Apollo discloses data breach from ongoing wave of attacks hitting financial sector

Apollo Global Management has revealed it was hit by a data breach as part of a wave of social engineering attacks targeting the financial sector. The private equity firm, which manages over $1 trillion in assets, confirmed that attackers accessed its cloud platforms between July 6 and July 10, compromising sensitive personal data.

The attack is believed to be linked to BlackFile, a threat group affiliated with The Com, which has been responsible for a series of extortion operations across multiple industries. In recent months, BlackFile and its affiliates have targeted financial institutions, law firms, medical technology companies, and other organizations, often using voice-phishing and social-engineering tactics to impersonate IT support.

According to Apollo’s data breach notification, attackers accessed personal data including names, dates of birth, contact information, home addresses, and Social Security numbers. While the company has not disclosed how many people were affected, it has assured that there is no evidence any data was posted online or used for identity theft or fraud. The incident was detected on July 10, but Apollo did not disclose when exactly it became aware of the breach.

Apollo’s disclosure marks the first time a victim of these attacks has formally acknowledged being compromised. Other affected organizations, including private equity firms Blackstone and Bain Capital, have been previously mentioned in reports as having been targeted by malicious infrastructure. However, it is unclear if they were also breached.

The threat group’s tactics are designed to extort money from its victims, with demands often starting at $3 million and being negotiated down to under $1 million. Some of the group’s recent victims have reported receiving threatening messages and other forms of escalation, including swatting incidents, which involve dispatching police or emergency services to a victim’s location.

The impact of these attacks is not limited to financial losses; they also erode trust in organizations’ ability to protect sensitive data. As the threat landscape continues to evolve, it is essential for companies and individuals to remain vigilant and take proactive measures to mitigate the risks associated with social engineering attacks.

If you’re a victim of a similar attack or suspect your organization has been compromised, don’t hesitate to contact law enforcement and engage cybersecurity experts to investigate and contain the breach. It’s also crucial to educate yourself on how to identify and avoid falling prey to these types of scams. By staying informed and taking proactive steps, we can work together to prevent such attacks from succeeding in the future.


Source: CyberScoop — 2026-08-21