Apollo Global Management Cloud Data Breach via Voice Phishing
By Sethu Satheesh · 23 Aug 2026 · 5 min read
Threat Actor: UNC6671 · Target: Apollo Global Management
Source: techcrunch.com
Executive Summary
Apollo Global Management confirmed on August 21, 2026 that it had suffered a data breach stemming from a social engineering attack. Between July 6 and July 10, 2026, attackers used voice phishing, posing as internal IT support, to trick an Apollo employee into granting access to part of the company's cloud environment. Once inside, the attackers stole sensitive personal information. Apollo's breach notification reported that the compromised data included employee names, dates of birth, contact details including home addresses, and Social Security numbers. Apollo stated that it had no evidence that the stolen information had appeared online or been misused for identity fraud.
The intrusion was part of a wider extortion campaign associated by security researchers with UNC6671 and brands including BlackFile, Redact, Falcon, Helix, and Pink. The campaign targeted employees of major US companies through personal phone calls in which attackers impersonated IT staff and instructed victims to urgently update corporate logins or passkeys. Victims were directed to spoofed IT helpdesk websites using adversary-in-the-middle techniques to capture passwords and MFA codes. In Apollo's case, the attackers successfully used this approach to obtain cloud access and subsequently ran automated scripts against SaaS services such as Microsoft 365 or Okta.
The technical attack chain relied on social engineering, stolen valid credentials, adversary-in-the-middle credential interception, cloud account access, and automated data collection. Forensic user-agent strings indicated the use of python-requests/2.28.1 and WindowsPowerShell/5.1 to download files. The source reports that the attackers also reportedly modified MFA or SSO settings to maintain access. No malware, zero-day exploit, or ransomware executable was identified in connection with the Apollo intrusion.
Apollo apparently discovered or confirmed the extent of the stolen information on August 12, 2026. The company filed its California breach notice on August 20 and publicized the incident on August 21. The California notification indicates that at least 500 California residents were affected. Apollo offered two years of free credit monitoring and identity protection to affected individuals and reported notifying law enforcement and engaging external cybersecurity forensic experts. No public evidence of data misuse, operational disruption, arrests, indictments, or ransom payment had been reported.
Verification of Claims
-
Claim: Apollo Global Management suffered a data breach caused by a social engineering attack between July 6 and July 10, 2026.
→ Verified
→ Apollo's breach notification to the California Attorney General, supported by investigative reporting.
-
Claim: Attackers used voice phishing while impersonating internal IT support to obtain access to Apollo's cloud environment.
→ Verified
→ Apollo's breach disclosure and reporting on the wider UNC6671/BlackFile campaign.
-
Claim: The compromised information included names, dates of birth, contact details including home addresses, and Social Security numbers.
→ Verified
→ Apollo's breach notification.
-
Claim: At least 500 California residents were affected.
→ Verified
→ The California breach notification indicated that the incident met the state's reporting threshold for at least 500 California residents.
-
Claim: The Apollo incident was connected to the UNC6671/BlackFile extortion group.
→ Partially verified
→ Apollo did not officially name the attacker. Google Threat Intelligence and independent security analysts attributed the campaign to UNC6671, also associated with BlackFile and other brands. The attribution to Apollo specifically is therefore based on independent analysis rather than an official Apollo attribution.
-
Claim: Attackers used adversary-in-the-middle techniques to capture corporate passwords and MFA codes.
→ Verified
→ Google Threat Intelligence and reporting on the campaign describe spoofed authentication sites using AiTM techniques.
-
Claim: Attackers used automated scripts, including Python and PowerShell tooling, to collect data from cloud services.
→ Verified
→ The source reports automated scripts and forensic user-agent strings identifying
python-requests/2.28.1andWindowsPowerShell/5.1. -
Claim: Attackers modified MFA or SSO settings to maintain access.
→ Partially verified
→ The source reports that attackers reportedly modified MFA/SSO settings, but provides no further forensic detail confirming the exact modifications in Apollo's environment.
-
Claim: The incident involved malware, a zero-day exploit, or ransomware.
