Apollo Global Management Confirms Data Breach Amid Surge of Social Engineering Attacks on Financial Sector

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Apollo Global Management has confirmed that it was affected by a series of social engineering attacks targeting the financial sector last month. The private equity firm reported unauthorized access to its cloud platforms between July 6 and July 10, as detailed in a data breach notification filed in California. The company has not disclosed when it became aware of the breach or how it occurred.

Apollo is the first organization to publicly acknowledge that sensitive personal data was compromised during this wave of attacks, which have also impacted large private equity firms, law firms, financial rating agencies, and medical technology companies. While the firm did not identify the attackers, Google attributed the ongoing campaign to a group known as BlackFile, which is associated with a larger cybercrime organization called The Com.

Matthew Breitfelder, Apollo’s global head of human capital, stated in the disclosure that the company promptly notified law enforcement, engaged cybersecurity experts, and enhanced its security protocols following the incident. An investigation revealed that personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers, were compromised. However, Apollo has not disclosed the number of individuals affected and noted that there is currently no evidence that the data has been posted online or used for identity theft.

Apollo Global Management is one of the largest private equity firms globally, managing approximately $1.05 trillion in assets as of June. Reports indicate that some of Apollo’s competitors, such as Blackstone and Bain Capital, were also targeted, although it remains unclear if they were compromised.

BlackFile has been linked to attacks across various sectors, including healthcare, technology, and retail, employing tactics such as impersonating IT support in voice-phishing schemes. The group typically issues extortion demands starting around $3 million, which are often negotiated down to less than $1 million. Recent reports also suggest that victims have faced escalating threats, including swatting incidents.

For more details, refer to the full article on CyberScoop.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

GitLab Vulnerability CVE-2026-19478 Exploited in the Wild, Update Available

Advisory Date: August 18, 2026Last Updated: August 21, 2026 GitLab has reported vulnerabilities affecting several versions of its software, specifically prior to the following releases: GitLab...

First Documented Android Malware Targets Automotive Head Units for Ad Fraud

In June 2026, researchers monitoring Android threats uncovered a novel piece of malware that specifically targets automotive head units. This malware, which installs like...

VAD Technologies Highlights Path for AI-Ready Channel Partners in the Middle East

VAD Technologies Charts a Course for AI-Ready Channel Partners in the Middle East VAD Technologies is emphasizing the critical role of channel partners in navigating...

Lawmakers Request GAO Investigation into CISA Staffing Cuts and Impact on Cybersecurity Operations

Members of Congress are urging a government watchdog to investigate the impact of staffing cuts at the Cybersecurity and Infrastructure Security Agency (CISA) on...