Apollo Global Management confirmed Friday it was among several financial institutions hit by a wave of social engineering attacks that compromised sensitive personal data. Attackers gained unauthorized access to some of the private equity firm's cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California.

On August 12, Apollo determined that personal data — including names, dates of birth, contact information, home addresses, and Social Security numbers — had been compromised. The company did not disclose how many people were affected but said it had found no evidence the data had been posted online or used for identity theft.

Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com that recently split its extortion operations across four brands: Redact, Pink, Helix, and Falcon. The group impersonates IT support staff in voice-phishing and social engineering attacks before making extortion demands, typically starting around $3 million and often negotiated down to less than $1 million.

Blackstone and Bain Capital were also reportedly targeted, though it remains unclear whether those firms were compromised. Apollo, which manages $1.05 trillion in assets, said it notified law enforcement, engaged cybersecurity experts, and enhanced its security protocols upon detecting the incident.