Apollo Global Management Confirms Data Breach Amid Surge of Social Engineering Attacks on Financial Sector

Published:

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Apollo Global Management has confirmed that it was affected by a series of social engineering attacks targeting the financial sector last month. The private equity firm reported unauthorized access to its cloud platforms between July 6 and July 10, as detailed in a data breach notification filed in California. The company has not disclosed when it became aware of the breach or how it occurred.

Apollo is the first organization to publicly acknowledge that sensitive personal data was compromised during this wave of attacks, which have also impacted large private equity firms, law firms, financial rating agencies, and medical technology companies. While the firm did not identify the attackers, Google attributed the ongoing campaign to a group known as BlackFile, which is associated with a larger cybercrime organization called The Com.

Matthew Breitfelder, Apollo’s global head of human capital, stated in the disclosure that the company promptly notified law enforcement, engaged cybersecurity experts, and enhanced its security protocols following the incident. An investigation revealed that personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers, were compromised. However, Apollo has not disclosed the number of individuals affected and noted that there is currently no evidence that the data has been posted online or used for identity theft.

Apollo Global Management is one of the largest private equity firms globally, managing approximately $1.05 trillion in assets as of June. Reports indicate that some of Apollo’s competitors, such as Blackstone and Bain Capital, were also targeted, although it remains unclear if they were compromised.

BlackFile has been linked to attacks across various sectors, including healthcare, technology, and retail, employing tactics such as impersonating IT support in voice-phishing schemes. The group typically issues extortion demands starting around $3 million, which are often negotiated down to less than $1 million. Recent reports also suggest that victims have faced escalating threats, including swatting incidents.

For more details, refer to the full article on CyberScoop.

Follow Cyber Warriors Middle East for further global cybersecurity developments.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

EU fines Google €403 million for location data breach, mandates compliance within six months.

DUBLIN: Ireland's Data Protection Commission (DPC), representing the European Union, has imposed a hefty fine of €403 million ($462 million) on Google for violating...

CrowdStrike’s SafeMind Enhances Cyber Defense with Advanced Offensive Techniques

Revolutionizing Cyber Defense: CrowdStrike's SafeMind System In the ever-evolving landscape of cybersecurity, the ability...

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability

Roundcube Security Advisory AV26-503 Warns of Exploited CVE-2026-48842 Vulnerability On May 24, 2026, Roundcube issued a critical security advisory addressing vulnerabilities in its webmail product....