Apollo Global Management Confirms Data Breach Amid Surge of Social Engineering Attacks on Financial Sector

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Apollo Global Management has confirmed that it was affected by a series of social engineering attacks targeting the financial sector last month. The private equity firm reported unauthorized access to its cloud platforms between July 6 and July 10, as detailed in a data breach notification filed in California. The company has not disclosed when it became aware of the breach or how it occurred.

Apollo is the first organization to publicly acknowledge that sensitive personal data was compromised during this wave of attacks, which have also impacted large private equity firms, law firms, financial rating agencies, and medical technology companies. While the firm did not identify the attackers, Google attributed the ongoing campaign to a group known as BlackFile, which is associated with a larger cybercrime organization called The Com.

Matthew Breitfelder, Apollo’s global head of human capital, stated in the disclosure that the company promptly notified law enforcement, engaged cybersecurity experts, and enhanced its security protocols following the incident. An investigation revealed that personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers, were compromised. However, Apollo has not disclosed the number of individuals affected and noted that there is currently no evidence that the data has been posted online or used for identity theft.

Apollo Global Management is one of the largest private equity firms globally, managing approximately $1.05 trillion in assets as of June. Reports indicate that some of Apollo’s competitors, such as Blackstone and Bain Capital, were also targeted, although it remains unclear if they were compromised.

BlackFile has been linked to attacks across various sectors, including healthcare, technology, and retail, employing tactics such as impersonating IT support in voice-phishing schemes. The group typically issues extortion demands starting around $3 million, which are often negotiated down to less than $1 million. Recent reports also suggest that victims have faced escalating threats, including swatting incidents.

For more details, refer to the full article on CyberScoop.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

IDScan Confirms Data Breach Exposing 153 Million Driver’s License Scans for Sale on Dark Web

Identity verification firm IDScan has confirmed a data breach that has exposed scans of approximately 153 million driver’s licenses, with the information reportedly available...

NVIDIA and Palantir Collaborate to Enhance Supply Chain Sovereignty with AI Solutions

Palantir Technologies Inc. and NVIDIA have announced a strategic collaboration aimed at enhancing supply chain sovereignty through advanced artificial intelligence (AI) solutions. This partnership...

Microsoft Warns of AI-Enhanced Executive Impersonation and Invoice Fraud Campaigns

In a concerning trend, threat actors are leveraging artificial intelligence (AI) to enhance their tactics in executing executive impersonation and invoice fraud schemes. Recent...

NASA’s SARSAT technology aids in rescue of five fishermen at sea

NASA's Search and Rescue Satellite-Aided Tracking (SARSAT) technology played a crucial role in the rescue of five fishermen off the Gulf Coast of Mississippi...