Advertisement
Advertisement
SendPulse

Private Equity Firms Like Apollo Are Getting Hacked. Here’s What They’re Doing About It

By Isaac Kwame · 26 August 2026

Apollo Global Management confirmed a data breach after a social engineering campaign now linked to Blackstone, Bridgewater and Bain Capital. Here’s what happened, how Apollo is responding, and what financial services firms should do to avoid being next.

Advertisement
Advertisement

Key Takeaways

  • Apollo Global Management, which manages $938 billion in assets, confirmed that hackers accessed its cloud systems between July 6 and July 10, 2026, exposing names, dates of birth, home addresses, contact information and Social Security numbers.
  • Google’s threat intelligence team tracks the group behind this campaign as UNC6671, operating under the aliases Falcon, Helix, Pink and Redact; subsequent reporting on that research has tied the campaign to Apollo, Blackstone, Bridgewater and Bain Capital, among other firms.
  • The attackers do not rely on malware or software exploits. They call employees on their personal mobile phones, impersonate the internal IT helpdesk, and talk victims into entering credentials and multi-factor authentication codes on lookalike login pages.
  • Apollo is offering affected individuals 24 months of complimentary credit monitoring and identity protection through Cyberscout, including proactive fraud assistance, with enrollment required within 90 days.
  • Google’s researchers recommend phishing-resistant, FIDO2-based authentication, shorter session lifetimes, and stricter controls on IT helpdesk identity verification as the most effective defenses against this style of attack.

Social Engineering Attacks: 2023–2026 at a Glance

Most reported social engineering techniques against enterprises (industry threat reporting, 2023–2026):

  • Phishing and spear-phishing email remains the most common initial-access technique reported across the period, typically used to harvest credentials or deliver malicious links and attachments.
  • Voice phishing (vishing), including help desk and IT support impersonation, has grown sharply as a distinct category since 2023, driven by campaigns targeting large enterprises through calls to employees’ personal phones.
  • Adversary-in-the-middle (AiTM) phishing kits, which proxy a real login session to steal credentials and session cookies in real time, have become a standard tool for bypassing traditional multi-factor authentication.
  • SIM swapping and MFA-fatigue (push-bombing) attacks continue to be used to defeat one-time-passcode and push-based authentication.
  • Business email compromise, where attackers impersonate executives or vendors to redirect payments, remains one of the costliest categories by reported financial loss, according to the FBI’s Internet Crime Complaint Center.

Figures reflect patterns described in public threat intelligence reporting, including from Google/Mandiant, the FBI IC3, and industry incident-response reports, rather than a single unified dataset.

Private equity firms manage some of the most sensitive information in the financial system: the personal data of limited partners, the financial details of portfolio companies, and deal information worth billions of dollars before it becomes public. That combination has made them a priority target for a hacking campaign that does not need to break through a firewall or exploit a piece of software. It only needs to get one employee on the phone.

What happened at Apollo

Apollo Global Management, the private equity firm that manages $938 billion in assets and employs roughly 5,000 people, confirmed that hackers gained unauthorized access to certain of its cloud platforms between July 6 and July 10, 2026. The firm disclosed the incident in a breach notification letter filed with the California Attorney General on August 20, 2026, which confirmed at least 500 California residents were affected; the total number of people impacted nationwide has not been made public.

The categories of data involved were names, dates of birth, contact information, home addresses, and Social Security numbers, according to the filing. Apollo has said it has no evidence, at this time, that the information has been publicly posted or used for identity theft or fraud.

Apollo was not alone. Press coverage of the same UNC6671 campaign, drawing on the Google research described below, has reported that Blackstone, Bridgewater and Bain Capital were also targeted, among a wider group of firms across other sectors caught up in the same threat actor’s activity.

What they’re doing about it

Apollo’s response follows the standard playbook for a breach involving Social Security numbers and other identifying data. The firm is providing affected individuals with what its notification describes as “complimentary access to Credit Monitoring and Identity Protection Services at no charge.” Enrolled individuals receive alerts “for twenty-four months from the date of enrollment when changes occur to your credit file,” giving them an early warning if someone tries to open a line of credit or otherwise use their identity fraudulently.

Alongside credit monitoring, Apollo is providing access to Cyberscout, a service that offers what the notification describes as “proactive fraud assistance.” Cyberscout’s model typically pairs the monitoring alerts with a case manager who helps a victim work through the practical steps of freezing credit, disputing fraudulent accounts and replacing compromised identity documents if fraud does occur, rather than leaving individuals to navigate that process alone. Enrollment is time-limited, with individuals given 90 days from the date of the letter to sign up. Apollo reported $938 billion in assets under management at the time of disclosure; the firm’s total has continued to grow since, underscoring just how much sensitive client and deal data now sits behind the credentials these attackers are after.

Credit monitoring and identity protection are a reasonable, and now fairly standard, response once a breach involving Social Security numbers has already happened. But they are a remedy for affected individuals after the fact. They do nothing to close the gap that let the attackers in, and boards at other financial services firms are increasingly asking a harder question: what would have stopped this before it started.

