Apollo Global Management, a prominent New York-based asset manager, disclosed a data breach that occurred between July 6 and July 10. Hackers gained unauthorized access to certain cloud platforms and stole personal information, including names, dates of birth, contact information, home addresses, and Social Security numbers. This incident is part of a larger wave of social engineering attacks targeting numerous U.S. financial institutions and private equity firms.

The breach involved "meticulous social engineering tactics," where hackers used phone calls, sometimes spoofing IT help desk numbers, to trick employees into divulging credentials. Google Threat Intelligence identified a group, UNC6671, as responsible for these vishing campaigns aimed at data extraction for extortion. Other firms reportedly targeted include Blackstone, KKR, Bain Capital, and Bridgewater Associates.

Apollo began notifying affected individuals on August 21, and is offering 24 months of complimentary credit monitoring and identity protection services through Cyberscout. The firm has stated there is no evidence the stolen information has been publicly posted or used for identity theft or fraud so far, but investigations are ongoing. Class-action attorneys have already launched investigations into Apollo's data protection measures, particularly given the sensitivity of Social Security numbers.

Apollo manages hundreds of billions of dollars in assets across various sectors and trades on the NYSE under the ticker APO. The incident highlights the continued effectiveness of low-tech social engineering tactics, even amid advanced cybersecurity tools. Affected individuals are advised to monitor financial accounts and credit reports for suspicious activity.