Apollo Global Breach Exposes SSNs in BlackFile Vishing Campaign
Apollo Global Management has disclosed a data breach that exposed sensitive personal information following a social engineering attack. According to a breach notice sent to affected individuals, threat actors accessed several of the private equity firm's cloud platforms between July 6 and 10 after successfully deceiving employees. An investigation is ongoing, but Apollo confirmed that personal information was likely compromised, including names, contact details, and Social Security numbers. The company has not disclosed the number of affected individuals but is offering identity protection and credit monitoring services. Affected individuals can verify their exposure using a email breach checker and should immediately review their accounts for suspicious activity.
The intrusion has been attributed to UNC6671, also tracked as BlackFile, a financially motivated cybercrime group that emerged in early 2026. The group is known for IT helpdesk-themed voice phishing (vishing) campaigns targeting organizations across North America, Australia, and the UK. After rebranding and diversifying operations, BlackFile has shifted focus to private equity, financial services, and professional services sectors. Researchers and public reporting indicate that infrastructure linked to the group has been used to probe firms including Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, Clearlake Capital, CME Group, Point72, Citadel, Two Sigma, and Millennium Management. Apollo is the only organization so far confirmed to have suffered a data compromise; several of the named firms have stated they detected or blocked attempts without evidence of theft.
BlackFile's operational success has drawn attention from major threat intelligence teams. Google Threat Intelligence Group (GTIG) recently reported that the group received over $10 million in Bitcoin ransom payments between January and May of this year. The vishing tactics typically involve impersonating internal IT staff to trick employees into resetting MFA credentials or installing remote access tools, giving attackers a foothold in cloud environments like Microsoft 365 and Workday. Employees targeted by such scams should run a password checker to confirm credential strength and rotate any reused passwords before attackers can weaponize stolen session tokens. With roughly $1.05 trillion in assets under management, Apollo represents one of the highest-profile victims in this campaign, underscoring how social engineering continues to defeat enterprise defenses regardless of organizational size.