top of page
OutSystems-business-transformation-with-gen-ai-ad-300x600.jpg
OutSystems-business-transformation-with-gen-ai-ad-728x90.jpg
TechNewsHub_Strip_v1.jpg

LATEST NEWS

Private equity firm Apollo confirms data breach as vishing wave targets major Wall Street institutions

  • Marijan Hassan - Tech Journalist
  • 11 minutes ago
  • 2 min read

5. Sec


Private equity firm Apollo confirms data breach as vishing wave targets major Wall Street institutions

Alternative asset management giant Apollo Global Management has confirmed it suffered a data breach involving sensitive personal information following a sophisticated social engineering attack. The disclosure, detailed in regulatory filings and breach notification letters, makes Apollo one of the highest-profile victims in a coordinated extortion campaign targeting major U.S. private equity and financial firms.


Editorial credit: Poetra.RH / Shutterstock
Editorial credit: Poetra.RH / Shutterstock

According to a notice signed by Matthew Breitfelder, Apollo’s Global Head of Human Capital, unauthorized actors accessed select cloud-based platforms between July 6 and July 10, 2026. Following an internal investigation assisted by forensic experts, Apollo determined on August 12 that intruders exfiltrated records containing full names, dates of birth, contact details, home addresses, and Social Security numbers.


The Vishing Campaign Targeting Financial Titans

The intrusion was executed through advanced social engineering rather than software vulnerability exploits. Threat actors utilized "vishing" (voice phishing), calling employees directly while posing as internal IT help desk personnel, to trick staff into divulging credentials and multi-factor authentication (MFA) codes via lookalike sign-in portals.


Google Threat Intelligence Group (GTIG) and cybersecurity researchers flagged the campaign as part of a wider extortion scheme operated by financial crime groups under various monikers (including Falcon, Pink, and Silent Ransom Group).


The campaign has actively probed and targeted high-net-worth investment management and financial services institutions across Wall Street, including Blackstone, KKR, CME Group, and Point72 Asset Management.


Remediation and Industry Impact

Apollo reported that it promptly notified law enforcement, contained the unauthorized access, and implemented secondary identity verification protocols across its cloud environments. The firm noted there is no evidence that the stolen data has been publicly leaked or used for identity theft and is offering complimentary credit monitoring services to affected individuals.


The incident underscores how social engineering strategies bypass traditional perimeter firewalls by exploiting administrative access workflows, prompting financial institutions to enforce stricter identity verification rules for IT help desks and employee password resets.

wasabi.png
Gamma_300x600.jpg
paypal.png
bottom of page