Apollo Global Management Suffers Data Breach Via Social Engineering Attack
Apollo Global Management has disclosed a data breach resulting from a social engineering attack that exposed personal information, including names, contact details, and Social Security numbers.

Private equity giant Apollo Global Management has confirmed a data breach that led to the exposure of sensitive personal information belonging to individuals. The incident, which occurred between July 6 and July 10, was facilitated by a social engineering attack that granted threat actors access to some of the company’s cloud platforms.
Following the intrusion, an investigation was launched, and Apollo recently determined that personal data may have been compromised. The exposed information includes names, contact details, and Social Security numbers (SSNs). While the company has not publicly identified the perpetrators, it stated that there is currently no evidence to suggest the compromised data has been published or used for fraudulent activities. Affected individuals are being offered identity protection and credit monitoring services as a precautionary measure.
The full extent of the breach, including the exact number of individuals impacted, remains unclear. However, the attack on Apollo Global Management, which oversees approximately $1.05 trillion in assets, is believed to be part of a broader campaign targeting major financial institutions. This campaign is attributed to a cybercrime group known as UNC6671, which has recently rebranded and diversified its operations under the name BlackFile.
The BlackFile group, which emerged in early 2026, has been employing IT helpdesk-themed vishing (voice phishing) attacks to target organizations across North America, Australia, and the UK. The group has recently shifted its focus to the private equity, financial services, and professional services sectors, indicating a strategic move towards high-value targets.
Researchers have identified several other prominent financial firms that may have been targeted in this BlackFile-linked campaign. These include private equity and investment firms such as Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, and CME Group, as well as hedge funds like Point72, Citadel, Two Sigma, and Millennium Management. It is important to note that this list is based on observed phishing infrastructure and domain registrations, and does not confirm a successful breach at all named entities.
Public disclosures have confirmed a successful data compromise only in the case of Apollo. Many of the other named organizations have stated that they detected or blocked intrusion attempts with no evidence of data theft. This suggests that while the campaign is widespread, its success rate in achieving data exfiltration varies.
The BlackFile group has demonstrated significant success in its extortion activities. Google Threat Intelligence Group (GTIG) reported that the group received over $10 million in Bitcoin ransom payments between January and May of 2026, underscoring the financial motivation and effectiveness of their operations.
This incident highlights the persistent threat of social engineering attacks against large financial institutions and the evolving tactics of cybercrime groups. The targeting of private equity and investment firms underscores the value of the data held by these organizations and the need for robust security measures beyond traditional technical defenses.