Apollo Global Management (NYSE:APO) disclosed Friday that an intruder accessed its cloud systems and removed a large cache of personal data, putting the private equity firm in the crosshairs of a broader cybercrime push aimed at big financial players.

The company said the attack relied on deception tactics rather than a technical exploit, a detail that can complicate defenses for large organizations.

Benzinga reached out to Apollo Global for comment, but did not receive a response at the time of publication.

A filing with California regulators reported the incident and described a window of access that spanned July 6 through July 10. The letter was signed by Apollo Global Head of Human Capital Matthew Breitfelder.

Breitfelder said the attackers used a social-engineering approach to get into Apollo’s cloud environment. The data taken included names, dates of birth, contact details such as home addresses and Social Security numbers.

The notice did not specify whose information was exposed, leaving open whether the affected group includes Apollo staff, people connected to portfolio companies, or other individuals, TechCrunch reported. 

The confirmation follows warnings from Google security researchers about an extortion-focused campaign that has been aimed at private equity and major financial firms. 

Google said the operators have used multiple monikers, including Falcon, Helix, Pink and Redact, and often pose as internal tech support over the phone to capture passwords and multi-factor authentication codes via fake sign-in pages.

Hackers used phone-based impersonation tactics and fake login pages designed to steal employee credentials. The attackers relied on a social engineering strategy known as “vishing,” calling employees on personal phones while pretending to be internal IT staff. Victims were then directed to fake websites designed to capture passwords and multifactor authentication codes.

Google Principal Threat Analyst Austin Larsen said the campaign appears financially motivated, telling Reuters, “Really, it’s a money thing.” Larsen said the attacks should not necessarily be viewed as highly advanced, adding, “Sophisticated is not the right word. It is just really effective.”

Reuters reported that Point72 Asset Management notified investors it had been targeted, while hedge funds including Two Sigma Investments and Citadel were also identified as potential targets. 

Photo: Image by Piotr Swat via Shutterstock