How firms are hardening themselves before an incident

Financial services firms outside the private equity and asset management space have already had to answer that question, and the steps they’ve taken are instructive. In a recent case study on this site, building products supplier Lambson used a penetration test to identify weaknesses in its cloud environment and worked through a structured cloud security overhaul before those weaknesses could be exploited. Separately, packaging manufacturer Allpack put in place automated dark web monitoring to catch employee and customer credentials that had already leaked, before they could be used against the company in exactly the kind of credential-based attack now being used against private equity firms.

Both cases point to the same underlying principle: the most damaging attacks against enterprises today rarely start with a sophisticated exploit. They start with a stolen or guessed credential, or with an employee talked into handing one over. Firms that test their own defenses against that reality, rather than assuming their perimeter security is enough, are the ones catching these gaps before an attacker does.

Remedies for individuals: what to do if you’ve been affected

For individuals who receive a breach notification like Apollo’s, or who suspect their data may be involved in this campaign, security practitioners generally recommend:

  • Enroll in the credit monitoring offered. Where a company the size of Apollo offers free monitoring through a service like Cyberscout, enrolling within the stated window costs nothing and provides an early warning system for fraudulent activity.
  • Place a credit freeze with all three major credit bureaus (Equifax, Experian and TransUnion), not just the monitoring service offered by the breached company. A freeze blocks new lines of credit from being opened in your name until you lift it, and is free to place and remove.
  • Watch for follow-on phishing. Breached personal data, including names, birth dates and addresses, is commonly used to make subsequent phishing or vishing attempts against the same individuals more convincing. Treat unexpected calls or emails referencing personal details with added scrutiny, particularly anything claiming to be from a bank, the IRS, or an employer’s IT department.
  • File an identity theft report with the Federal Trade Commission at IdentityTheft.gov if you notice any signs of fraudulent activity, which creates a recovery plan and supporting documentation for disputing fraudulent accounts.

How to avoid becoming the next headline

For financial services firms looking to avoid being the next name in a breach notification, the tactics used against Apollo and its peers point directly to the defenses that would have blunted them:

  • Move to phishing-resistant, FIDO2-based authentication rather than one-time passcodes or app-based push notifications, which can be defeated by adversary-in-the-middle (AiTM) phishing kits, tools that sit between a victim and a real login page to intercept credentials and session tokens as they’re entered in real time.
  • Tighten IT helpdesk identity verification. Because these attacks rely on convincing an employee that the caller genuinely is internal IT, requiring a second, independent verification step, such as a callback to a known number or verification through a manager, before any password reset or MFA re-enrollment, closes the exact opening these attackers use.
  • Shorten session lifetimes and enforce re-authentication for sensitive systems, so that a stolen session token has a smaller window in which to be useful to an attacker.
  • Centralize authentication through single sign-on so that security controls, monitoring and anomaly detection apply consistently across every application employees use, rather than varying system by system.
  • Run regular social engineering simulations against staff, including phone-based pretexting, not just email phishing tests, since this campaign’s primary technique is a phone call, not an email.

What happens next

According to Google security researchers, who published detailed threat intelligence on this campaign earlier this month, the group behind it, tracked as UNC6671 and operating under the aliases Falcon, Helix, Pink and Redact, has been steadily shifting its focus toward higher-value targets. Google’s researchers describe the group’s targeting moving from manufacturing, real estate, healthcare and insurance in the spring, to technology and intellectual property-heavy targets by early summer, and then specifically to financial services, private equity and law firms by July, sectors the researchers note are attractive for their mergers and acquisitions activity, capital deployment decisions and sensitive litigation data.

The technique itself has stayed consistent throughout: calls to employees’ personal mobile phones, impersonating IT helpdesk staff with an urgent pretext, most often a mandatory multi-factor authentication or passkey enrollment update, that directs the employee to a convincing but fake login page. Once credentials and authentication codes are entered there, the attackers use adversary-in-the-middle infrastructure to capture and reuse the live session, giving them access without ever needing to guess a password or exploit a software vulnerability.

Google’s researchers also noted that the group’s domain registration activity accelerated through June and July, with new lookalike domains appearing roughly once every 1.6 days by mid-summer, up from once every 2.2 days earlier in the year, a sign the campaign shows no indication of slowing down. For financial services firms managing sensitive client and deal data, the message from researchers is that the exposure isn’t hypothetical: it is an active, ongoing campaign that has already reached several of the largest names in the industry.

Who can help

Firms looking to test their own exposure to this style of attack before an incident, rather than after, typically start with the same categories of service Apollo and its peers are now being asked about publicly. DigitalXRAID, a UK-based cybersecurity company, offers a dedicated social engineering testing service that simulates phishing and pretexting attempts against a workforce and follows up with targeted training to close any gaps identified, alongside broader penetration testing, red teaming, and a 24/7 CREST-accredited security operations centre for firms that want ongoing monitoring and incident response instead of a one-off test.

For an industry built on protecting other people’s capital, the lesson from this summer’s campaign is a simple one: the weakest point in a financial services firm’s security is rarely its software. It’s the phone call an employee didn’t expect to have to question.

Join the CEOs, CIOs, CTOs and CISOs who rely on our insights.

Stay up to date with emerging threats, network infrastructure strategy, compliance and the latest tools.