{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"},"incident":{"title":"Apollo Global Management breached by BlackFile callers posing as IT support","date":"2026-07-06","date_precision":"day","victim_org":"Apollo Global Management","sector":"Financial Services","country":"United States","primary_vector":"Vishing (Voice Phishing)","secondary_vectors":["Help Desk Impersonation"],"ai_involvement":"Unknown","ai_notes":"Researchers described a large pool of human callers recruited for small fees rather than synthetic voice.","outcomes":["Data Breach","Extortion","Identity Theft"],"loss_usd":null,"loss_note":"Apollo did not disclose a figure; researchers said BlackFile typically opens around $3 million and settles under $1 million.","records_affected":null,"threat_actor":"BlackFile (tracked by Google as UNC6671), part of The Com, operating the Redact, Pink, Helix and Falcon extortion brands","summary":"Apollo Global Management disclosed that attackers accessed its cloud platforms between 6 and 10 July 2026, a compromise it discovered on 12 August 2026. Names, dates of birth, contact information, home addresses and Social Security numbers were exposed; Apollo said it had no evidence the data had been posted online or used for fraud. The intrusion is attributed to BlackFile, which gained initial access through voice-phishing calls in which operators impersonated IT support staff.","how_it_worked":"BlackFile industrialised the phone call. Researchers describe hundreds of callers, often low-level people recruited for a small fee or for standing within the group, dialling employees while impersonating internal IT support until one target complies. Volume replaces finesse: the crew averages about 1.5 new victims a day and has hit private equity firms, law firms, ratings agencies and medical technology companies. Once an identity is obtained the operators move into cloud platforms and collect data for extortion, escalating with threatening messages and swatting when victims resist.","lessons":"Phishing-resistant MFA plus a strict no-credentials-over-the-phone policy blunts high-volume calling, and cloud data stores need export alerting because these crews steal rather than encrypt.","confidence":"Confirmed","sources":[{"title":"Apollo discloses data breach from ongoing wave of attacks hitting financial sector","url":"https://cyberscoop.com/apollo-discloses-data-breach-social-engineering-attack/","publisher":"CyberScoop"},{"title":"Details emerge on BlackFile's recent attacks on financial companies","url":"https://cyberscoop.com/blackfile-cyberattacks-financial-sector/","publisher":"CyberScoop"}],"entry_type":"incident","slug":"2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp","year":2026,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2026-apollo-global-management-breached-by-blackfile-callers-posing-as-it-supp"}}