Apollo confirms breach as hackers set their sights on financial sector

Apollo Global Management has reported a data breach exposing personal, sensitive information of an undisclosed number of victims.
Apollo Global Management is a New York-based private equity firm specializing in investments in credit, private equity, infrastructure, secondaries, and real estate markets, with additional offices in North America, Asia, Africa, and Europe.
The firm employs over 2,540 workers and made $31.8 billion in revenues last year.
According to a data breach notification addressed to Rob Bonta, Attorney General for the State of California, the company recently experienced a “social engineering incident,” without providing any details on what exactly happened.
“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” Apollo states.
The data breach notification says that an unauthorized party managed to gain access to some cloud platforms between July 6th and July 10th. The company got wind of this on August 12th.
The attackers may have potentially stolen personal and sensitive information, including names, dates of birth, contact information, home addresses, and Social Security numbers.
The private equity firm says there’s no evidence that any of the potentially exfiltrated information has been used for identity theft or fraud. However, as a precaution, Apollo is offering affected victims third-party identity protection and credit monitoring services.
Victims are recommended to be vigilant for phishing attempts, identity theft, and other fraudulent activities.
Apollo Global Management appears to be one of the victims of a campaign conducted by a cybercrime operation known as BlackFile or UNC6671.
Members pretend to be IT support in an attempt to steal login credentials or session tokens by sending employees of targeted companies to fraudulent login pages. Once they gain access to their target’s cloud services, they exfiltrate corporate data for extortion.
Other private equity and investment firms targeted by BlackFile include Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, and CME Group, as well as hedge funds such as Point72, Citadel, Two Sigma, and Millennium Management.