Hackers Tricked Employees at a $938 Billion Firm Into Giving Up Their Passwords

Apollo Global Management has confirmed that hackers stole personal information from its computer systems, according to a letter filed with California's attorney general on August 21, 2026. Apollo's human resources chief, Matthew Breitfelder, said the hackers used a social engineering attack to get into the company's systems between July 6 and July 10, 2026. Social engineering means tricking people into giving up passwords or access codes rather than hacking through technical defenses. The stolen data included names, birth dates, home addresses, and Social Security numbers. Apollo spokesperson Giovanna Falbo did not provide comment when reached by TechCrunch.
Apollo is one of the world's largest private equity firms, with $938 billion in assets under management and about 5,000 employees as of February 2026. The breach is part of a larger hacking campaign known as UNC6671, which has targeted private equity companies and financial giants. Google researchers warned that the attackers rely on social engineering, specifically tricking employees into typing their passwords and multi-factor authentication codes into fake login websites that look real. Reuters reported that Apollo was targeted alongside Blackstone, Bridgewater, Bain Capital, and others.
Hackers built 72 malicious websites aimed at employees at firms including Blackstone, Apollo, and KKR. Google's security researchers said hackers are also calling employees of large U.S. financial firms directly on the phone to steal sensitive data and extort money from victims. Some attacks earned the hackers ransoms as much as $750,000, according to Google. Law firm Greenberg Traurig, also reportedly targeted, released a statement saying its security measures protected client data and prevented a breach. Google's threat intelligence researchers attributed the activity to hackers known by names including Falcon, Helix, Pink, and Redact.
The Mandiant M-Trends 2026 report found that the technology sector overtook finance as the top target of cyberattacks, accounting for 17% of all Mandiant investigations in 2025. The UNC6671 campaign shows a continued, focused threat against financial services. The report covers cyber threats including ransomware recovery denial and extreme persistence. Until 2025, TechCrunch was a subsidiary of Yahoo, an advertising technology company owned by Apollo.
The broader context here is that the Apollo attack relied on social engineering rather than a sophisticated technical hack. The method that compromised Apollo, stealing multi-factor authentication codes through fake login pages, gets around protections that many companies consider strong enough. Multi-factor authentication, or MFA, is the extra step where you enter a code from your phone after typing your password. The problem is that attackers can trick people into entering those codes on fake websites. The technique requires very little technical investment from the hackers. Fake login pages and phone calls to employees work because they take advantage of human trust.
The theft of Social Security numbers and home addresses from a firm of Apollo's size creates risks that extend well beyond Apollo itself. Employees whose data was stored in Apollo's systems face potential identity theft. The combination of Social Security numbers, birth dates, and home addresses gives attackers what they need to run targeted scams and fraud campaigns that could last for months or years.
For people responsible for security at their companies, the Apollo breach and the UNC6671 campaign reinforce the need for protections beyond MFA. Authentication methods that resist phishing, ongoing monitoring for unusual access, and employee training that covers direct phone contact can all reduce risk. The ransom payments of up to $750,000 reported by Google show the campaign is profitable for the attackers, which makes continued targeting more likely.
The fact that a private equity firm with $938 billion in assets was compromised through social engineering rather than a sophisticated technical exploit is a reminder that the weakest link in any security system is still the human being. A firm with Apollo's resources being vulnerable should give pause to smaller organizations with less money to spend on security. Google's research provides a useful baseline for understanding the threat, but the reality is that social engineering campaigns adapt quickly to defenses. The fake websites built to target employees at Blackstone, Apollo, and KKR were likely designed to look enough like real login pages to fool even tech-savvy users. The successful breach at Apollo and the ransoms collected from other targets suggest the attackers behind UNC6671 have found a formula that works. Until financial firms adopt authentication methods that phishing cannot defeat, campaigns like UNC6671 will keep finding victims.


