. Earlier in July 2024, Levi Strauss disclosed that social engineers had compromised three employees’ company‑issued computers and exfiltrated corporate data. Similarly, Google’s Threat Analysis Group warned that the extortion‑focused group UNC6671—also known as “BlackFile”—had been targeting private‑equity and financial‑services firms, including Apollo, Blackstone, Bridgewater, and Bain Capital. Google reported that UNC6671 typically calls employees on their personal phones, pretends to be a colleague or IT support staff, and directs victims to spoofed login pages designed to harvest credentials and multi‑factor authentication (MFA) codes.
Tactics Employed by the Attackers
The social‑engineering technique described by Google involves voice‑based phishing (vishing) where attackers use convincing impersonation to trick employees into divulging login credentials or approving MFA prompts. Once inside the network, the threat actors can move laterally, access cloud environments, and exfiltrate sensitive data. In Apollo’s case, the attackers apparently succeeded in gaining entry to unspecified cloud platforms during the July 6‑10 window, although the firm has not released technical details about how the credentials were obtained or which specific services were compromised.
Attribution and Unanswered Questions
Apollo’s notification stops short of explicitly attributing the breach to UNC6671 or any other threat actor. However, the firm deliberately links its incident to “similar attacks elsewhere,” stating that it “recently experienced a social engineering incident” akin to those seen at other financial‑services firms. This phrasing suggests a recognition of a shared threat landscape while preserving flexibility in any ongoing investigation. Several key details remain unknown: the exact number of individuals whose Social Security numbers were exposed, the specific cloud services that were breached, and whether any data has already been sold or used in illicit markets.
Implications for the Financial Sector
The incident highlights the increasing effectiveness of employee‑centric attacks against high‑value targets such as private‑equity firms and asset managers. Traditional perimeter defenses—firewalls, intrusion detection systems, and endpoint antivirus—are less effective when attackers bypass them by exploiting human trust. Consequently, organizations are urged to invest in robust security‑awareness training, implement strict verification protocols for phone‑based requests, adopt phishing‑resistant MFA solutions, and enforce least‑privilege access controls on cloud resources. Continuous monitoring for anomalous login activity and rapid incident‑response capabilities are also critical to limit the dwell time of attackers, as demonstrated by the four‑day window in the Apollo case.
Conclusion and Outlook
Apollo Global Management’s disclosure serves as a stark reminder that even sophisticated financial institutions remain vulnerable to well‑crafted social‑engineering schemes. While the firm has taken immediate remedial steps and is offering protective services to potentially affected individuals, the breach underscores the need for a holistic security strategy that blends technology, policy, and human‑factor defenses. As threat groups like UNC6671 refine their tactics, the financial sector must stay vigilant, continually update its safeguards, and foster a culture where employees are both the first line of defense and a well‑informed checkpoint against credential‑harvesting attacks.

