Fifteen Months, One Phone Call: How the Same Attack Went From Marks & Spencer to Apollo Global Management

In April 2025, someone called the Marks & Spencer IT help desk, impersonated an employee, and got a multi-factor authentication reset. In July 2026, someone called Apollo Global Management employees pretending to be internal IT and captured their credentials. Between those two events sit £1.9 billion in UK manufacturing losses, a 275-million-record education breach, and a Google threat advisory naming Blackstone, Bridgewater, and Bain Capital.
April 2025: the demonstration
On April 22, 2025, Marks & Spencer confirmed a cyber incident. Within days it had suspended all online and telephone orders and sent warehouse staff home. On April 30 the Co-operative Group detected suspicious activity and proactively shut down critical IT systems. On May 1 Harrods restricted internet access across its stores.
Three of Britain's most recognizable retailers, nine days.
The access method was the same at each. An attacker called an outsourced IT help desk, impersonated an employee, and convinced the agent to reset multi-factor authentication on a privileged account. At M&S that produced domain administrator access, the customer database, and the operational capability to deploy ransomware.
M&S was offline for 46 days. The Cyber Monitoring Centre assessed the combined M&S and Co-op impact at £270 to £440 million and classified it a Category 2 systemic event. In July, the National Crime Agency arrested four people aged 17 to 20.
Two things about that arrest record deserve attention. The first is that this tradecraft required no nation-state resources, no zero-day, and no exceptional technical skill. The second is that arresting four people did not stop the technique, because the technique is not a person.
The full account of the UK retail wave is in the Breach Library.
What the NCSC said in May 2025
On May 6, 2025, the UK National Cyber Security Centre issued updated guidance on defending against social engineering. It emphasized two things specifically: stronger verification protocols for help desks, and phishing-resistant multi-factor authentication.
That guidance was correct, published fifteen months before Apollo, and largely not acted on.
Nobody needed a zero-day. From Marks & Spencer to Apollo Global Management, the entry point was a phone call to someone whose job is to be helpful.
September 2025: the escalation
On September 1, 2025, Jaguar Land Rover detected an intrusion and shut its IT systems down. Production stopped across Solihull, Halewood, and Wolverhampton and did not restart for five weeks.
The Cyber Monitoring Centre assessed the total economic loss at £1.9 billion, the most damaging cyber event in UK history. JLR reported roughly $350 million in direct loss. Q3 wholesale volumes fell 43.3 percent year over year. Around 5,000 supply chain businesses were affected, some of them facing insolvency because their largest customer had stopped ordering.
A group calling itself Scattered Lapsus$ Hunters claimed it. Security researchers noted the plausibility that data from earlier CRM and database compromises had been used to make a vishing campaign against JLR more targeted — employee directories stolen in one attack becoming the raw material for the next.
JLR had an £800 million cybersecurity and IT contract with Tata Consultancy Services. Full account here.
March through July 2026: the industrialization
In March 2026, Aura — a company that sells identity theft protection — lost approximately 900,000 records when an attacker vished an employee. ShinyHunters claimed it.
In April and May, Canvas / Instructure was compromised twice, exposing 275 million student and staff records.
In June, DentaQuest declined to pay and 234 gigabytes covering 2.6 million people went public.
In July, RingCentral declined to pay and 1.6 million customer records went public.
Each of these was reported as a discrete event. They were not discrete. They were the same technique, refined against progressively higher-value targets, over sixteen months, in public.
July 2026: Wall Street
Between July 6 and July 10, 2026, attackers accessed Apollo Global Management's cloud platforms and exfiltrated names, dates of birth, home addresses, contact details, and Social Security numbers. Apollo's forensic team confirmed the exfiltration on August 12. The company disclosed publicly on August 21.
The method, per Apollo's own notice: advanced social engineering rather than software vulnerability exploits. Attackers called employees posing as internal IT help desk, walked them to lookalike sign-in portals, and captured credentials and MFA codes.
Google's Threat Intelligence Group had publicly warned weeks earlier that a coordinated vishing campaign was targeting private equity and financial firms. Reuters reported the target list includes Blackstone, Bridgewater Associates, and Bain Capital.
Apollo manages roughly $700 billion. Blackstone manages a trillion. Bridgewater manages around $150 billion. Bain manages roughly $185 billion.
All of them were reachable by the technique that took Marks & Spencer offline fifteen months earlier. Full account.
Why fifteen months of warning produced no defense
The technique was public. The NCSC published guidance in May 2025. Every incident was covered by the trade press and most by the mainstream press. The controls that stop it — phishing-resistant MFA and hardened help desk verification — are neither novel nor expensive.
Three reasons the warning did not convert.
Every organization read the wrong lesson. The coverage framed M&S as a retail story, JLR as a manufacturing story, Aura as an irony story, and Apollo as a Wall Street story. Sector framing let every reader outside that sector conclude the story was not about them. It was about the help desk, and everyone has one.
"We have MFA" felt like an answer. It is not, and the distinction is technical enough that it did not land. MFA verifies the login. The attack steals the session token the login produces, or has the help desk reset the factor entirely. Every victim organization in this sequence had MFA deployed.
The help desk is not where security attention goes. It is a cost center, frequently outsourced, measured on resolution speed. Nobody's security roadmap has help desk verification procedure on it. It is now the most consequential control most organizations have not examined.
The four people the National Crime Agency arrested in July 2025 were aged 17 to 20. Between the technique they used and Apollo Global Management sat fifteen months, a £1.9 billion manufacturing shutdown, an NCSC advisory nobody actioned, and roughly $2 trillion in assets under management at the firms that were targeted next. The exploit was a phone call. It is still a phone call. The only question a board should be asking this week is whether their own help desk would take it.
Cloudskope advises PE deal teams, portfolio company boards, and general counsel on identity exposure and cyber diligence. SARTUS is our fixed-fee six-day engagement: three days of assessment across identity, cloud posture, credential exposure, and active-compromise indicators, three days of done-for-you remediation.
.png)