Skip to content

Security2 publishers2 min readPublished Updated

Apollo's California filing puts Social Security numbers into the private equity attack wave

The firm says intruders reached its cloud platforms in July and took names, birth dates and Social Security numbers. Google attributes the campaign to BlackFile, a Com affiliate with four extortion brands.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying Apollo's California filing puts Social Security numbers into the private equity attack wave
Photo: techcrunch.com

What happened

  • On Aug. 12 the firm concluded that names, dates of birth, contact information, home addresses and Social Security numbers had been compromised.
  • It is the first victim in the summer's wave against private equity, law firms, rating agencies and medical technology firms to confirm personal data loss.
  • Researchers say Blackstone and Bain Capital were also targeted with malicious infrastructure, with no confirmation that either was compromised.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • precedent With one filing on the record naming Social Security numbers, silence from the other targeted firms stops looking like an absence of evidence and starts looking like a determination a regulator...
  • cost A demand opening near $3 million and settling under $1 million is a rounding error against a $1.05 trillion book, so the price of the crime does nothing to discourage the next round of calls, and...
  • constraint Apollo's statement that it has seen no data posted or misused is a measure of what is visible, and against a group that negotiates most demands downward rather than publishing, it cannot carry...

The number the filing does not contain is a detection date. Apollo puts the unauthorized access to its cloud platforms between July 6 and July 10 [2], and says it worked out on August 12 which categories of personal data had been taken [4]. That is 33 days from the last day of access to the determination [16], but Apollo did not say when or how it became aware of the intrusion, and it did not respond to a request for comment [13]. So the 33 days could be forensic reconstruction after a same-week catch, or most of a month of quiet before anyone looked.

Who signed the notice is also informative. It went out under the name of Matthew Breitfelder, Apollo's global head of human capital, and describes law enforcement notification, outside forensic experts, tightened protocols and an investigation [14]. Apollo has not said whose records these are, or how many people are involved [5]. A human capital byline on a notice listing dates of birth and Social Security numbers points toward people on a payroll rather than fund investors, though the company does not say that either.

Google's attribution supplies the name Apollo left out: BlackFile, affiliated with The Com, which recently split its extortion operations into four brands running on shared infrastructure, Redact, Pink, Helix and Falcon [6]. The method underneath the branding is a phone call. The group impersonates IT support in voice-phishing operations and moves from one sector to the next [9], having already worked through healthcare, technology, transportation, logistics, wholesale, and retail and hospitality this year [8]. That sequence is better read as a list of industries whose help desks will act on a convincing caller than as a ranking of whose data is worth having. Private equity, law firms, rating agencies and medical technology companies were the current stop [3].

Home addresses were in Apollo's compromised set [4], and Google has said some of this group's recent victims received threatening messages and faced escalation including swatting, a tactic used across several subsets of The Com [15]. That pairing is not what a credit monitoring enrolment is designed to answer, and it is the part of the filing that has a shelf life longer than the investigation.

What to watch

  • Whether Blackstone, Bain Capital, or any targeted law firm or rating agency files a breach notice of its own.
  • Whether Apollo's state filings ever put a count of affected individuals on the record.
  • Whether Apollo data surfaces on the leak channels of any of the four BlackFile brands: Redact, Pink, Helix or Falcon.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories