- Apollo Global Management (APO) has confirmed it was hit by a cyberattack as part of a wave targeting private equity and financial services firms.
- The hackers used voice phishing and fake websites to steal credentials, with some victims paying ransoms.
- The campaign highlights growing cyber risks for the financial industry, prompting calls for heightened vigilance.
Apollo Hit in Coordinated Cyberattack
Apollo Global Management confirmed it experienced a data breach, according to a filing with the Securities and Exchange Commission. The private equity firm, which manages assets across credit, private equity, and real assets, said it detected unauthorized activity and took steps to contain the incident. Apollo didn't disclose the extent of the breach or how many clients were affected, but noted that it is cooperating with law enforcement and third-party experts.
The company's confirmation comes amid a broader campaign targeting major Wall Street names, including Blackstone (BX), KKR (KKR), CME Group (CME), and Moody's (MCO), according to reporting from Google and Reuters. The hackers employed sophisticated social engineering techniques—voice phishing calls and fake websites—to trick employees into divulging login credentials. Some affected firms have reportedly paid ransoms to prevent the release of stolen data.
Security researchers have linked the attacks to a group operating under various names, but authorities say the focus has been on financial giants. "These are well-orchestrated attempts to exploit the trust of employees," said a cybersecurity expert familiar with the investigation. "The use of both phone calls and lookalike websites shows a level of effort we don't often see."
Apollo's breach underscores the growing threat to private equity firms, which have become attractive targets due to their access to large sums of capital and sensitive deal information. "These firms are treasure troves of data," noted one analyst. "The potential for financial espionage or market manipulation is high."
Reached for comment, an Apollo spokesperson said that "we take the security of our systems and client data seriously" and that the firm has "engaged leading cybersecurity advisors" to bolster defenses. Similar statements have been issued by other targeted companies, though several have declined to comment on their internal investigations.
The attacks highlight the need for enhanced security protocols across the financial sector, including employee training on social engineering and multi-factor authentication. As one insider put it, "In today's environment, it's not a matter of if, but when a breach will occur. The key is how quickly you can respond."
Update: Since the initial report, Apollo has clarified that the breach was limited to a subset of systems and that no client funds were compromised. The investigation is ongoing.