Isometric diagram of BlackFile social engineering breach reaching cloud document platforms at financial firms

The private equity firm did not say when or how it detected the intrusion, and it did not respond to a request for comment. The activity described here was documented by CyberScoop.

Key Insight: Apollo Global Management confirmed attackers reached some of its cloud platforms between July 6 and July 10, according to a data breach notification the firm filed in California.

On Aug. 12, Apollo determined that the compromised data included names, dates of birth, contact information, home addresses and Social Security numbers. The company has not disclosed how many people were affected, and says it has found no evidence so far that the data was posted online or used for identity theft or fraud.

What makes this disclosure significant for your firm is that Apollo is the first victim to formally confirm personal data loss from a broader wave of social engineering attacks. That campaign has hit large private equity firms, law firms, financial rating agencies and medical technology companies. Researchers previously told CyberScoop that Blackstone and Bain Capital were also targeted with malicious infrastructure, though whether those firms were compromised is unclear.

Apollo did not name the group responsible. Google attributed the ongoing campaign earlier this month to BlackFile, a threat group affiliated with The Com, which recently split its extortion operations across four brands sharing infrastructure: Redact, Pink, Helix and Falcon.

The financial data at stake here is employee and client identity data, the kind that triggers state breach notification obligations and long-tail credit monitoring costs. Apollo managed $1.05 trillion in assets at the end of June, and the intrusion still lasted several days across cloud platforms before the timeline closed.

BlackFile's extortion demands often start around $3 million and are typically negotiated down to less than $1 million, according to reporting on the group's activity across healthcare, technology, transportation, logistics, wholesale, and retail and hospitality victims this year.

If your firm handles investor records, deal documents or client personal data in cloud platforms, this campaign has already demonstrated interest in exactly that profile of target.

Coordinated Attack Wave: BlackFile, Falcon, Helix, Pink, Redact, and The Com

Google attributed the campaign that hit Apollo to BlackFile, an extortion group affiliated with The Com, the loose English-speaking cybercriminal community that recruits heavily from social platforms and gaming circles. BlackFile recently split its extortion operations across four brands, Redact, Pink, Helix and Falcon, that run on shared infrastructure.

That branding split matters for attribution work. Four names publishing separate victim lists off one backend makes the crew look larger and more distributed than it is, and it complicates any attempt to correlate a single intrusion with a single leak site. If your incident response vendor tells you the extortion brand contacting you is new, the underlying operators may be the same ones documented in earlier cases.

The intrusion method is human, not technical. BlackFile operators impersonate IT support staff in voice-phishing calls, walking employees through steps that hand over credentials or authentication approvals. In MITRE ATT&CK terms that maps to phishing for information via voice (T1598.004) and impersonation (T1656), followed by use of valid cloud accounts (T1078.004) rather than exploitation of a software flaw.

That distinction changes what an investigation looks like. There is no CVE to point to and no malicious binary to hash, so the forensic record lives in identity and cloud audit logs: help desk tickets that do not match a real employee request, MFA registrations for new devices, session tokens issued from unfamiliar geographies, and bulk reads against document stores (T1530).

The sector rotation is deliberate. Since the beginning of this year the group and its affiliates have worked through healthcare, technology, transportation, logistics, wholesale, and retail and hospitality before moving to financial services. Each shift lets the operators reuse a script that already works, calling employees in an industry whose help desk conventions they have just spent months learning.

Within the current wave, targeting has extended past private equity to law firms, financial rating agencies and medical technology companies. Researchers told CyberScoop that malicious infrastructure was also aimed at Blackstone and Bain Capital, though whether those firms were compromised is unclear. Infrastructure staged against a named target is evidence of intent, and it is often the earliest signal available before any account is actually taken over.

Financial firms are attractive here for a specific reason. Deal teams, fund administration and investor relations all run on cloud document platforms holding employee and investor records, and access to those platforms is governed by identity rather than network location. An operator who convinces one person to approve a login inherits that person's permissions, and the resulting activity looks like ordinary business use.

The extortion economics are consistent across victims. Demands often open around $3 million and are typically negotiated down to less than $1 million, which suggests the operators price for volume and settlement speed instead of maximum extraction from any single firm.

