Apollo Global Management, a leading New York-based asset manager, announced a data breach that compromised personal information of some employees following a series of targeted cyber intrusions against major US financial institutions using social engineering phone tactics.
- Unauthorized access to Apollo’s cloud systems in early July
- Personal employee data including social security numbers compromised
- Cybercriminals used phone-based social engineering tactics
What happened
In early July, hackers gained unauthorized access to certain cloud platforms used by Apollo Global Management, a major US asset management firm. The breach specifically occurred between July 6 and July 10, exposing sensitive employee information. Details potentially accessed include names, dates of birth, contact information, home addresses, and social security numbers.
This breach is part of a broader pattern of ransomware-linked cyberattacks targeting dozens of prominent US financial institutions and other high-profile companies. Attackers employed low-tech but effective methods such as phone calls to trick employees into divulging credentials or security details, allowing attackers to penetrate their systems.
Why it matters
The incident highlights continuing vulnerabilities in the financial sector, despite advanced cybersecurity programs. The use of social engineering through phone calls demonstrates how attackers can bypass sophisticated defenses by exploiting human factors within organizations.
Compromise of personally identifiable information such as social security numbers carries significant risks for affected individuals, including potential identity theft and fraud. Apollo’s response, including offering identity protection and credit monitoring, illustrates the growing need for companies to mitigate damage from such breaches and reassure stakeholders.
What to watch next
Apollo’s investigation is ongoing, and the firm has yet to find evidence that stolen data has been publicly posted or misused. Continued monitoring of the situation will be critical to detect any emerging misuse of the compromised information.
More broadly, industry observers should watch for increased efforts by financial institutions to strengthen social engineering defenses and improve employee awareness training. Additionally, regulators and cybersecurity experts may push for updated protocols to counteract the resurgence of phone-based hacking techniques.