What Happened
Private equity firm Apollo Global Management disclosed a data breach stemming from a social engineering attack, which gave intruders unauthorized access to some of its cloud platforms between July 6 and July 10. The exposed information includes names, dates of birth, home addresses, contact information, and Social Security numbers belonging to an undisclosed number of individuals. Apollo says it found no evidence the stolen data appeared for sale or use in identity theft, and it is offering affected individuals 24 months of complimentary credit monitoring and identity protection. The breach follows earlier Google warnings naming the extortion group UNC6671, tracked under aliases including Falcon, Helix, Pink, and Redact, as targeting Apollo alongside other private equity and financial firms including Blackstone, Bridgewater, and Bain Capital.
Why This Matters for Canadian Organizations
UNC6671 and similar crews rely on phone-based impersonation of IT helpdesk staff to trick employees into entering credentials and multi-factor codes on spoofed login portals, a tactic requiring no software exploit and bypassing traditional perimeter defenses entirely. Canadian financial institutions, pension funds, and asset managers operate in the same global market as Apollo and face the same social engineering playbook, and the campaign’s focus on private equity and financial services firms places Canadian counterparts squarely inside the threat actor’s target profile. Entities under OSFI Guideline B-13 face regulatory expectations around technology and cyber risk management extending to employee-targeted social engineering defenses, not only technical controls, and firms handling personal information under PIPEDA carry notification duties if similar tactics succeed against Canadian operations.
What to Do
Financial sector security teams should treat this campaign as an active threat rather than a one-off incident, given its pattern of targeting named firms in sequence. Priority steps include hardening helpdesk verification procedures against caller impersonation, enforcing phishing-resistant multi-factor authentication such as hardware security keys for cloud platform access, and running targeted awareness training referencing this specific vishing and spoofed-portal pattern. Additional detail on the breach and the broader campaign is available from SecurityWeek and TechCrunch.






