Apollo Global Hit by Social Engineering Attack That Exposed Names and Social Security Numbers

A phone-based scam tricked Apollo Global Management's IT support staff into handing over access. Names, contact details, and Social Security numbers may have been stolen.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing
Share

Key points

  • Apollo Global Management, a private equity firm managing roughly $1.05 trillion in assets, disclosed a data breach affecting personal information including Social Security numbers.
  • Criminals accessed Apollo's cloud systems between 6 and 10 July using a social engineering attack, meaning they manipulated employees by phone rather than using technical hacking tools.
  • The attack is linked to a criminal group called BlackFile (also tracked as UNC6671), which collected over $10 million in Bitcoin ransom payments between January and May 2025.
  • Apollo says it found no evidence that stolen data has been published or used to commit fraud, and is offering affected people free identity protection and credit monitoring.
  • Several other major finance firms appear to have been targeted in the same campaign, though only Apollo has confirmed a successful breach so far.

Apollo Global Management, one of the world's largest private equity firms, has told affected individuals that criminals broke into some of its cloud systems and may have taken their personal details. The exposed information includes names, contact information, and Social Security numbers, which are the nine-digit government IDs Americans use for taxes, banking, and benefits.

How did the attackers get in?

They made phone calls. No exotic software was needed. The group used a technique called vishing, which stands for voice phishing: criminals ring a company's IT helpdesk, pretend to be a colleague or a vendor, and talk staff into resetting passwords or granting system access.

The intrusion ran from 6 July to 10 July. Apollo says an investigation is still under way.

Who is behind this?

The attack is tied to a criminal group researchers call BlackFile, also logged under the tracking label UNC6671. The group surfaced in early 2026 and has been running helpdesk-impersonation phone scams against companies across North America, Australia, and the UK. Google's Threat Intelligence Group recently reported that BlackFile received more than $10 million in Bitcoin ransom payments in the first five months of 2025 alone.

BlackFile has recently shifted its focus toward private equity, financial services, and professional services firms. SecurityWeek reported that organisations observed in the same campaign's phishing infrastructure include Blackstone, Bain Capital, KKR, Bridgewater Associates, and several major hedge funds. Being named in that list does not mean those firms were breached. Several have confirmed they detected and blocked attempts with no data taken.

Apollo is the only company that has publicly confirmed a successful breach from this campaign so far.

Should affected people be worried?

Apollo says it found no sign that stolen data has appeared online or been used for fraud, which is a meaningful point. Still, a Social Security number in criminal hands is a slow-burning risk.

What was exposed What to watch for
Full name Fraudulent accounts opened in your name
Contact information Targeted phishing calls or texts
Social Security number Credit applications you did not make

Apollo is offering free identity protection and credit monitoring to people whose information was exposed. If you receive a letter from the company, sign up. Place a free credit freeze with the three main credit bureaus (Equifax, Experian, TransUnion) if you want the strongest protection against someone opening new accounts in your name. A freeze costs nothing and can be lifted any time you need it.

MFA (multi-factor authentication, which requires a second check beyond a password, such as a code sent to your phone) can slow this type of attack, but is not a complete fix when the attacker has already talked a helpdesk worker into bypassing it. Staff training on recognising suspicious calls is where this kind of threat is most honestly addressed.

© 2026 Threat Vectr