Apollo confirms data breach amid hacking wave targeting financial firms

Via apollo.com

Apollo confirms data breach amid hacking wave targeting financial firms

The private equity giant disclosed that a social engineering attack potentially exposed Social Security numbers and other sensitive data, joining a growing list of financial firms targeted by coordinated hackers.

Apollo Global Management, one of the largest private equity firms in the world, has confirmed that hackers breached its systems through a social engineering attack earlier this summer. The incident, which took place between July 6 and 10, potentially exposed a trove of sensitive personal information including names, dates of birth, contact details, home addresses, and Social Security numbers.

The disclosure lands at a particularly uncomfortable moment for the financial industry. Just weeks earlier, Google Threat Intelligence researchers published a report detailing a coordinated vishing campaign targeting some of the biggest names in American finance.

A low-tech attack on a high-value target

In Apollo’s case, the unauthorized access targeted certain cloud platforms during a narrow four-day window in early July. The firm has since begun notifying individuals whose data may have been compromised, following standard post-incident protocols required under US data-breach notification laws.

Advertisement

Apollo manages hundreds of billions of dollars in assets across credit, private equity, and real assets. The firm trades on the New York Stock Exchange under the ticker APO.

Part of a broader campaign

The Google Threat Intelligence report, published on August 6, identified a threat actor group tracked as UNC6671. The group carried out coordinated vishing attacks, short for voice phishing, targeting several major US financial and investment firms.

Apollo wasn’t alone on the target list. Blackstone, KKR, Bain Capital, and Bridgewater Associates were among the other high-profile firms named in the report.

Google’s researchers noted that the attackers’ goal was data extraction for extortion purposes.

Legal fallout already brewing

The legal machinery has started moving quickly. Class-action attorneys launched investigations into potential claims against Apollo in mid-to-late August, looking into whether the firm took adequate measures to protect the personal data in its custody.

Data breach class actions in the US have become a well-worn playbook. Firms that suffer breaches exposing Social Security numbers tend to face the steepest legal exposure, because SSNs are permanent identifiers that can’t simply be changed like a password.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.
Apollo confirms data breach amid hacking wave targeting financial firms
Apollo confirms data breach amid hacking wave targeting financial firms

The private equity giant disclosed that a social engineering attack potentially exposed Social Security numbers and other sensitive data, joining a growing list of financial firms targeted by coordinated hackers.

Via apollo.com

Apollo Global Management, one of the largest private equity firms in the world, has confirmed that hackers breached its systems through a social engineering attack earlier this summer. The incident, which took place between July 6 and 10, potentially exposed a trove of sensitive personal information including names, dates of birth, contact details, home addresses, and Social Security numbers.

The disclosure lands at a particularly uncomfortable moment for the financial industry. Just weeks earlier, Google Threat Intelligence researchers published a report detailing a coordinated vishing campaign targeting some of the biggest names in American finance.

A low-tech attack on a high-value target

In Apollo’s case, the unauthorized access targeted certain cloud platforms during a narrow four-day window in early July. The firm has since begun notifying individuals whose data may have been compromised, following standard post-incident protocols required under US data-breach notification laws.

Advertisement

Apollo manages hundreds of billions of dollars in assets across credit, private equity, and real assets. The firm trades on the New York Stock Exchange under the ticker APO.

Part of a broader campaign

The Google Threat Intelligence report, published on August 6, identified a threat actor group tracked as UNC6671. The group carried out coordinated vishing attacks, short for voice phishing, targeting several major US financial and investment firms.

Apollo wasn’t alone on the target list. Blackstone, KKR, Bain Capital, and Bridgewater Associates were among the other high-profile firms named in the report.

Google’s researchers noted that the attackers’ goal was data extraction for extortion purposes.

Legal fallout already brewing

The legal machinery has started moving quickly. Class-action attorneys launched investigations into potential claims against Apollo in mid-to-late August, looking into whether the firm took adequate measures to protect the personal data in its custody.

Data breach class actions in the US have become a well-worn playbook. Firms that suffer breaches exposing Social Security numbers tend to face the steepest legal exposure, because SSNs are permanent identifiers that can’t simply be changed like a password.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.