Apollo Confirms Data Breach After Social Engineering Attack
Apollo Global Management confirmed a cloud data breach after a social engineering attack exposed names, addresses, birth dates and Social Security numbers.
Private equity giant Apollo Global Management has confirmed a data breach after attackers used social engineering to gain unauthorised access to parts of the company’s cloud environment and steal sensitive personal information.
According to Apollo’s breach notification filed with the California Attorney General, the unauthorised access occurred between July 6 and July 10. Apollo said it discovered the incident, notified law enforcement and brought in outside cybersecurity and forensic specialists.
Apollo breach exposed Social Security numbers
The company determined on Aug. 12 that affected information could include names, dates of birth, contact information, home addresses and Social Security numbers. Apollo said it had no evidence at the time of notification that the information had been publicly posted or used for identity theft or fraud.
The notice does not identify whether the affected individuals were Apollo employees or people connected to companies in its portfolio. Apollo, which manages about $938 billion in assets, reported roughly 5,000 employees in its latest annual regulatory filing.
Apollo is offering affected individuals 24 months of complimentary credit monitoring and identity protection services while its investigation continues.
The breach follows a campaign targeting financial firms
The disclosure comes shortly after Google Threat Intelligence Group warned about UNC6671, a financially motivated operation targeting private equity firms, financial services companies and other businesses through voice phishing and fake login portals.
Google said attackers have operated under several extortion brands, including Redact, Pink, Helix and Falcon. Their tactics often involve calling employees while impersonating IT help desk staff, directing them to spoofed authentication sites and intercepting passwords and multifactor authentication credentials before stealing data from cloud services.
Reuters previously identified Apollo among companies targeted by malicious websites linked to the campaign, alongside Blackstone, Bridgewater Associates, Bain Capital, KKR and other financial firms. At the time, Reuters could not determine which attempted intrusions had succeeded.
Google said the group typically begins ransom negotiations with demands of $1 million to more than $3 million. In more than half of the tracked cases reviewed between January and May, final payments averaged about $750,000.
Apollo’s filing now confirms that the firm suffered a successful intrusion involving cloud-stored personal information, though it does not publicly attribute the breach to UNC6671 or any particular extortion group.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0