Apollo Global Management Discloses Data Breach Following Targeted Financial Sector Vishing Campaign

Attackers aimed to steal passwords from employees of private equity firms and other financial companies as part of the broader campaign.
Google Threat Intelligence linked the extortion campaign to actor groups Falcon, Helix, Pink and Redact.
Apollo disclosed the breach via an official letter to the California Attorney General, noting unauthorized access to certain cloud platforms between July 6 and July 10 and exposure of personal data.
The incident occurred within a broader wave of attacks that also targeted hedge funds such as Point72, Citadel and Millennium.
Apollo is a large investment firm with about $938 billion in assets under management.
Apollo Global Management disclosed a social engineering attack that compromised its cloud systems between July 6 and July 10, exposing personal data including names, birth dates, addresses, and Social Security numbers Financial Times. The breach is part of a broader wave of cyberattacks targeting Wall Street, with other victims including Blackstone, Bridgewater Associates, Bain Capital, KKR, and CME Group Insurance Journal.
Google's Threat Intelligence linked the incident to coordinated vishing campaigns by hacker groups including UNC6671, Falcon, Helix, Pink, and Redact Insurance Journal. Apollo, which manages about $938 billion in assets, said there is no immediate evidence that stolen data has been publicly posted or used for fraud Investing.
The attackers used vishing — voice-based phishing — to steal passwords from employees at private equity firms and other financial companies Insurance Journal. This tactic is cheaper and often more effective than technical hacks. The campaign targeted a wide range of financial institutions, showing how vulnerable the entire sector has become to social engineering attacks.
Apollo disclosed the breach via an official letter to the California Attorney General Investing. The company notified law enforcement and said the attack affected certain cloud platforms. The breach lasted only five days, but hackers managed to steal sensitive personal information during that window.
Apollo is not alone. Other major targets include Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG, CME Group, and Moody's Financial Times. Hedge funds like Point72, Citadel, and Millennium were also hit by the same coordinated campaign. These are some of Wall Street's biggest and most sophisticated firms.
The sheer number of targets suggests a coordinated, well-resourced attack. Hackers are focusing on stealing data for extortion rather than immediate fraud. They plan to demand ransoms from these firms, threatening to release sensitive information if payments aren't made.
Technical security systems are strong, but employee passwords are the weakest link. When hackers call employees pretending to be IT support, many give up login credentials without thinking Financial Times. This human vulnerability is harder to fix than patching software or upgrading firewalls.
Even firms managing $938 billion in assets can be breached this way Insurance Journal. The attacks show that size and resources don't guarantee security. Wall Street must now invest heavily in employee training and better password protection systems to prevent future breaches.
Publishers
12
Articles
107
Reach
119