A $1 Trillion Firm, a Phone Call, and a Stolen Identity File
Apollo Global Management — a private equity firm that manages roughly $1.05 trillion in assets — has disclosed that attackers accessed its cloud systems between 6 and 10 July, according to Security Week. What they walked away with: names, contact details, and Social Security numbers belonging to an undisclosed number of people.
The method was social engineering (manipulating real employees into handing over access — no lock-picking required). Specifically, the attackers posed as IT helpdesk staff in phone-based vishing (voice phishing) calls, convincing someone on the inside to open a door that should have stayed closed.
The group behind it is tracked as UNC6671 / BlackFile, a cybercrime operation that emerged in early 2026 and has already collected over $10 million in Bitcoin ransom payments since January. Apollo appears to be the only confirmed successful breach so far. Other major firms — Blackstone, KKR, Citadel, and others — were targeted but say they detected and blocked the attempts.
Apollo says there is no evidence the stolen data has been published or used for fraud, and is offering affected people identity protection and credit monitoring services.
If you receive a letter from Apollo, accept the free credit monitoring without hesitation. Everyone else: if anyone calls claiming to be from your company's IT team and asks you to confirm credentials or grant remote access, call them back on the official number before doing anything.
Sources