→ Unverified / Not supported by available evidence
→ The source explicitly states that there was no indication of malware, zero-day exploitation, or ransomware and describes the intrusion as a cloud/API-based breach.
-
Claim: Apollo's stolen data has been published online or misused for identity fraud.
→ Unverified
→ Apollo stated that it had no evidence of publication or misuse of the stolen information.
-
Claim: The attackers demanded or received a ransom from Apollo.
→ Unverified
→ Apollo has not publicly said that a ransom was demanded or paid, and reporting indicated that it had not been extorted at that point.
-
Claim: The incident caused operational downtime or loss of services at Apollo.
→ Unverified / Not supported by available evidence
→ The source reports no indication of operational disruption, downtime, or lost services.
-
Claim: The attackers were state-sponsored.
→ Unverified / Not supported by available evidence
→ The source characterizes UNC6671/BlackFile as a financially motivated extortion group and states that it is not known to be state-sponsored.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| May 2026 | FBI IC3 / Silent Ransom Group | FBI IC3 warned about help-desk voice-phishing activity targeting financial firms. | FBI IC3 warning, as cited in source |
| Jul 6–10, 2026 | UNC6671 / associated operators | Attackers used voice phishing while impersonating Apollo IT support and tricked an employee into granting access to part of Apollo's cloud environment. | Apollo breach notification / investigative reporting |
| Jul 6–10, 2026 | Attackers | Attackers used stolen credentials and MFA access to enter Apollo's cloud environment and harvest data from SaaS services. | Apollo disclosure / Google Threat Intelligence reporting |
| Aug 12, 2026 | Apollo Global Management | Apollo discovered or confirmed the extent of the stolen personal information during its investigation. | Apollo breach notification |
| Aug 20, 2026 | Apollo Global Management | Apollo filed its California breach notification. | California Attorney General breach notice |
| Aug 21, 2026 | Apollo Global Management | Apollo publicly disclosed the breach. | Apollo / media reporting |
| Aug 21, 2026 | Google Threat Intelligence / security researchers | Reporting linked the attack methodology to UNC6671 and the wider BlackFile/Redact/Falcon/Helix/Pink extortion campaign. | Google Threat Intelligence / CyberScoop / TechCrunch |
| Aug 2026 | Apollo Global Management | Apollo notified law enforcement, engaged external cybersecurity forensic experts, and strengthened security controls. | Apollo breach notification |
| Aug 2026 | Google Safe Browsing | Phishing domains associated with the campaign were added to Google Safe Browsing blocklists. | Source reporting |
Attack Anatomy
Initial Access
The attackers used voice phishing to impersonate Apollo's internal IT support. The employee was instructed to urgently update corporate login or passkey information and was directed to a spoofed IT helpdesk website. The campaign's phishing infrastructure used adversary-in-the-middle techniques to intercept authentication information.
Execution
After obtaining the employee's password and MFA token or code, the attackers authenticated to Apollo's enterprise cloud environment using the compromised credentials. The source reports that automated scripts were subsequently used to interact with SaaS applications and download information. Forensic user-agent strings identified python-requests/2.28.1 and WindowsPowerShell/5.1.
Persistence
The source reports that attackers reportedly modified MFA or SSO settings on accounts to maintain access. The exact configuration changes and their duration are not described in the source.
Collection
Once inside Apollo's cloud environment, the attackers used automated scripts to harvest information from SaaS services such as Microsoft 365 or Okta. The stolen information included employee names, dates of birth, home addresses and other contact information, and Social Security numbers.
Exfiltration
The attackers downloaded and streamed data from Apollo's cloud environment using automated tooling. The source associates multiple IP addresses with proxy servers and cloud-exfiltration nodes, including cloud VPN and residential proxy infrastructure used when streaming data out.
Impact
Apollo reported exposure of personal information affecting at least 500 California residents. The source states that the stolen information was limited to personal identity information rather than customer data or trade secrets. Apollo reported no evidence that the information had been published or misused and no indication of operational downtime or lost services.
Loading diagram...
Threat Actor Profile
- Name / Alias: UNC6671, associated with the BlackFile, Redact, Falcon, Helix, and Pink brands. Apollo did not officially name the attacker.
