Back to Home
Security

$1T investment giant Apollo breached after social engineering attack

Hackers spent four days inside the org's cloud platforms after apparently talking their way in

t
tech4you AI
August 24, 20262 min read
Share

cyber-crime

$1T investment giant Apollo breached after social engineering attack

Hackers spent four days inside the org's cloud platforms after apparently talking their way in

Apollo Global Management has admitted that attackers talked their way into its cloud systems and got their hands on Social Security numbers and other personal information.

The investment giant disclosed the breach in a notification filed with California's attorney general, saying it had suffered a "social engineering incident" that resulted in unauthorized access to "certain cloud platforms" between July 6 and July 10.

Apollo isn't saying which cloud platforms were compromised, how the attackers got in, or how many people are affected by the breach.

What it does say is that its investigation determined on August 12 that the potentially compromised information included names, dates of birth, contact information, home addresses, and Social Security numbers.

The company said it has so far found no evidence that the information has been publicly posted or used for identity theft or fraud. Those affected are being offered 24 months of credit monitoring and identity protection services.

"Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation," Matthew Breitfelder, Apollo's global head of human capital, said in the notification.

The breach comes weeks after Google warned that UNC6671, an extortion-focused crew also known as "BlackFile," was targeting private equity firms and other financial-sector companies. Reuters reported at the time that Apollo was among the companies targeted, alongside Blackstone, Bridgewater and Bain Capital, although it was then unclear whether any of the attacks had succeeded.

Apollo's disclosure now confirms that, in its case at least, someone did get in. While the company has not attributed the breach to UNC6671, its notification makes a point of linking the incident to similar attacks elsewhere, saying:

"Similar to other financial services firms, Apollo recently experienced a social engineering incident."

Google said UNC6671 has been calling employees on their personal phones while posing as colleagues or IT support staff, then steering them to spoofed login pages built to harvest credentials and multi-factor authentication codes. Once inside, the attackers steal corporate data and threaten to publish it unless victims pay up. Some payments have reached $750,000, according to Google's researchers.

The incident lands amid a run of attacks in which crooks have gone after employees rather than trying to batter their way through corporate defenses. Earlier this month, Levi Strauss said that social engineers compromised three employees' company-issued computers and made off with corporate data.

For Apollo, plenty remains unanswered, including whose Social Security numbers were exposed and exactly how many people now have reason to watch their credit reports more closely. ®


Originally published on The Register

$1T investment giant Apollo breached after social engineering attack | tech4you