Executive Summary

Apollo Global Management disclosed a data breach occurring between July 6-10, 2024, where attackers used social engineering tactics to gain unauthorized access to cloud platforms. The attack was attributed to BlackFile, a threat group affiliated with The Com collective, which has been targeting financial institutions, law firms, and medical technology companies. Personal data including names, Social Security numbers, dates of birth, and contact information were compromised, though Apollo found no evidence of data being posted online or used for identity theft.

This incident exemplifies the growing threat of sophisticated social engineering campaigns targeting the financial sector, particularly as cybercriminals increasingly focus on high-value private equity firms and leverage voice-phishing techniques to bypass traditional security controls.

Why This Matters Now

Financial institutions face escalating social engineering attacks as threat actors like BlackFile systematically target the sector with voice-phishing campaigns, demanding multi-million dollar ransoms and employing intimidation tactics including swatting incidents.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Personal information including names, Social Security numbers, dates of birth, contact information, and home addresses were compromised during the July 2024 attack.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained BlackFile actors' ability to move laterally across Apollo's cloud platforms and reduced their access scope to sensitive data repositories through segmented network controls and identity-aware routing.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Initial credential compromise would likely still occur, but CNSF identity-aware policies would have constrained the attackers' ability to access broader cloud resources beyond their compromised user's authorized scope

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Zero trust segmentation would likely have limited the attackers' ability to escalate privileges across cloud platforms by enforcing granular access controls between workloads and data repositories

Lateral Movement

Control: East-West Traffic Security

Mitigation: East-west traffic controls would likely have significantly constrained lateral movement between cloud platforms by blocking unauthorized inter-service communications and limiting cross-platform access paths

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Multicloud visibility controls would likely have detected and constrained persistent command and control communications across Apollo's cloud infrastructure through enhanced monitoring and policy enforcement

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Egress security policies would likely have constrained the volume and scope of data exfiltration by limiting outbound data flows from sensitive repositories to authorized destinations and protocols only

Impact (Mitigations)

While regulatory disclosure and reputational impact would likely still occur, the scope of compromised personal data would have been significantly reduced through constrained access paths and limited data exfiltration capabilities

Impact at a Glance

Affected Business Functions

  • Asset Management Operations
  • Client Relationship Management
  • Regulatory Compliance
  • Investment Portfolio Administration
Operational Disruption

Estimated downtime: 2 days

Financial Impact

Estimated loss: $5,000,000

Data Exposure

Personal data including names, dates of birth, contact information, home addresses and Social Security numbers of Apollo employees and potentially clients. No evidence of data posted online or used for identity theft/fraud found during investigation.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to limit lateral movement between cloud platforms and data repositories
  • Deploy Multicloud Visibility & Control to detect anomalous interactions and suspicious automation across hybrid environments
  • Strengthen Egress Security & Policy Enforcement to prevent unauthorized data exfiltration to external destinations
  • Enable Threat Detection & Anomaly Response capabilities to identify social engineering attacks and covert access tools
  • Establish Encrypted Traffic controls with high-performance encryption to protect sensitive data during transit and exfiltration attempts

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image