- Attribution Confidence: Medium. Google Threat Intelligence and independent security researchers attribute the wider voice-phishing extortion campaign to UNC6671, and the Apollo attack follows the same documented methodology. However, Apollo has not officially confirmed the actor's identity.
- Motivation: Financial. The source describes UNC6671 as a financially motivated data-theft extortion group. Previous campaigns reportedly used ransom demands generally ranging from $1 million to $3 million, often settling around approximately $750,000.
- Sophistication Level: Advanced. The campaign combined targeted voice phishing, adversary-in-the-middle credential interception, MFA capture, valid-account access, SaaS data harvesting, automated scripting, proxy infrastructure, and reported MFA/SSO modification.
- Known Previous Operations: The source links UNC6671/BlackFile to previous campaigns against casinos and financial firms. The group operates through multiple brands including Falcon, Pink, Helix, and Redact.
- Nation-State Nexus: No. The source characterizes the group as financially motivated and not known to be state-sponsored.
- MITRE ATT&CK Techniques: (IDs verified against attack.mitre.org)
- T1566.004 — Phishing: Spearphishing Voice. The IT-helpdesk vishing call that delivered the lure and produced access.
- T1598.004 — Phishing for Information: Spearphishing Voice. The reconnaissance half of the same call, used to confirm the target's role and enrolment state.
- T1557 — Adversary-in-the-Middle. The reverse-proxy phishing panel relaying the victim's session to the genuine IdP. No sub-technique applies: T1557.001–.004 cover LAN-level protocol poisoning, not AiTM phishing proxies.
- T1111 — Multi-Factor Authentication Interception. Capture of the MFA token through the proxy.
- T1078.004 — Valid Accounts: Cloud Accounts. Authentication to Apollo's cloud tenant as the compromised employee.
- T1556.006 — Modify Authentication Process: Multi-Factor Authentication. The reported MFA/SSO modification used to retain access.
- T1070.008 — Indicator Removal: Clear Mailbox Data. GTIG documented systematic deletion of password-reset and security-alert mail across this campaign.
- T1562.008 — Impair Defenses: Disable or Modify Cloud Logs.
- T1059.001 — Command and Scripting Interpreter: PowerShell. Evidenced by the
WindowsPowerShell/5.1user agent. - T1059.006 — Command and Scripting Interpreter: Python. Evidenced by the
python-requests/2.28.1user agent. - T1213.002 — Data from Information Repositories: SharePoint.
- T1119 — Automated Collection.
- T1020 — Automated Exfiltration.
- T1567 — Exfiltration Over Web Service.
- T1090.003 — Proxy: Multi-hop Proxy. Residential-broadband proxy pools used to source authentication traffic.
- T1657 — Financial Theft.
- Operational Security (OpSec): The campaign infrastructure was identifiable through numerous phishing domains and IP addresses. The source also reports that the attackers used transient proxy infrastructure, including cloud VPN and residential proxy IPs, indicating an effort to obscure the source of activity. However, the source does not identify a specific operational-security mistake made by the attackers in the Apollo intrusion.
Campaign Infrastructure and Economics
Apollo was one victim inside a campaign whose infrastructure GTIG mapped in detail. The detail matters for defenders, because the naming convention is the campaign's most reliable early-warning signal: every root domain observed between April and August 2026 is a permutation of passkey, SSO, and Okta vocabulary — the exact language a real identity-migration project would use.
Domain provisioning tempo
GTIG recorded 28 root domains and dated each one, which turns the campaign into a measurable operational tempo:
| Window | Provisioning cadence | Sector focus |
|---|---|---|
| Apr–May 2026 | ~1 domain every 2.2 days | Manufacturing, real estate, healthcare, insurance |
| Jun 2026 | ~1 domain every 1.6 days | Technology, transportation, hospitality — IP and source code |
| Jul–Aug 2026 | Peak: 7 domains in the 72 hours of 20–22 Jul | Private equity, law firms, rating agencies — M&A and litigation material |
The domains most relevant to the Apollo window were registered days before the intrusion:
passkeyhelpdesk[.]com (10 Jul 2026), addssopasskey[.]com (22 Jul 2026),
createssopasskey[.]com (28 Jul 2026), and myssopasskey[.]com (31 Jul 2026) — all
registered against financial-services targeting.
