Apollo Acknowledges Cloud Breach: A Social Engineering Catastrophe
Apollo Global Management has confessed that they were outsmarted by some sly hackers who charmed their way into its cloud systems and stole Social Security numbers along with other personal information. The investment giant revealed this in a notification to California’s attorney general, estimating that it had experienced a “social engineering incident” which resulted in unauthorized access to “certain cloud platforms” from July 6 to July 10.
The Enigma of the Breach
Apollo is tight-lipped about which cloud platforms were compromised, how the intruders gained access, or how many individuals were affected by this incident. What they disclosed is that on August 12, they discovered the leaked information potentially included names, birth dates, contact numbers, home addresses, and Social Security numbers. So far, there are no indications that the information has been spread across the internet or utilized for any nefarious identity theft. Nevertheless, they have generously offered 24 months of credit monitoring and identity protection for those impacted. Every cloud, right?
Apollo’s Reaction to the Breach
Matthew Breitfelder, Apollo’s head of human capital, stated that they notified law enforcement, enlisted top-tier cybersecurity and forensic professionals, enhanced their security measures, and initiated an investigation as soon as they detected the breach. All personnel are engaged at Apollo, then.
The Broader Context: Similar Incidents in the Financial Sector
This security debacle follows Google’s warning regarding UNC6671, a notorious extortion group referred to as “BlackFile,” which has been troubling private equity firms and other financial businesses. Reuters suggested that Apollo was among their targets back then, along with Blackstone, Bridgewater, and Bain Capital. However, it was uncertain if the assaults had any effect. Apollo’s admission now verifies that, at least for them, someone indeed crossed the line.
UNC6671’s Deceptive Strategies
Google’s experts allege that UNC6671 have been calling employees on their personal phones, masquerading as coworkers or IT support, then guiding them to fraudulent login pages to capture credentials and multi-factor authentication codes. Once they gain access, they steal corporate data and threaten to sell it unless the target pays up. Some individuals have reportedly paid as much as $750,000, according to Google’s specialists.
Rising Trend of Targeting Employees Instead of Systems
This commotion is merely the latest in a series of assaults where the perpetrators concentrate on employees rather than breaching corporate technological defenses. Earlier this month, Levi Strauss was caught off guard when social engineers compromised three employees’ workstations and stole their corporate data. For Apollo, there’s still significant uncertainty regarding whose Social Security numbers were compromised and how many individuals should now monitor their credit reports meticulously.
Summary: A Social Engineering Drama of Epic Proportions
So there you have it, another day, another tech blunder in the expansive world of business. Apollo fell victim to a social engineering fiasco, and while investigators work on the case, the rest of you should remain vigilant with your own information. If it’s not one thing, it’s your credit report!