Skip to content
Rush Commerce
Field Notes3 min read

Apollo's breach: your MFA codes are phishable

Apollo Global lost SSNs to a phone call and a fake login page. One-time codes stopped nothing. Phishing-resistant auth is the fix, and it is cheap.

A firm with $938 billion under management lost names, birth dates, home addresses, and Social Security numbers because employees typed their passwords and one-time codes into a page that looked right. Apollo Global Management confirmed the breach on August 21. There was no exploit in the chain. The lesson is that MFA codes are phishable, and most small businesses are running the exact same setup.

What actually happened

In a filing with California's attorney general reported by TechCrunch, Apollo said attackers reached its cloud environment through a social engineering attack between July 6 and July 10. Bloomberg reported the same disclosure. Apollo said it did not finish determining which categories of data were taken until August 12 — over a month after the intrusion window closed — and disclosed on August 21.

The method, per Google researchers describing the broader campaign, is a phone call. Someone claiming to be the internal IT help desk walks an employee to a convincing fake sign-in page and collects the password and the one-time code in real time. The code is valid for thirty seconds; the attacker only needs five. TechCrunch reports the same campaign has targeted Blackstone, Bridgewater, and Bain Capital, with the crews operating under names including Falcon, Helix, Pink, and Redact.

Apollo says it notified law enforcement, brought in outside forensics, and has no evidence the data has been posted or used for fraud. It declined to say whether a ransom was paid.

Why phishing-resistant MFA matters for your business

SMS codes and authenticator apps are shared secrets. Anything a person can read off a screen and type somewhere else can be typed into the attacker's screen instead. That is the whole attack. Adding MFA moved you from one phishable factor to two.

Passkeys and hardware keys are not phishable. FIDO2 and WebAuthn bind the credential to the domain. On a fake login page the browser has nothing to offer, and the employee cannot manually override it. Microsoft Entra, Google Workspace, Okta, and Shopify all support this today, and for a ten-person team the hardware keys cost less than one month of a mid-tier SaaS bill.

Write the help desk rule down and tell everyone. Ours: IT never asks for a code, ever, on any channel. If someone does, hang up and call back on a number from your own directory. That single sentence, said out loud in a team meeting, is a free control.

Watch the disclosure clock, not just the breach. Intrusion July 10, data categories confirmed August 12, notice August 21. If your vendor is breached, assume you will hear about it weeks later. That is an argument for knowing which vendors hold your customer PII before you need the list, not after.

Key takeaways

  • Apollo Global confirmed attackers reached its cloud environment July 6-10 via social engineering
  • Stolen: names, dates of birth, contact details, home addresses, and Social Security numbers
  • The method is help-desk impersonation plus a spoofed login page that harvests passwords and one-time codes live
  • The same campaign has targeted Blackstone, Bridgewater, and Bain Capital
  • Passkeys and FIDO2 hardware keys are domain-bound and cannot be relayed to a fake page
  • Disclosure lagged the intrusion by six weeks — assume the same delay from your own vendors

If a phone call can get into your systems, your login page is not the control you think it is. We move small teams onto phishing-resistant auth and map which vendors actually hold your customer data — usually in under a week. Ask us to review your login and vendor exposure, or see how we build systems you own.

Sources: TechCrunch, Bloomberg.

  • #mfa
  • #phishing
  • #identity
  • #data-breach
  • #passkeys
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.