The Hackers Picking Off Private Equity One Phone Call at a Time
Hackers just walked out of a $938 billion asset manager with a phone call and a fake login page. The targeting shift behind the Apollo breach reprices operational risk for private equity — and hands the mandate to a short list of identity-security names.
On July 6, 2026, someone at Apollo Global Management answered a phone call. The number that flashed up looked like the company's own IT help desk. The voice on the other end was calm, professional, and in a hurry: a mandatory security migration, an urgent passkey enrollment, a link to a login page that looked exactly like the one the employee used every day. Over the next four days, the caller and his colleagues walked in through the front door of a $938 billion asset manager and walked out with names, birth dates, home addresses, and Social Security numbers.
No malware. No zero-day exploit. No breached firewall. Just a phone call and a fake login page — and one of the largest private equity firms on earth confirmed the breach this week in a filing with California's attorney general.
Apollo is not an outlier. It is a data point in the most deliberate targeting shift in cybercrime this year — and the market has not priced what it means.
The attackers stopped hacking computers and started hacking calendars
For most of the last decade, financially motivated hackers played a volume game. Spray phishing emails, buy stolen credentials in bulk, hit whoever fell for it — hospitals, manufacturers, school districts, the occasional retailer. The victim was whoever was careless. The payday was whatever you could get.
That is not what is happening now. According to a threat intelligence report published this month by Google's Threat Intelligence Group, the crew behind the Apollo-style attacks — tracked as UNC6671, and operating under a rotating set of extortion brands including Redact, Pink, Helix, and Falcon — has spent 2026 methodically narrowing its aim.
Google mapped the group's infrastructure registrations month by month, and the picture is striking:
- April–May: broad enterprise sweeps across manufacturing, real estate, healthcare, and insurance. High-volume credential harvesting.
- June: a pivot to technology, transportation, and hospitality — firms holding valuable intellectual property, source code, and VIP client data.
- July: the aim narrowed again, this time to private equity firms, law firms, and financial rating agencies.
Read that last line the way an investor should. The attackers didn't drift toward finance by accident. They walked up the value chain of secrets — from stolen identities, to corporate IP, to the single richest concentration of confidential information in the economy: the firms that sit inside every merger, every leveraged buyout, every capital deployment, every piece of high-stakes litigation. Google's analysts put it plainly: concentrating on organizations "involved in mergers, acquisitions, capital deployment, and litigation may reflect a strategy to target high-value corporate and confidential data to maximize leverage."
A private equity firm's entire competitive moat is its confidential data. That is exactly why it is now the target.
Briefings like this land in members' inboxes before the market prices them in. Join free →
The technique is embarrassingly simple — which is the whole point
There is no exotic tradecraft here, and that is what makes it dangerous. The playbook, per Google, is almost entirely human:
- Call the employee on their personal cell phone. This sidesteps every corporate security control the company paid for. In recent cases the attackers have even spoofed the real help desk phone number so the caller ID looks legitimate.
- Invent an urgent pretext — a mandatory passkey rollout, an MFA re-enrollment deadline — that pressures the target to act before thinking.
- Send them to a lookalike login page (companies get their own custom subdomains like
[company].addssopasskey.com) where adversary-in-the-middle infrastructure captures the password and the multi-factor code in real time. - Establish persistence, then quietly delete the evidence — the password-reset confirmations, the security alerts, the MFA-change notifications — so nobody notices until the extortion email arrives.
The economics are brutal for the defender. Google reviewed the group's Bitcoin wallets and found initial ransom demands of $1–3 million, typically negotiated down to an average final payment around $750,000. Between January and mid-May of this year, just 18 tracked wallets took in roughly $10.7 million. And critically: the payments kept flowing straight through the group's supposed "retirement" and rebrand in May — the shutdown was theater, the business never stopped.
Here is the uncomfortable part for anyone holding financial-sector equities. The industry spent fifteen years and hundreds of billions of dollars building walls — firewalls, endpoint detection, network segmentation. UNC6671 doesn't climb the walls. It phones the receptionist and asks her to open the gate. The entire defensive stack most firms are running was built for a war the attackers stopped fighting.
Which raises the question every investor in this space should be asking: if the target has shifted to the firms that manage your money, and the technique defeats the security most of them bought, who actually gets repriced — and who gets paid to fix it?