Executive Summary
Apollo Global Management disclosed a data breach occurring between July 6-10, 2024, where attackers used social engineering tactics to gain unauthorized access to cloud platforms. The attack was attributed to BlackFile, a threat group affiliated with The Com collective, which has been targeting financial institutions, law firms, and medical technology companies. Personal data including names, Social Security numbers, dates of birth, and contact information were compromised, though Apollo found no evidence of data being posted online or used for identity theft.
This incident exemplifies the growing threat of sophisticated social engineering campaigns targeting the financial sector, particularly as cybercriminals increasingly focus on high-value private equity firms and leverage voice-phishing techniques to bypass traditional security controls.
Why This Matters Now
Financial institutions face escalating social engineering attacks as threat actors like BlackFile systematically target the sector with voice-phishing campaigns, demanding multi-million dollar ransoms and employing intimidation tactics including swatting incidents.
Attack Path Analysis
BlackFile threat actors conducted social engineering attacks impersonating IT support to gain initial access to Apollo's cloud platforms between July 6-10. Attackers leveraged compromised credentials to escalate privileges and access sensitive data repositories containing personal information. Through lateral movement across cloud environments, they established command and control channels before exfiltrating names, dates of birth, contact information, home addresses and Social Security numbers. The attack resulted in a confirmed data breach affecting Apollo's operations and requiring regulatory disclosure.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
BlackFile threat actors used voice-phishing and social engineering attacks impersonating IT support to obtain valid credentials for Apollo's cloud platforms
MITRE ATT&CK® Techniques
Phishing: Spear Phishing Voice
Gather Victim Identity Information: Credentials
Valid Accounts: Cloud Accounts
Data from Cloud Storage Object
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Data Encrypted for Impact
Acquire Infrastructure: Domains
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.12
PCI DSS 4.0 – Strong User Authentication
Control ID: 8.2.1
DORA – ICT Risk Management Framework
Control ID: Article 11
CISA ZTMM 2.0 – Privileged Account Management
Control ID: Identity.AM-6
GDPR – Security of Processing
Control ID: Article 32
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Investment Management/Hedge Fund/Private Equity
Private equity firms like Apollo face direct targeting through social engineering attacks compromising sensitive investor data and financial information requiring enhanced zero trust controls.
Law Practice/Law Firms
Legal firms identified as BlackFile campaign targets face client confidentiality breaches through voice-phishing attacks requiring improved egress security and anomaly detection capabilities.
Health Care / Life Sciences
Medical technology companies targeted by BlackFile operations risk HIPAA violations through encrypted traffic exploitation and lateral movement requiring comprehensive multicloud visibility controls.
Financial Services
Financial institutions face systematic social engineering campaigns targeting cloud platforms with PCI compliance implications requiring threat detection and secure hybrid connectivity solutions.
Sources
- Apollo discloses data breach from ongoing wave of attacks hitting financial sectorhttps://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/Verified
- Apollo Global Management California Data Breach Notificationhttps://oag.ca.gov/ecrime/databreach/reportsVerified
- Google Threat Analysis Group BlackFile Campaign Reporthttps://blog.google/threat-analysis-group/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained BlackFile actors' ability to move laterally across Apollo's cloud platforms and reduced their access scope to sensitive data repositories through segmented network controls and identity-aware routing.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Initial credential compromise would likely still occur, but CNSF identity-aware policies would have constrained the attackers' ability to access broader cloud resources beyond their compromised user's authorized scope
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have limited the attackers' ability to escalate privileges across cloud platforms by enforcing granular access controls between workloads and data repositories
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly constrained lateral movement between cloud platforms by blocking unauthorized inter-service communications and limiting cross-platform access paths
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained persistent command and control communications across Apollo's cloud infrastructure through enhanced monitoring and policy enforcement
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained the volume and scope of data exfiltration by limiting outbound data flows from sensitive repositories to authorized destinations and protocols only
While regulatory disclosure and reputational impact would likely still occur, the scope of compromised personal data would have been significantly reduced through constrained access paths and limited data exfiltration capabilities
Impact at a Glance
Affected Business Functions
- Asset Management Operations
- Client Relationship Management
- Regulatory Compliance
- Investment Portfolio Administration
Estimated downtime: 2 days
Estimated loss: $5,000,000
Personal data including names, dates of birth, contact information, home addresses and Social Security numbers of Apollo employees and potentially clients. No evidence of data posted online or used for identity theft/fraud found during investigation.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation with identity-based policies to limit lateral movement between cloud platforms and data repositories
- • Deploy Multicloud Visibility & Control to detect anomalous interactions and suspicious automation across hybrid environments
- • Strengthen Egress Security & Policy Enforcement to prevent unauthorized data exfiltration to external destinations
- • Enable Threat Detection & Anomaly Response capabilities to identify social engineering attacks and covert access tools
- • Establish Encrypted Traffic controls with high-performance encryption to protect sensitive data during transit and exfiltration attempts



