“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” Matthew Breitfelder, Apollo’s global head of human capital, wrote in the company’s disclosure.
Apollo’s timeline: cloud access between July 6 and July 10; Aug. 12 finding
Apollo Global Management said attackers gained unauthorized access to some of the firm’s cloud platforms between July 6 and July 10, according to a data breach notification filed in California. The firm said it determined on Aug. 12 that personal data had been compromised; the disclosure named the types of records exposed but did not specify how many people were affected. Apollo did not say when or how it first became aware of the intrusion and declined to respond to a request for comment, the filing said.
What was taken: names, dates of birth, contact information, addresses, Social Security numbers
In its notice, Apollo listed the categories of information impacted: names, dates of birth, contact information, home addresses and Social Security numbers. The company said it has “thus far found no evidence any data was posted online or used for identity theft or fraud.” The filing does not provide a headcount of affected individuals.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAttribution and the wider campaign: Google links attacks to BlackFile and The Com
Apollo did not name the group it believes responsible. Separately, Google researchers earlier this month attributed an ongoing campaign hitting financial services and other sectors to BlackFile, a threat group affiliated with The Com. Google said BlackFile recently split its extortion operations across four brands sharing infrastructure — Redact, Pink, Helix and Falcon — and that the campaign has affected organizations beyond private equity, including healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the start of the year.
Technique and escalation: social engineering, voice-phishing, extortion and swatting
According to researchers cited by CyberScoop, the extortion group moves from sector to sector, impersonating IT support in voice-phishing and social-engineering attacks before threatening alleged victims with extortion demands. The initial demands often start around $3 million and are typically negotiated down to less than $1 million, researchers said. Google also reported that some victims of the group had been subject to threatening messages and other forms of escalation, including swatting incidents — a tactic several subsets of The Com have adopted.
How Apollo’s peers, security teams, and affected individuals are likely to respond
- Blackstone and Bain Capital (named by researchers as among firms targeted with malicious infrastructure) — These firms and other large private equity competitors will be watching whether publicly disclosed compromises lead to follow-on misuse of data or additional disclosures that clarify scope and methods.
- Security teams at large financial institutions and law firms — Teams responsible for cloud platforms and identity controls will be tracking the analytic and forensic findings that Apollo and outside investigators produce, particularly any indicators of compromise tied to voice-phishing or impersonation of IT support.
- Individuals whose personal data was listed — People whose names, dates of birth, contact details, home addresses or Social Security numbers could be affected will be weighing credit- and identity-protection options; Apollo said it found no evidence the data has been posted or used for fraud as of its notice.
Apollo is one of the world’s largest private equity firms, with $1.05 trillion in assets under management at the end of June, the company said in a regulatory filing cited in the disclosure. The firm is the first in this cluster of campaign victims to formally disclose that sensitive personal data in its custody was compromised; researchers have said other large financial firms and professional services organizations were targeted with malicious infrastructure, though it remains unclear which — if any — of those firms suffered similar data exposures.
The disclosure raises immediate questions that only the ongoing investigation and law enforcement notifications can answer: how the social-engineering chain began, whether access was limited to specific cloud services, and the eventual tally of affected individuals. For now, the record is anchored to the July 6–10 access window and Apollo’s Aug. 12 determination that sensitive personal data was among the material taken.
Read the original CyberScoop story: https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/