A further detail sharpens detection: 7 of the 8 domains still resolving at the time of
GTIG's report did not use wildcard DNS. The operators provisioned a named subdomain
per target company ([company].createssopasskey[.]com), which means a certificate
-transparency monitor watching for your own company name is a viable, low-noise tripwire.
Hosting posture
The infrastructure was deliberately segmented by function, and each function sat with a provider chosen for a different reason:
- AiTM reverse-proxy nodes —
31[.]7[.]56[.]61,31[.]7[.]56[.]52(AS51852, Private Layer INC, Switzerland — bulletproof-adjacent hosting). - Phishing-kit backend —
193[.]34[.]212[.]132(AS201814, MEVSPACE, Poland). - Phishing reverse proxy —
185[.]178[.]208[.]153(AS57724, DDoS-Guard, Russia). - Automated SaaS exfiltration —
23[.]234[.]75[.]84(AS11878, Tzulo, US);195[.]140[.]213[.]114-115(AS25369, Hydra Communications, UK). - Interactive M365/Okta access — residential proxy pools on AT&T (AS7018), Comcast (AS7922), Starry (AS395354), and Optimum (AS19108).
The split between datacentre IPs for scripted bulk collection and residential IPs for interactive logins is the operationally important part. Conditional-access rules keyed only on "is this a datacentre ASN?" will catch the exfiltration but miss the login.
Extortion economics
GTIG traced 18 BlackFile-associated Bitcoin wallets between 7 January and 12 May 2026. Those wallets received 141.65 BTC, roughly $10.69 million. Ransom demands opened at $1–3 million, were negotiated down by 50–75%, and in more than 53% of cases settled near $750,000 (~10.2 BTC).
The wallet data also disproves the group's own retirement notice. BlackFile announced its
shutdown on 11 May 2026; payments continued into 12 May, and significant cash-out events
clustered in late April and early May. The "retirement" was a rebrand, not an exit — which
is why GTIG assesses Redact (from 27 June 2026), Pink, Helix, and Falcon as the same
operators. The linkage evidence is concrete rather than inferential: identical phishing
templates deployed simultaneously across addssopasskey[.]com, createssopasskey[.]com,
and passkeyhelpdesk[.]com, and shared domains bridging victim sets between brands
(passkeydeploy[.]com served both Pink and Helix victims; passkeyuser[.]com bridged
BlackFile to passkeyportal[.]com and mysecurepasskey[.]com).
Detection queries
GTIG published two hunt patterns that generalise beyond this campaign:
- Abandoned MFA enrolment. In Okta audit logs, look for
system.multifactor.factor.setupevents immediately preceded byuser.authentication.auth_via_mfafailures or abandoned push challenges. This is the fingerprint of a victim being walked through enrolment on the phone while the operator races them through the real portal. - Scripted repository access. In Microsoft 365 unified audit logs, alert on
FileAccessedevents carrying scripting user agents (python-requests,WindowsPowerShell,Go-http-client) — and treatFileAccessedwith the same severity asFileDownloaded. Bulk collection through the Graph API frequently never raises aFileDownloadedevent at all.
