On 21 August 2026, Apollo Global Management disclosed a data breach: between 6 and 10 July, attackers had gained unauthorised access to several of the firm’s cloud platforms and exposed names, dates of birth, home addresses, and Social Security numbers belonging to an unknown number of people. Apollo manages more than one trillion dollars in assets. The access was not achieved through a software vulnerability or unpatched system; it was achieved through a phone call.
What Apollo experienced is precisely the scenario that vishing awareness training exists to prevent. The attackers, tracked by researchers as UNC6671 and BlackFile, called Apollo employees on their personal phones, posed as colleagues or IT support, and directed them to spoofed login pages that captured credentials and MFA codes. Managing human cyber risk as an operational discipline means building verification systems that hold even when the caller sounds legitimate and the urgency feels real.
The Attack Required No Technical Sophistication
According to The Register, UNC6671 and BlackFile have been running IT helpdesk-themed vishing campaigns against organisations across North America, Australia, and the United Kingdom since early 2026, making Apollo one of multiple large targets caught in the same campaign. The attack pattern is consistent: a caller impersonates IT support or a known colleague, creates urgency around an account or access issue, and persuades the target to authenticate through a convincing replica of the organisation’s portal. The credential and MFA code entered go directly to the attacker.
Apollo disclosed the breach on 21 August 2026 after an investigation determined on 12 August that personal data had been exposed. The company has not disclosed the number of people affected or which platforms were compromised. It stated no evidence has been found that the exposed information was publicly posted or misused for identity theft or fraud.
Canadian Financial Organisations Face the Same Exposure
This campaign is not limited to the United States. UNC6671 and BlackFile have explicitly targeted North American organisations, and the attack playbook requires no modifications to work against a Canadian finance team, a credit union, or an insurance company. The Cybersecurity Canada Report 2026 puts the average cost of a domestic data breach at CA$6.98 million, a 10.4 percent increase year over year. A single successful vishing call that yields valid credentials and authenticated session access can begin a breach of that scale.
Why Finance and Executive Teams Are the Most Exposed
IT helpdesk vishing targets employees who have system access, authority to act, and a professional obligation to respond to urgent requests quickly. Finance teams, treasury operations, executive assistants, and C-suite staff sit squarely in that profile, and they process high-stakes requests under time pressure all day. Yet these roles typically receive the least tailored security training, because generic annual modules do not address the specific social mechanics that make a pressured phone call from apparent IT support difficult to question in the moment.
In our work with Canadian finance and executive teams, we consistently see that the highest-value targets receive the least training, because nobody wants to make the CEO sit through a 20-minute module. This is exactly the gap that incidents like the one above exploit.
One Practical Step for This Week
Establish and practise a verification protocol specifically for finance and executive staff: any request arriving by phone that asks an employee to log in through a link, approve an MFA notification, or authorise a transfer should trigger a hang-up and a callback through the official company directory. This behaviour can be installed quickly, but only through realistic practice. Organisations that run vishing simulations as part of their security awareness program build this reflex systematically, before an attacker tests it live.
Sources
- The Register: $1T investment giant Apollo breached after social engineering attack (24 August 2026)
- Bloomberg: Apollo Reports Data Breach From Social Engineering Incident (21 August 2026)
- SecurityWeek: Personal Information Exposed in Apollo Global Data Breach
- Cybersecurity Canada Report 2026: The State of Canadian SMB Cyber Risk