Apollo Global Management disclosed in August that an unauthorised party had gained access to certain cloud platforms between 6 and 10 July following a social engineering incident. The information potentially affected included names, dates of birth, contact details, home addresses and Social Security numbers.
For an organisation of Apollo's scale and sophistication, that is clearly significant and implies that key controls may either not have been in place, or operating as intended. The full details have not been released (and might never be), but – even more worryingly – it appears that a number of other PE firms could also have been subject to attacks at the same time.
The chess pieces were already being positioned
On 6th August, Reuters reported that attackers had created tailored phishing infrastructure for more than 200 organisations over a period of roughly five weeks, including major private equity firms and asset managers. Apollo, Blackstone, Bain Capital, KKR, TPG, Clearlake Capital and Bridgewater were all among the organisations reportedly targeted. Google identified 72 malicious websites associated with the campaign, and Reuters found that many had been customised for individual companies. We should be clear about what this does and does not indicate: there is no evidence that these organisations were themselves breached, but the data suggests that the infrastructure to support an attack was being prepared.
Taken as a whole, the targeting indicates that threat actors are actively mapping the private capital ecosystem and are making deliberate choices based on research into how the industry operates. Google’s threat analyst put it clearly: “really, it’s a money thing” – the targets are firms holding data of sufficient sensitivity that they would pay to prevent its publication.
The campaign matters more than the individual breach
Apollo has not publicly attributed its breach to a specific threat actor. The incident took place against the backdrop of a wider campaign involving voice phishing, impersonation of IT support personnel, credential theft and compromise of cloud identity environments. Google Threat Intelligence Group has tracked activity from a financially motivated cluster it calls UNC6671.
The pattern is consistent. Attackers call employees, often on personal mobiles, pretending to be from IT:
- They create urgency around something plausible: an MFA reset, a passkey rollout, a security migration.
- They direct the victim to a convincing login page. Adversary-in-the-middle infrastructure sitting behind the page intercepts credentials, session information or authentication tokens, circumventing most forms of multi-factor authentication in the process.
- Once inside, they use legitimate access to move quickly through cloud services.
For this type of attack, identity has effectively become the perimeter, and identity is still, to a significant extent, human.
Despite the rise of AI, human weakness remains the target
A key takeaway from the Apollo incident is not simply that cloud systems can be compromised. It is that an attacker may not need a zero-day, a compromised software supplier or advanced malware. Techniques that have existed for decades still work: a plausible phone call, manufactured time pressure, and a login page that looks right.
The fund itself is a concentration point
Private equity cyber programmes tend to focus on portfolio companies, which is understandable. Portfolio businesses can vary enormously in maturity, and there is an imperative to generate value before exit. Some will have sophisticated security teams and mature controls, others will have outsourced IT, limited internal capability and several years of accumulated technological debt. The Apollo incident is a useful reminder that the management company itself can represent a significant concentration of risk.
The management company’s own environment – deal pipeline, LP information, board material, valuation models and employee records – is now accessed through a small number of identity platforms and SaaS services, creating efficiency, but also concentration risk which should be understood and managed appropriately. The scope of Apollo’s breach appears to be limited to personnel data; there is no suggestion that fund or deal data was compromised.
The network around the GP matters too
The cyber risk of a PE firm does not stop at the boundary of the management company. The GP, portfolio company management, lawyers, investment banks, lenders, consultants, fund administrators, placement agents and outsourced technology providers are all exchanging information. From an attacker's perspective, this is an extremely interesting environment. The recent campaign did not focus just on investment firms. Law firms – Paul Hastings and Greenberg Traurig were both named in the Reuters analysis – and other organisations surrounding financial transactions were also targeted.
That matters because an attacker does not need to compromise the most technically vulnerable organisation in a transaction. They need the organisation or person that gives them the best position.
Cyber risk is becoming an investment issue
We have written extensively about why private equity has historically underinvested in what we describe as asset safety. Cybersecurity is a good example. It has traditionally been treated as a technology or operational matter sitting within individual portfolio companies, or within the IT function of the fund: a cost and an unwanted overhead. That made some sense when a cyber incident was principally seen as an IT problem. A serious incident can interrupt revenue, create unexpected remediation costs, trigger regulatory scrutiny, affect customers, disrupt a transaction, change negotiation leverage and ultimately affect enterprise value. For the fund itself, it can do real reputational damage at precisely the wrong point in a fundraising cycle.
The Apollo incident will inevitably generate discussion around MFA, cloud security, social engineering and identity controls, but there is a bigger point. Attackers appear to be taking an increasingly systematic interest in private capital. They can identify firms, executives, advisers and portfolio companies. They can understand the relationships between them, and build attacks around the way transactions actually operate. And importantly, they do not necessarily need an especially sophisticated technical capability to succeed.
How you can use this to drive change
Four questions are worth putting to your own IT function (internal or external) this week, and to portfolio company management teams at their next board meetings.
- How does your service desk verify a caller before it resets credentials or enrols a new authentication device? If the answer relies on information an attacker could find on LinkedIn, it is not verification. Verification through a separate channel the caller does not control, or manager confirmation, should be mandatory for identity changes.
- Is your multi-factor authentication phishing-resistant? Push notifications and one-time codes can be intercepted by the adversary-in-the-middle technique described above. Hardware keys and passkeys bound to the device are not.
- How long do session tokens live, and would you notice if one were replayed from an unfamiliar location or device? Token theft leaves the password intact, so a password reset alone does not end the intrusion.
- Does anyone monitor for the deletion of security-alert and password-reset emails from executive mailboxes? It is a low-cost detection for a tactic this group is known to use.
None of this is expensive relative to the cost of a disclosure. It is, however, unglamorous, which is part of why it goes undone.
Sometimes the route around millions of pounds of cybersecurity investment is simply a convincing telephone call. Private equity firms should therefore assume that somebody, somewhere, is already looking at their organisation and asking a simple question:
Where is the easiest way in?
A useful exercise for any PE firm is to ask the same question before the attacker does.

Private Equity Cyber Risk Checklist
Our PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness. Work through it and know exactly where your gaps are.
- 10 steps across five phases - deal, first 100 days, portfolio ownership, ESG, and exit.
- Self-assessment at every step - rate your current position and walk away with a clear gap count.
- Written for fund leadership, No jargon. Financial language throughout.
Insights

Fool me once: What the Apollo breach tells private equity about the threats it now faces
Apollo’s August breach was one data point in a five-week campaign mapping 200+ private capital firms. What it means for fund-level cyber risk.

From Red Flag to Redline: How Cyber Findings Actually Change Deal Terms
A cyber finding rarely kills a deal, it can and does, however what it does far more often, is move it: from a line in a due diligence report to a redline in the SPA.

Why Summer is a Blind Spot in Private Equity Risk Oversight
Threat levels don't take annual leave. Why PE firms need continuous cyber oversight of portfolio companies, not seasonal assessment.

Private Equity Cyber Risk Checklist
The PE Cyber Risk Checklist is a ten-step diagnostic for PE fund leadership, covering every stage from pre-deal surveillance to exit readiness.