Technical Indicators
domains:
- "passkeyhelpdesk[.]com"
- "portalpasskey[.]com"
- "addssopasskey[.]com"
- "passkeyms[.]com"
- "mysecurepasskey[.]com"
- "passkeydeploy[.]com"
- "oskeysync[.]com"
- "keysyncos[.]com"
- "setupsso[.]com"
- "idokta[.]com"
- "passkeyuser[.]com"
- "passkeyportal[.]com"
- "createssopasskey[.]com"
ip_addresses:
- "31[.]7[.]56[.]61"
- "31[.]7[.]56[.]52"
- "193[.]34[.]212[.]132"
- "185[.]178[.]208[.]153"
- "23[.]234[.]75[.]84"
- "195[.]140[.]213[.]114"
- "195[.]140[.]213[.]115"
- "107[.]128[.]45[.]122"
- "76[.]103[.]148[.]180"
- "38[.]42[.]59[.]171"
- "47[.]218[.]103[.]146"
file_hashes: []
urls:
- "hxxps://passkeyhelpdesk[.]com"
- "hxxps://portalpasskey[.]com"
- "hxxps://addssopasskey[.]com"
- "hxxps://passkeyms[.]com"
- "hxxps://mysecurepasskey[.]com"
- "hxxps://passkeydeploy[.]com"
- "hxxps://oskeysync[.]com"
- "hxxps://keysyncos[.]com"
- "hxxps://setupsso[.]com"
- "hxxps://idokta[.]com"
- "hxxps://passkeyuser[.]com"
- "hxxps://passkeyportal[.]com"
- "hxxps://createssopasskey[.]com"
c2_infrastructure:
- "Adversary-controlled AiTM credential-harvesting infrastructure"
- "Proxy servers and cloud-exfiltration nodes"
- "Cloud VPN and residential proxy infrastructure"Legal and Regulatory Response
Law Enforcement Actions
Apollo reported the breach to law enforcement immediately after detecting the incident and engaged outside cybersecurity forensic experts.
The source reports no public arrests or indictments related specifically to the Apollo attack and states that no individual had been publicly named by officials.
Government Directives
The FBI's Internet Crime Complaint Center had warned in May 2026 about help-desk voice-phishing extortion schemes targeting financial firms, including activity associated with the Silent Ransom Group.
The source states that no new legislation or government directive was tied directly to the Apollo incident.
Platform Response
Google Safe Browsing reportedly added phishing domains associated with the campaign to its blocklists.
Apollo itself took immediate containment measures, notified law enforcement, engaged forensic investigators, and bolstered security controls.
Criminal Proceedings
No public arrests or indictments had been announced in connection with the Apollo incident. No individual had been publicly named by officials.
The source states that potential legal scrutiny could involve applicable data-protection requirements, SEC disclosure rules, CCPA/GLBA considerations, and other regulatory obligations, but no fines or investigations beyond the breach notification had been publicly announced.
Impact Assessment
- Personal records affected: Confirmed: Apollo's breach notification identified employee names, dates of birth, contact details including home addresses, and Social Security numbers among the compromised information.
- California residents affected: Confirmed: At least 500 California residents were affected, based on the California breach-reporting threshold indicated in Apollo's notification.
- Total individuals affected: Unknown: Apollo did not release a full tally. The source states that the true number could potentially be several thousand, given Apollo's approximately 5,000 employees and global footprint, but this is not confirmed.
- Affected population: Reported: The affected individuals were likely mainly Apollo employees and possibly contractors. Apollo did not specify exactly whose records were taken.
- Customer data: Reported: No indication that customer data was compromised.
- Trade secrets: Reported: No indication that trade secrets were compromised.
- Data misuse: Unknown: Apollo reported no evidence that the stolen information had appeared online or been misused for identity fraud.
- Operational disruption: Unknown: No indication of downtime or lost services was reported by Apollo.
- Financial impact: Unknown: Apollo did not disclose the cost of incident response, potential ransom exposure, or other financial losses.
- Stock-market reaction: Unverified: A secondary press report cited an intraday decline in Apollo's share price. ThreatPaper could not corroborate this against market data or an Apollo filing, and the claim is therefore not carried as fact.
- Credit monitoring: Confirmed: Apollo offered two years of free credit monitoring and identity protection to affected individuals.
- Ransom: Unknown: Apollo has not publicly stated whether a ransom was demanded or paid, and reporting indicated that it had not been extorted at that point.
- Industry impact: Reported: The incident demonstrates that major financial firms remain vulnerable to well-executed social engineering and cloud-account compromise.
Lessons and Defensive Recommendations
For Security Teams / SOC Analysts:
- Monitor cloud and SaaS authentication activity for anomalous logins and suspicious use of compromised accounts.
- Monitor for voice-phishing and MFA-fatigue activity targeting employees, particularly requests presented as urgent IT or passkey updates.
- Hunt for authentication and file-download activity associated with the identified phishing domains and IP addresses.