Pressure tactics escalate beyond the usual leak-site countdown. Google researchers said some recent victims received threatening messages and were subjected to swatting incidents, false emergency reports that send armed police to a home address. Several subsets of The Com have adopted this tactic, and it aims at named individuals such as executives and negotiators, which pulls physical security and legal counsel into what starts as a data incident.

The practical read for financial services is that these operators treat your help desk and your identity provider as the attack surface. Behavioral indicators around account provisioning, MFA changes and anomalous cloud data access carry the investigative weight that file hashes and IP blocklists normally would.

BlackFile intrusion chain: voice phishing to extortion
1
Voice phishing call
Operators call employees and pose as internal IT support staff to collect information. T1598.004
2
Help desk impersonation
The caller walks the employee through steps that hand over credentials or approve an authentication prompt. T1656
3
Valid cloud accounts
Access proceeds through legitimate cloud identities rather than exploitation of a software flaw, so there is no CVE or malicious binary. T1078.004
4
Bulk document store reads
Operators pull data from cloud document stores. Evidence sits in identity and cloud audit logs: new MFA device registrations and session tokens from unfamiliar geographies. T1530
5
Extortion under split brands
Victim lists are published across the Redact, Pink, Helix and Falcon brands running on shared infrastructure, which complicates correlating one intrusion with one leak site. High

Regulatory and Compliance Exposure for Affected Firms

Social Security numbers in the compromised set are what turn this from an IT incident into a statutory notification event in nearly every U.S. state. Apollo filed its notice in California, but individuals affected by a breach of this type rarely live in one state, and each state's law sets its own trigger, content requirements and attorney general notice threshold. If your firm holds workforce or investor records across multiple jurisdictions, you are managing parallel clocks, not one.

Apollo's disclosure was signed by Matthew Breitfelder, the firm's global head of human capital. That points toward employee and personnel data rather than fund investor records, which pulls employment counsel and state labor requirements into a matter your firm would otherwise handle as a pure privacy filing.

For a registered investment adviser, the obligations stack:

  • State breach notification statutes, which in several states require an offer of identity theft protection when Social Security numbers are involved, plus separate notice to the state attorney general.
  • The GLBA Safeguards Rule, which governs how financial institutions protect customer information and gives the FTC a reporting hook for certain unauthorized access events at nonbank financial institutions.
  • SEC Regulation S-P, as amended, which requires covered advisers and broker-dealers to notify individuals whose sensitive customer information was accessed without authorization.
  • Form 8-K Item 1.05, if your firm is publicly traded, once you determine the incident is material. The determination itself is the regulated act, and regulators will examine when you made it and on what basis.

The interval between intrusion and determination is where examiners spend their time. Attackers were in Apollo's cloud platforms between July 6 and July 10, and the company said it determined on Aug. 12 that personal data was compromised. That gap is normal for cloud forensics, but you will be asked to document what you knew on each date and why the analysis took as long as it did. Firms that cannot reconstruct that timeline from logs and vendor reports end up defending the gap with narrative instead of evidence.

State attorney general offices routinely open inquiries after multi-state filings involving Social Security numbers, and plaintiff firms monitor public breach databases for exactly these notices. Expect consumer class action activity to follow public notification, with claims typically built around negligence and inadequate safeguards. Your exposure is driven less by the intrusion itself and more by whether your written information security program matched what you told regulators and clients you had in place.

There is also a payment question. BlackFile's demands often start around $3 million and are typically negotiated down to less than $1 million, which puts the figure inside the range many firms would consider paying quietly. Any payment decision carries sanctions screening obligations, and the fact of a payment can become disclosable in its own right depending on your reporting posture.

The institutional trust cost lands in due diligence. Limited partners, counterparties and prospective clients ask about material incidents in their questionnaires, and an affirmative answer follows your firm through every operational due diligence review for years. For a manager with $1.05 trillion under management, that friction shows up in renewal conversations and allocation decisions rather than in an immediate headline loss. Document the incident response record now, because that record is what you will hand to every LP who asks.

