Apollo Global Data Breach Exposes Personal Data

www.news4hackers.com-apollo-global-data-breach-exposes-personal-data-apollo-global-data-breach-exposes-personal-data

Personal Information Exposed in Apollo Global Data Breach A private equity firm has confirmed a data breach involving the exposure of sensitive personal information.

Breach Details

Investigation Findings

The incident, attributed to a social engineering attack, allowed unauthorized access to cloud platforms between July 6 and July 10. A subsequent investigation revealed that details such as names, contact information, and Social Security Numbers may have been compromised.

Affected Individuals

The organization has not identified the perpetrators but stated there is no evidence the data has been publicly disclosed or used for fraudulent purposes. Affected individuals are being provided with identity protection and credit monitoring services.

Cybercriminal Group Activities

The breach is linked to a cybercriminal group known as UNC6671 and BlackFile, which has been active since early 2026. The group employs IT helpdesk-themed vishing attacks to target entities across North America, Australia, and the UK. Recent operational changes include a rebranding effort and expanded focus on private equity, financial services, and professional services sectors.

Notable Entities

Researchers have observed phishing infrastructure, domain registrations, and intrusion attempts tied to the group, though not all listed organizations have confirmed breaches. Notable entities associated with the campaign include Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, CME Group, Point72, Citadel, Two Sigma, and Millennium Management.

  • Blackstone
  • Bain Capital
  • KKR
  • TPG
  • Bridgewater Associates
  • Clearlake Capital
  • CME Group
  • Point72
  • Citadel
  • Two Sigma
  • Millennium Management

Financial Gains

The BlackFile group has demonstrated significant financial gains, with the Google Threat Intelligence Group reporting over $10 million in Bitcoin ransom payments between January and May.

Conclusion

The breach highlights ongoing challenges in securing cloud environments against sophisticated social engineering tactics. The private equity firm, managing approximately $1.05 trillion in assets, joins a growing list of high-profile targets in a campaign that underscores the evolving threat landscape for financial and professional services organizations.


Blog Image

About Author

en_USEnglish