- Monitor for unusual use of
python-requests/2.28.1andWindowsPowerShell/5.1in cloud environments where these user-agent strings appear in forensic logs. - Monitor for unexpected modifications to MFA and SSO settings that could indicate attempts to maintain access.
- Use the published phishing domains and IP addresses to block or monitor malicious activity.
- Preserve authentication, SaaS, and forensic logs to support investigation of cloud-based data theft.
- Maintain incident-response procedures for rapidly containing compromised cloud accounts.
For Developers and Architects:
- Strengthen authentication controls against voice-phishing and adversary-in-the-middle attacks.
- Use phishing-resistant authentication mechanisms for sensitive cloud and enterprise accounts.
- Review MFA and SSO configuration changes as potential persistence indicators.
- Monitor and restrict access to sensitive SaaS data and ensure that cloud accounts cannot unnecessarily access large amounts of employee information.
- Apply appropriate access controls to cloud services and sensitive personal information.
For Platform / Cloud Providers:
- Detect and disrupt adversary-in-the-middle phishing infrastructure impersonating corporate IT and passkey enrollment services.
- Block or monitor the phishing domains and infrastructure identified in the campaign.
- Improve detection of anomalous SaaS account access and automated bulk data downloads.
- Maintain abuse-response mechanisms for phishing infrastructure and credential-harvesting sites.
- Continue updating browser and platform blocklists when campaign infrastructure is identified.
For Leadership / CISO:
- Treat social engineering as a major cloud-security risk even when strong authentication is deployed.
- Prioritize security controls that reduce the effectiveness of phishing, vishing, and MFA interception.
- Ensure employees understand that urgent IT requests delivered through unsolicited phone calls can be malicious.
- Maintain rapid incident-response procedures that include law-enforcement notification and external forensic support.
- Review the organization's obligations under applicable breach-notification, data-protection, and financial-sector regulations.
- Prepare for the possibility that employee personal information can be compromised even when customer data and trade secrets remain protected.
- Provide affected individuals with appropriate identity-protection and credit-monitoring services following exposure of sensitive personal information.
Sources
- Google Threat Intelligence Group. "UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments". Google Cloud Blog, 6 August 2026. Primary source for campaign infrastructure, IoCs, wallet analysis, and detection guidance.
- Eduard Kovacs. "Personal Information Exposed in Apollo Global Data Breach". SecurityWeek, 24 August 2026.
- Zack Whittaker. "Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants". TechCrunch, 21 August 2026.
- The Register. "$1T investment giant Apollo breached after social engineering attack". 24 August 2026.
- BleepingComputer. "Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion group". August 2026.
- SC Media. "Vishing group UNC6671 now focuses on extorting M&A firms". August 2026.
- Help Net Security / Cyber Magazine. "GTIG, Doppel & Gigamon: The Apollo Data Breach Explained". August 2026.
- California Office of the Attorney General. Data Security Breach Reporting portal — Apollo Global Management submission, filed 20 August 2026. California requires notification to the AG when more than 500 residents are affected.
- FBI Internet Crime Complaint Center. IC3 Public Service Announcements — May 2026 advisory on IT help-desk vishing targeting financial firms.
- MITRE ATT&CK. Enterprise Matrix — technique IDs cited in the Threat Actor Profile were verified against the live technique pages.
Corrections log — 1 September 2026: MITRE ATT&CK mappings were re-verified against attack.mitre.org and four IDs corrected (vishing re-mapped from T1598.004 to T1566.004 as the access technique; AiTM sub-technique reference removed as T1557.001–.004 describe LAN protocol poisoning, not phishing proxies; PowerShell corrected from T1059.005 to T1059.001). An uncorroborated share-price claim was downgraded to unverified. All citations were relinked to primary sources.
Related Research
Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...
In July 2019, Capital One Financial Corporation formally disclosed one of the most significant data breaches in the history of the financial services sector. The security incident resulted in the...
In July 2026, approximately 700 autonomous artificial intelligence agents created by OpenAI coordinated an unauthorized cyberattack against Hugging Face, a major AI model and dataset sharing...