Detection and Containment Actions for Financial Institutions

Start with your service desk. The intrusions in this campaign begin with callers impersonating internal IT support, so the first control to verify is how your help desk authenticates a person requesting a password reset, an MFA re-enrollment, or a new device registration. If that process relies on information an attacker can find in a directory or on LinkedIn, treat every reset performed in the last 60 days as suspect.

Within the first 24 hours, pull identity provider audit and sign-in logs and filter for the events that matter in a social engineering intrusion:

  • MFA method additions, deletions, or resets, especially phone-number and authenticator app changes tied to privileged accounts
  • New device registrations and join events that do not match a known asset record
  • Sign-ins from hosting-provider or VPN address space, and sessions where the authentication succeeded but the device compliance state changed
  • OAuth application consents and service principal creation in your cloud tenant
  • Newly created inbox forwarding or mailbox rules on finance, legal, and executive accounts

Adlumin ITDR watches these authentication patterns across environments Capstone manages, correlating a help desk reset with a first-time sign-in location so the sequence surfaces as one incident instead of two unrelated log lines. That correlation matters because the individual events look routine on their own.

Isolate before you interrogate. If an account shows an unexplained MFA change followed by cloud platform access, disable the account, revoke its active refresh tokens, and quarantine any endpoint that registered during the same window. A password reset by itself leaves issued session tokens valid, which means the attacker keeps working while you believe you have contained the account.

Over the next one to two weeks, work through your privileged tier. Reset credentials and re-enroll MFA for domain admins, cloud tenant global admins, and any account with standing access to investor, HR, or deal data. Then review your egress evidence. Proxy and cloud access logs will show bulk downloads from SharePoint, Box, or similar repositories, and uploads to consumer file-transfer and cloud storage domains. DNS logs are where you find lookalike domains registered to imitate your SSO portal or your own IT support branding, which is the infrastructure the vishing calls point victims toward.

Preserve this material deliberately. Cloud identity and SaaS audit logs age out on default retention settings, and forensic questions surface weeks after the initial call. Export the relevant windows to cold storage and document chain of custody before your investigators need it.

For the longer effort, hunt persistence that survives a credential reset. That means rogue OAuth grants, added federation trusts, unauthorized service principals, and remote monitoring and management tools such as remote support agents installed outside a change window. Endpoint telemetry should be queried for new remote-access binaries executing from user profile directories.

Third-party access deserves the same scrutiny. Portfolio companies, fund administrators, law firms, and IT contractors often hold standing credentials into your environment, and an intrusion at a private equity firm gives an attacker a path into everything it touches. Inventory every external identity, apply time-bound access, and segment the networks holding personnel and investor records from general corporate systems.

Finally, prepare your people. This group escalates against individuals with threatening messages and swatting attempts, so brief named executives and their families, and open a line to local law enforcement before an incident rather than during one.

Supply-Chain Risk and Third-Party Vendor Exposure

Apollo Global Management is an asset manager, not a payment processor or an identity verification provider, and that distinction shapes how far this incident travels. The firm reported $1.05 trillion in assets under management at the end of June, which places it in the middle of a dense web of fund administrators, custodians, outside counsel, auditors and portfolio company finance teams. Data does not stay inside a firm of that size. It moves through the parties that service the funds.

The more useful signal for you is the target list. This campaign has hit large private equity firms, law firms, financial rating agencies and medical technology companies. Those are the specialist third parties that financial institutions hand their most sensitive material to, and the attackers appear to be working that layer deliberately.

If you are a mid-market lender, insurer or advisory firm, your exposure here is probably not your own perimeter. It is the outside counsel holding your deal files, the rating agency reviewing your issuance, and the administrator running your investor records.

Concentration makes this worse. Researchers told CyberScoop that Blackstone and Bain Capital were also targeted with malicious infrastructure, though it remains unclear whether either was compromised. When several firms in one vertical are approached in the same window, the reason is usually that they share the same short list of service providers, the same outsourced IT desks and the same legal panels. Your vendor questionnaire may show four separate suppliers that all subcontract to the same two.

The financial exposure is measurable. Extortion demands in this campaign often open around $3 million and are typically negotiated down to less than $1 million. That payment, if a vendor makes it, buys a promise about deleted data. It does not transfer to you, and it does not extinguish your obligation to notify the people whose records were in that vendor's environment. You carry the notification cost, the call center cost and the credit monitoring cost for data you never stored yourself.

