Published · 2d agoSecurity2 min read
Apollo's California filing puts Social Security numbers into the private equity attack wave
The firm says intruders reached its cloud platforms in July and took names, birth dates and Social Security numbers. Google attributes the campaign to BlackFile, a Com affiliate with four extortion brands.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Apollo Global Management confirmed Friday that it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month.
- Attackers gained unauthorized access to some of Apollo's cloud platforms between July 6 and July 10, according to a data breach notification the company filed in California.
- Apollo did not say when or how it became aware of the intrusion, and did not respond to a request for comment.
- Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies.
- Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised.
Compiled by The WatchSomething wrong?How this is made
Why it matters
The number the filing does not contain is a detection date. Apollo puts the unauthorized access to its cloud platforms between July 6 and July 10 [2], and says it worked out on August 12 which categories of personal data had been taken [5]. That is 33 days from the last day of access to the determination [1], but Apollo did not say when or how it became aware of the intrusion, and it did not respond to a request for comment [3]. So the 33 days could be forensic reconstruction after a same-week catch, or most of a month of quiet before anyone looked.
Who signed the notice is also informative. It went out under the name of Matthew Breitfelder, Apollo's global head of human capital, and describes law enforcement notification, outside forensic experts, tightened protocols and an investigation [6]. Apollo has not said whose records these are, or how many people are involved [7]. A human capital byline on a notice listing dates of birth and Social Security numbers points toward people on a payroll rather than fund investors, though the company does not say that either.
Google's attribution supplies the name Apollo left out: BlackFile, affiliated with The Com, which recently split its extortion operations into four brands running on shared infrastructure, Redact, Pink, Helix and Falcon [8]. The method underneath the branding is a phone call. The group impersonates IT support in voice-phishing operations and moves from one sector to the next [11], having already worked through healthcare, technology, transportation, logistics, wholesale, and retail and hospitality this year [10]. That sequence is better read as a list of industries whose help desks will act on a convincing caller than as a ranking of whose data is worth having. Private equity, law firms, rating agencies and medical technology companies were the current stop [4].
Home addresses were in Apollo's compromised set [5], and Google has said some of this group's recent victims received threatening messages and faced escalation including swatting, a tactic used across several subsets of The Com [13]. That pairing is not what a credit monitoring enrolment is designed to answer, and it is the part of the filing that has a shelf life longer than the investigation.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Apollo Global Management confirmed Friday that it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month.
- [2]
Attackers gained unauthorized access to some of Apollo's cloud platforms between July 6 and July 10, according to a data breach notification the company filed in California.
ReportedView cited source - [3]
Apollo did not say when or how it became aware of the intrusion, and did not respond to a request for comment.
ReportedView cited source - [4]
Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies.
ReportedView cited source - [5]
Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised.
ReportedView cited source - [6]
The disclosure notice was written by Matthew Breitfelder, Apollo's global head of human capital, who said the company promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced its security protocols and launched an investigation.
ReportedView cited source
Sources & coverage · 2 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- cyberscoop.comMatt Kapko2d agoApollo discloses data breach from ongoing wave of attacks hitting financial sector
- securityweek.comEduard Kovacs2h agoPersonal Information Exposed in Apollo Global Data Breach
Additional citations
- Apollo Global Management, via CyberScoop
- Google, per CyberScoop
- Google researchers, per CyberScoop



