teiss – News – Apollo Global Management reveals security breach following social engineering attack

Apollo Global Management, a leading asset management firm, disclosed a data security incident after threat actors leveraged social engineering tactics to infiltrate its internal network and exfiltrate confidential information from its cloud-based systems.

 

Headquartered in New York City, USA, Apollo Global Management is a global asset management company. It provides investment management and financial services across private equity, credit, and real assets. Through its subsidiary Athene, Apollo also offers retirement savings products and annuities.

 

In a filing with California’s attorney general, Apollo disclosed a cyber security incident in which an unauthorised third party gained access to the company ’s internal network after using social engineering techniques.

 

A social engineering campaign is a cyber attack that tricks people into revealing sensitive information or granting access to systems. Hackers often use phishing, impersonation, fake messages, or phone calls to deceive employees and gain unauthorised access to company data.

 

Following the incident, the company immediately launched an investigation, with assistance from external cyber security experts, to determine the scope of the incident. It also took steps to secure the affected systems and notified law enforcement authorities about the incident.

 

Based on our investigation, we determined that there was unauthorized access to certain cloud platforms between July 6 and July 10, 2026,” Apollo said.

 

The compromised data included names, dates of birth, contact information, home addresses, and your Social Security Numbers.

 

Although Apollo found no indication that the exposed information had been misused, it urged affected individuals to remain vigilant by regularly reviewing their credit reports, account and benefits statements, and to report any suspicious activity to law enforcement agencies, including local police and the state attorney general. 

 

The asset management company has also offered two years of complimentary credit monitoring services through Cyberscout to all affected individuals.

 

Although Apollo Global Management did not reveal the identity of the threat actors behind the cyber attack, multiple media reports have linked the incident to UNC6671, a financially motivated threat group known for using voice-phishing and social engineering tactics to compromise organisations. Google’s Threat Intelligence Group (GTIG) has associated UNC6671 with recent campaigns targeting hundreds of organisations, in which attackers sought to obtain employee credentials and access sensitive corporate systems and data.

 

Reuters reported that the hackers, who are also known by aliases such as Redact, Pink, Falcon, and Helix, had targeted firms including Blackstone, Bridgewater, Bain Capital and more. However, it was still unclear whether the attackers had successfully compromised any of the companies.

Click Here For The Original Source

——————————————————–

..........

.

.