LIVE · cybersecurity feed
Live wire
breach

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

zeroday.news ·

Apollo Global Management, a major private equity firm, has confirmed it experienced a data breach in July, impacting some of its cloud platforms. The company disclosed that sensitive personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers, was compromised during the incident.

The breach occurred between July 6 and July 10, according to a data breach notification filed in California. Apollo stated that it became aware of the intrusion and promptly notified law enforcement, engaged external cybersecurity and forensic experts, and enhanced its security protocols. The ongoing investigation determined on August 12 that personal data had been compromised.

While Apollo did not specify the number of individuals affected, it noted that there is currently no evidence of the data being posted online or used for identity theft or fraud. The firm, which manages $1.05 trillion in assets, is the first to formally disclose a personal data compromise stemming from a series of social engineering attacks targeting the financial sector.

Google has attributed the ongoing campaign to BlackFile, a threat group affiliated with "The Com." This group has reportedly split its extortion operations across four brands—Redact, Pink, Helix, and Falcon—which share infrastructure. BlackFile and its affiliates have impacted organizations across various industries, including healthcare, technology, transportation, logistics, wholesale, retail, and hospitality, since the beginning of the year.

The attackers typically employ voice-phishing and social engineering tactics, often impersonating IT support, before issuing extortion demands. These demands frequently begin around $3 million but are often negotiated down to less than $1 million. Google researchers have also reported that some recent victims of the group have faced threatening messages and other forms of escalation, including swatting incidents.

While Apollo did not name the responsible group, its disclosure places it among several financial institutions believed to have been targeted in this wave of attacks. Other large private equity firms, law firms, financial rating agencies, and medical technology companies have also reportedly been affected. Previous reports indicated that some of Apollo's competitors, such as Blackstone and Bain Capital, were targeted with malicious infrastructure, though it remains unconfirmed if those firms were compromised.

breachcloudfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Lawmakers call for investigation into impact of CISA staffing cuts

Lawmakers say little is known about how recent cuts have impacted CISA and how the knowledge that was lost has been replaced.

security

Your Shredded Visa Card May Still Work at the Checkout

UMass Amherst researchers showed expired Visa contactless cards can make real purchases by exploiting an unsigned expiry field in Visa’s EMV kernel. Researchers at the University of Massachusetts Amherst demonstrated at USENIX Security 2026 in Baltimore that expired Visa contactless credit cards can complete real purchases, including transactions at live retail and grocery merchants, by […]

phishing

New SynkLoader malware pushed in Microsoft Teams phishing campaign

A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]

ai

OWASP Flags Top AI Skill Risks in New Security Blueprint

The Open Worldwide Application Security Project has a brand-new top 10 security list tailored for the modern era, and it debuts a Universal Skill Format to add consistency and security to the AI add-ons.

ai

AI Is Learning to Write Genetic Code

This sort of research is both exciting and terrifying: The two models in question were told to generate complete genomes for a viable bacteriophage—a type of virus able to infect and replicate itself inside bacteria, destroying them from the inside. Using an existing bacteriophage as an example—ΦX174 (pronounced “fie-ex-1-7-4”), known for its ability to infect and destroy E. coli bacteria—the mode

vulnerability

Homeland security cybercops say patch TrueConf (Russia's Zoom) if you're using it

Ukrainian hacktivists exploiting the bugs, but TrueConf's reach stretches well beyond home turf