Apollo Global Confirms Data Breach Following UNC6671 Vishing Attack on Wall Street Firms

Apollo Global Management confirmed a breach that exposed personal data of clients after a vishing attack by the UNC6671 group, which targeted dozens of Wall Street firms between July and August 2026.
Apollo Global Management confirmed on August 21 that hackers accessed its cloud infrastructure between July 6 and July 10, extracting personal data from an undisclosed group of clients and employees, including names, birth dates, residential addresses, and contact information. The American firm, which manages over $650 billion in assets, became the highest-profile private equity firm to publicly confirm an intrusion resulting from a coordinated extortion campaign monitored by the Google Threat Intelligence Group since January 2026.
The Group Behind the Attacks
The responsible party is UNC6671, tracked by Google as an extortion organization that operated under the BlackFile brand until May 2026 and has since operated under aliases REDACT (announced on June 27), PINK, HELIX, and FALCON, each with its own data leak portal. The rebranding did not change the method: operators call employees' personal cell phones, identifying themselves as IT teams conducting an urgent security migration or FIDO2 key registration. Victims are directed to customized phishing portals structured as subdomains like [company].createssopasskey[.]com, where an Adversary-in-the-Middle infrastructure captures credentials and MFA tokens in real time. There is no CVE in the attack framework: exploitation is exclusively social engineering.
Scale of the Operation
UNC6671 registered over 60 phishing domains between January and August 2026, at a frequency of one domain every 1.6 to 2.2 days. The report by the Google Threat Intelligence Group, published on August 6, identified at least 141.65 BTC in tracked payments between January and May, equivalent to about $10.69 million, with initial demands ranging from $1 million to $3 million and final agreements around $750,000 in more than 53% of cases. The target environments after access are Microsoft 365 and Okta; automated scripts identified by Google, using user agents such as python-requests/2.28.1 and WindowsPowerShell/5.1, perform bulk exfiltration.
The group shifted its sector focus throughout 2026: manufacturing, healthcare, and real estate from April to May; technology and hospitality in June; and financial and legal sectors from July onward. Reuters reported that UNC6671's phishing infrastructure was built to target Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody's, among dozens of other firms. As of the publication deadline of this article, Apollo was the only firm to confirm successful access. The firm stated that it has notified the appropriate authorities and is offering credit monitoring and identity protection for affected individuals; the total number of impacted persons was not disclosed.
Exposure That Crosses Borders
The campaign uses residential proxies from subnets in Switzerland (Private Layer, AS51852) and Poland (MEVSPACE, AS201814), rendering geographic blocks ineffective. The targeted firms have offices in London, Frankfurt, Tokyo, and São Paulo; compromised Microsoft 365 and Okta credentials provide access to local systems regardless of the impacted employee's region.
For security teams in Brazil, the UK, and Japan, the risk vector is structurally identical to that of the U.S.: internal helpdesks with limited coverage outside of local business hours are the most exploited point by UNC6671. Google recorded a peak of phishing domain registrations between July 20 and July 22, concentrated in windows outside standard American business hours, precisely when the responsiveness of security teams is reduced.
The group’s successful attacks in the European financial sector have not yet been publicly confirmed, but the profile of targets—private equity firms and hedge funds with global portfolios and small security teams—is common across all geographies. In Latin America, medium-sized firms with operations based on Microsoft 365 and Okta are exposed to the same vector without necessarily having continuous identity monitoring.
Public Disclosure Changes the Regulatory Calculation
Apollo's transparency is atypical in the private equity sector, which has historically preferred confidential settlements with regulators over public announcements. This move likely reflects SEC rules for asset managers that have been in effect since 2025, which require notification of material incidents within four business days after determining materiality.
Regulators in the UK (FCA) and Europe (ESMA) are monitoring UNC6671's campaign and may enact similar notification obligations for firms operating within their jurisdictions. For the dozens of firms that have not confirmed any intrusion, silence is no longer a neutral choice: in a regulatory regime that equates omission with negligence, being the second to confirm is preferable to being found without having reported.