Apollo Global Hit by Social Engineering Attack That Exposed Names and Social Security Numbers
A phone-based scam tricked Apollo Global Management's IT support staff into handing over access. Names, contact details, and Social Security numbers may have been stolen.

Key points
- Apollo Global Management, a private equity firm managing roughly $1.05 trillion in assets, disclosed a data breach affecting personal information including Social Security numbers.
- Criminals accessed Apollo's cloud systems between 6 and 10 July using a social engineering attack, meaning they manipulated employees by phone rather than using technical hacking tools.
- The attack is linked to a criminal group called BlackFile (also tracked as UNC6671), which collected over $10 million in Bitcoin ransom payments between January and May 2025.
- Apollo says it found no evidence that stolen data has been published or used to commit fraud, and is offering affected people free identity protection and credit monitoring.
- Several other major finance firms appear to have been targeted in the same campaign, though only Apollo has confirmed a successful breach so far.
Apollo Global Management, one of the world's largest private equity firms, has told affected individuals that criminals broke into some of its cloud systems and may have taken their personal details. The exposed information includes names, contact details, and Social Security numbers, the nine-digit government IDs Americans use for taxes, banking, and benefits.
How did the attackers get in?
They made phone calls. No exotic software was needed. The technique is called vishing (voice phishing): criminals ring a company's IT helpdesk, pretend to be a colleague or vendor, and talk staff into resetting passwords or granting system access. The intrusion ran from 6 to 10 July. Apollo's investigation is ongoing.
Who is behind this?
Researchers tie the attack to BlackFile, also logged as UNC6671. The group emerged in early 2026 and has been running helpdesk-impersonation calls against organisations across North America, Australia and the UK. It's since rebranded and shifted its focus toward private equity, financial services and professional services. We've been tracking BlackFile since 9 July 2026, and this is our third story on the group.
Google's Threat Intelligence Group reported that BlackFile collected over $10 million in Bitcoin ransom payments in the first five months of 2025. SecurityWeek reported that organisations observed in the same campaign's phishing infrastructure include Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, CME Group, and hedge funds including Point72, Citadel, Two Sigma and Millennium Management. Appearing on that list doesn't mean those firms were breached. Several confirmed they detected and blocked attempts with no data taken.
Apollo's the only company that has publicly confirmed a successful breach from this campaign.
Should affected people be worried?
Apollo says it's found no sign that stolen data has appeared online or been used for fraud, which matters. Still, a Social Security number in criminal hands is a slow-burning risk, not a closed case.
| What was exposed | What to watch for |
|---|---|
| Full name | Fraudulent accounts opened in your name |
| Contact information | Targeted phishing calls or texts |
| Social Security number | Credit applications you did not make |
If you receive a letter from Apollo, sign up for the free identity protection and credit monitoring it's offering. A free credit freeze with the three main bureaus (Equifax, Experian, TransUnion) is the strongest protection against someone opening new accounts in your name. It costs nothing and can be lifted whenever you need it.
MFA (multi-factor authentication, a second check beyond a password such as a code sent to your phone) can slow this type of attack, but it's not a complete defence once an attacker has already talked a helpdesk worker into bypassing it. The honest fix is staff training on recognising suspicious calls. As we noted covering the Heights Finance breach on 18 August, the cloud platform is rarely the weakest link; the person answering the phone often is.



