All incidents

Apollo Global Management data breach via social engineering

breachopenAug 24, 2026 — Aug 24, 2026
Apollo Global Management Hit by Social Engineering Data Breach

APOLLO Global Management disclosed a data breach stemming from a social engineering attack that exposed personal data including names, phone numbers and Social Security Numbers for individuals whose information was held between July 6 and July 10 2026. The firm said there is no sign the data has been misused publicly but is offering identity protection services.

The breach was discovered on August 24 2026 after anomalous access to an internal employee portal was flagged. Investigators said the attackers used pretext phone calls to trick staff into revealing credentials, which then allowed lateral movement to a file server holding HR records. No CVE identifiers have been assigned because the incident relies on human manipulation rather than software flaw.

The exposed records include full names, email addresses, telephone numbers and Social Security Numbers. Apollo said the data set does not contain financial account numbers or investment details. The company has begun notifying affected individuals and is providing twelve months of credit monitoring and identity theft restoration at no cost.

Security researchers linked the activity to the ransomware group BlackFile and the associated tracking reference UNC6671, which has previously targeted private equity firms and financial advisers, according to a report published by SecurityWeek. BlackFile has been observed collecting ransom payments in Bitcoin, reportedly exceeding ten million dollars in the last month, although Apollo said no ransom demand was made in this case.

The incident highlights how social engineering remains a top vector for data theft even at organisations with mature technical defences. It highlights the need for continuous staff verification processes and stricter controls over privileged access to personnel files.

Defenders should review call‑handling procedures and enforce multi‑factor authentication for all remote access points, especially those that touch employee directories. Regular phishing simulation campaigns can help staff recognise pretext calls and deceptive emails. Organisations must also ensure that access to sensitive HR data is limited to roles that absolutely require it and that logs are reviewed for unusual query patterns.

Individuals who receive notification from Apollo are encouraged to place a fraud alert on their credit files, consider a security freeze if they suspect misuse, and monitor account statements for unfamiliar transactions. The company has set up a dedicated help line and a website where affected persons can enrol in the offered credit monitoring service.

Organisations should also review their incident response plans to ensure they include specific steps for social engineering scenarios, such as verifying caller identity through secondary channels and preserving logs for forensic analysis. Engaging a third‑party breach coach can help coordinate notification, regulatory reporting and remediation efforts while preserving evidence for potential legal action.

Intelligence briefing updated Aug 24, 2026

BlackFile
Timeline Coverage

Swipe to explore timeline