Apollo Breach Tied to IT Helpdesk Vishing

Security Week Feed · High sophistication
Last updated August 24, 2026

Apollo Global Management disclosed a breach after attackers used social engineering to access some of its cloud platforms over several days in July. The company says personal data may have been exposed, including names, contact details, and Social Security numbers. Reporting links the incident to an IT helpdesk-themed vishing campaign targeting financial and investment firms.

Key findings

  • Apollo says a “social engineering attack” led to access to “some of the company’s cloud platforms” between July 6 and 10.
  • Potentially exposed data includes “names, contact information, and SSNs.”
  • The activity appears linked to an IT helpdesk-themed vishing campaign associated with “UNC6671 and BlackFile.”
  • Researchers/reporting say multiple private equity and hedge funds were targeted, but “public disclosures confirm a successful data compromise only in the case of Apollo.”
  • GTIG reported the group “received over $10 million in Bitcoin ransom payments between January and May.”

Who’s being targeted

  • Commonly targeted roles: All employees, Finance, Investment teams, Executive assistants, IT helpdesk/service desk, Identity and access management (IAM) administrators, Cloud administrators.
  • Affected industries: Private equity, Financial services, Professional services, Hedge funds, Investment management.
  • Attack channels: vishing.
  • Impersonated: Internal IT helpdesk.

Awareness takeaways

  • Treat unexpected “IT helpdesk” calls as suspicious and verify the caller through a known internal number or directory before taking any action.
  • Never share one-time passcodes or approve access prompts because someone called you, report and confirm through official channels first.
  • Prioritize training for teams in finance/investments and other high-value business units, because attackers are actively targeting these sectors.
  • Assume social engineering can lead directly to cloud account compromise and downstream exposure of sensitive identity data.

Red flags to watch for

  • Unsolicited helpdesk call requesting urgent action related to access
  • Requests to share one-time passcodes or approve prompts during the call
  • Pressure/urgency to act immediately without verification
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

An IT helpdesk call just helped breach Apollo and expose names, contact details, even Social Security numbers. The script is simple: “Hi, this is the IT helpdesk, I’m calling about your access to our cloud platform. Can you approve that login prompt I just sent?” That’s helpdesk-themed vishing tied to the Apollo breach. Here’s the trap: the call feels internal and urgent, but they need you to read out a one-time code or tap Approve so they can jump into our cloud platforms, exactly how Apollo’s data was accessed over several days. Your move: if you get an unexpected IT helpdesk call about your access, hang up, call back using the official IT number in our directory, and only then take action.

Similar attacks

Wall Street Hit by Help Desk Impersonation Calls

Wall Street Hit by Help Desk Impersonation Calls

A real campaign of voice-phishing (vishing) calls targeted major hedge funds and private equity firms by impersonating internal IT/help desk staff. Victims were pressured into completing “routine” security steps and were sent to fake login pages that captured usernames, passwords, and MFA codes in…

August 20, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026