Apollo Global Management disclosed a breach after attackers used social engineering to access some of its cloud platforms over several days in July. The company says personal data may have been exposed, including names, contact details, and Social Security numbers. Reporting links the incident to an IT helpdesk-themed vishing campaign targeting financial and investment firms.
Key findings
- Apollo says a “social engineering attack” led to access to “some of the company’s cloud platforms” between July 6 and 10.
- Potentially exposed data includes “names, contact information, and SSNs.”
- The activity appears linked to an IT helpdesk-themed vishing campaign associated with “UNC6671 and BlackFile.”
- Researchers/reporting say multiple private equity and hedge funds were targeted, but “public disclosures confirm a successful data compromise only in the case of Apollo.”
- GTIG reported the group “received over $10 million in Bitcoin ransom payments between January and May.”
Who’s being targeted
- Commonly targeted roles: All employees, Finance, Investment teams, Executive assistants, IT helpdesk/service desk, Identity and access management (IAM) administrators, Cloud administrators.
- Affected industries: Private equity, Financial services, Professional services, Hedge funds, Investment management.
- Attack channels: vishing.
- Impersonated: Internal IT helpdesk.
Awareness takeaways
- Treat unexpected “IT helpdesk” calls as suspicious and verify the caller through a known internal number or directory before taking any action.
- Never share one-time passcodes or approve access prompts because someone called you, report and confirm through official channels first.
- Prioritize training for teams in finance/investments and other high-value business units, because attackers are actively targeting these sectors.
- Assume social engineering can lead directly to cloud account compromise and downstream exposure of sensitive identity data.
Red flags to watch for
- Unsolicited helpdesk call requesting urgent action related to access
- Requests to share one-time passcodes or approve prompts during the call
- Pressure/urgency to act immediately without verification
Read the video transcript
An IT helpdesk call just helped breach Apollo and expose names, contact details, even Social Security numbers. The script is simple: “Hi, this is the IT helpdesk, I’m calling about your access to our cloud platform. Can you approve that login prompt I just sent?” That’s helpdesk-themed vishing tied to the Apollo breach. Here’s the trap: the call feels internal and urgent, but they need you to read out a one-time code or tap Approve so they can jump into our cloud platforms, exactly how Apollo’s data was accessed over several days. Your move: if you get an unexpected IT helpdesk call about your access, hang up, call back using the official IT number in our directory, and only then take action.