There is also a timing problem built into most vendor agreements. A firm can spend weeks between confirming unauthorized access and determining which specific records were involved, and standard contract language of "without undue delay" gives you no fixed hour count during that period. Your regulators and your clients will still ask when you knew. If your agreements do not specify a notification window in hours, an audit right, or an obligation to share forensic findings, your visibility into a supplier breach depends entirely on that supplier's willingness to volunteer detail.

The personnel dimension is unusual in this campaign and worth factoring into vendor relationships. Google researchers noted that some victims have faced threatening messages and escalation tactics including swatting. The named contacts in your vendor contracts, the people whose direct lines appear in service agreements, are the same people this crew calls while impersonating IT support. Those individuals become part of the attack surface.

The wider pattern is sector rotation. BlackFile and its affiliates have moved through healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the start of this year before turning toward finance. A supplier that looked low-risk in your last assessment because it sits in an unrelated industry may sit directly in the next rotation. Your third-party risk register reflects a point in time, and this crew changes sectors faster than most firms refresh those reviews.

How third-party exposure reaches your firm
1
Target the service layer
The campaign selects large private equity firms, law firms, financial rating agencies and medical technology companies rather than the institutions they serve. High
2
Exploit shared suppliers
Firms in one vertical are approached in the same window because they share service providers, outsourced IT desks and legal panels. Separate suppliers on a questionnaire may subcontract to the same few.
3
Reach client records
Data held by outside counsel, rating agencies and fund administrators sits outside your perimeter: deal files, issuance reviews and investor records. High
4
Extortion of the vendor
The demand opens high and is typically negotiated down. Any payment buys the vendor a promise about deleted data and does not transfer to you. Medium
5
Notification gap
Confirming unauthorized access and identifying affected records are separate stages, and open-ended contract wording sets no fixed reporting clock. Notification, call center and credit monitoring costs land on you. "without undue delay"

Next Steps: Incident Response and Long-Term Resilience

The most useful detail in Apollo's disclosure is what it says about the rest of the campaign. Apollo is the first organization to formally confirm that personal data under its care was taken, which means the list of affected firms you can see today is smaller than the list that exists. Researchers told CyberScoop that Blackstone and Bain Capital were also targeted with malicious infrastructure, with no confirmation either way on compromise.

If your firm has a business relationship with Apollo, its funds, or its portfolio companies, the first thing worth establishing is whether any of your personnel, investor, or counterparty records sat inside the affected cloud platforms. That is a question for your legal and compliance leads and your incident response retainer, not a question to resolve informally over email with a relationship manager.

Two characteristics of this actor should shape how you plan, separate from any technical work:

  • Extortion pricing: demands often open around $3 million and are typically negotiated down to under $1 million, which tells you the group expects a negotiation and prices to what a target can pay.
  • Escalation against people: Google researchers reported that some victims received threatening messages and were subjected to swatting incidents, so employee safety and HR belong in your response planning, not only IT.
  • Sector rotation: the same crew has hit healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the start of this year before moving to finance.

Being outside private equity does not put you outside the target set. Review your vendor and fund-relationship inventory against the actor profile described here, and document what you find so your legal team has something concrete to work from.

Response steps for firms exposed to the Apollo campaign
1
Establish record exposure
Determine whether your personnel, investor, or counterparty records sat inside the affected cloud platforms tied to Apollo, its funds, or its portfolio companies. High
2
Route through legal and IR
Send the question to legal and compliance leads and the incident response retainer, rather than settling it informally by email with a relationship manager. High
3
Plan for extortion pricing
The group opens with a large demand and typically settles lower, so it expects a negotiation and prices to what a target can pay. Medium
4
Add HR and staff safety
Google researchers reported threatening messages sent to victims and swatting incidents, so employee safety and HR belong in the response plan alongside IT. High
5
Review and document inventory
Check your vendor and fund-relationship inventory against this actor profile, which has moved across healthcare, technology, transportation, logistics, wholesale, retail and hospitality before finance, and record the findings for legal. Medium

In This Article

Top hits