A major private equity firm has fallen victim to a sophisticated social engineering attack that exposed sensitive personal information. Apollo Global Management, which manages over $1 trillion in assets, has disclosed a data breach that compromised names, contact details, and Social Security numbers of its clients.
The breach is believed to have been carried out by the BlackFile cybercrime group, which has been using IT helpdesk-themed vishing attacks to target organizations across North America, Australia, and the UK. According to researchers, the group has been highly successful in evading detection, with some reports suggesting that they received over $10 million in Bitcoin ransom payments between January and May.
The investigation into the breach is ongoing, but Apollo has confirmed that personal information may have been compromised during a brief period of unauthorized access to its cloud platforms. While there is no evidence to suggest that the stolen data has been made public or used for fraudulent purposes, affected individuals are being offered identity protection and credit monitoring services as a precautionary measure.
Apollo’s breach is not an isolated incident. The BlackFile group appears to be targeting organizations in the private equity, financial services, and professional services sectors. Several firms have reportedly detected attempts by the hackers, but Apollo is so far the only confirmed victim of a successful data compromise. Other targeted organizations include well-known private equity and investment firms such as Blackstone, Bain Capital, and KKR.
The breach highlights the ongoing threat posed by sophisticated social engineering attacks. These types of attacks often rely on psychological manipulation rather than technical vulnerabilities, making them challenging to detect and prevent. Organizations must remain vigilant in protecting themselves against these threats, investing in robust cybersecurity measures and employee training programs that can help prevent such incidents.
For individuals who may have been affected by the breach, it is essential to be cautious when receiving unsolicited communications from companies or organizations. If you receive a suspicious email or phone call claiming to be from a reputable firm, do not engage with the sender. Instead, contact the company directly through official channels to verify the authenticity of the communication.
By staying informed and taking proactive steps to protect yourself online, you can reduce your risk of falling victim to these types of attacks. As cybersecurity threats continue to evolve, it is essential for both organizations and individuals to prioritize their security and take necessary measures to safeguard sensitive information.
Source: SecurityWeek — 2026-08-24