Apollo. Blackstone. Bridgewater. Bain. The Same Crew Is Vishing Them All — And Bain Is Already a Defendant.
Apollo Global Management confirmed a data breach on August 21. Google Threat Intelligence Group has publicly named Blackstone, Bridgewater, and Bain Capital as targets of the same campaign. Bain Capital is also a named defendant in the first federal ruling to hold a private equity firm directly liable for a portfolio company's data breach. Same firm, two-front war.
The wave
On August 21, Apollo Global Management confirmed that unauthorized actors accessed its cloud platforms between July 6 and July 10, 2026, and exfiltrated names, dates of birth, home addresses, contact information, and Social Security numbers. Apollo has not disclosed how many individuals are affected. The firm's public notice, signed by Global Head of Human Capital Matthew Breitfelder, describes the intrusion as "advanced social engineering rather than software vulnerability exploits."
Weeks before Apollo's disclosure, Google Threat Intelligence Group publicly warned that a coordinated vishing campaign was targeting private equity and financial firms. Reuters reported the target list includes Blackstone, Bridgewater Associates, Bain Capital, and other Wall Street institutions. GTIG and its research partners have tracked the actors under names including Falcon, Helix, Pink, Redact, and Silent Ransom — subgroups adjacent to or overlapping with the ShinyHunters extortion ecosystem responsible for the 2026 Canvas / Instructure breach, the RingCentral incident, and the Aura consumer identity-protection breach.
The attack pattern is consistent across the wave. Employees receive phone calls from someone claiming to be internal IT help desk. The caller is friendly, competent, and mid-conversation about a routine sign-in issue before the target realizes what is happening. The employee is walked to a lookalike Microsoft or Okta portal, types credentials, completes the MFA challenge, and hands the attacker's proxy an authenticated session token that no dashboard flags because the MFA challenge was successfully completed. The attacker walks into the cloud platform from a browser somewhere else in the world, wearing the employee's identity. The identity provider sees a successful login.
Apollo's took five days. Then five weeks before anyone realized what had happened.
The mechanism, plainly
Multi-factor authentication is not designed to defeat authenticated sessions. It is designed to prevent an attacker who has stolen a password from completing a login. Once an MFA challenge has been completed by a human at a keyboard, the resulting session token is trusted by the identity provider until it expires. If that session token is captured in transit by a lookalike portal, the attacker has the same access as the employee, without needing to defeat MFA again. The attacker never has to compromise the identity provider. The identity provider was working exactly as designed. It just was not the layer the attacker chose to attack.
The layer the attacker chose was the helpdesk. Every large PE firm has a helpdesk. The helpdesk has extraordinary access — the ability to reset accounts, verify identities, walk employees through login problems, and issue credentials. The helpdesk's authority is what the vishing call exploits. Not by breaking it. By using it. From the outside.
Private equity is now being attacked from two directions at once. Extortion crews are compromising the firms directly through their own helpdesks. Federal courts are holding them liable for what happens at their portfolio companies.
The attestation gap
Every major PE firm publishes something to its limited partners about cybersecurity. Every major PE firm's insurance renewal now includes a controls attestation. Every major PE firm's due diligence questionnaire, sent to portfolio companies, asks about identity controls, phishing defenses, and helpdesk procedures.
The Apollo breach is a demonstration that the answers being given in those attestations, questionnaires, and LP letters may not survive contact with a competent phone call. It is a demonstration that the industry has been telling itself and its LPs that MFA solves the identity problem. MFA solves one part of the identity problem. The part it does not solve — session token theft via social engineering — is the part that just took down Apollo.
The Bain double-hit
Bain Capital is one of the firms Google identified as targeted in the vishing campaign. Bain Capital is also, as of March 18, 2026, a named defendant in a federal ruling that allowed data breach claims against a private equity firm to proceed based on operational control of a portfolio company. The portfolio company was PowerSchool, acquired by Bain in October 2024 for $5.6 billion. The breach at PowerSchool was disclosed in early 2025, exposed roughly 60 million students, teachers, and parents, and was ultimately attributed to a 19-year-old Massachusetts college student named Matthew Lane who used stolen vendor credentials to exfiltrate data over several months.
The court's reasoning is worth reading carefully. Judge Rita F. Lin in the Southern District of California allowed claims to proceed against Bain based on allegations that Bain "ratified and conditioned its offer on cost reduction measures," which included laying off domestic cybersecurity staff. Pre-closing, Bain held contractual veto rights over vendor contracts and capital expenditures over $5 million. Post-closing, Bain directed PowerSchool to offshore cybersecurity, engineering, and IT functions to Movate — the very vendor whose compromised credentials the attacker used. The court explicitly rejected the argument that contractual disclaimers of control were dispositive. The court's precedent: actual operational control is what matters, and PE firms may face direct liability regardless of what their acquisition agreements say.
That is a two-front war. The extortion crew is at Bain's front door with a phone. The plaintiff's bar is at Bain's back door with a class action complaint. The same firm is answering both.
The Insight Partners precedent, which nobody covered as a PE story
Insight Partners disclosed in September 2025 that ransomware actors compromised its HR and finance systems, exfiltrated data starting on or around October 25, 2024, and began encryption on January 16, 2025. Public filings confirmed more than 12,600 people were affected. The stolen data included information about Insight's funds, management companies, and portfolio companies, along with banking and tax records for current and former employees and — the number that should focus attention — Insight's limited partners.
Limited partners of Insight Partners include some of the largest endowments, sovereign wealth funds, and pension systems in the world. Their identities are, by policy and by contract, private. That privacy just got contingent on a VC firm's HR system.
Insight described the initial vector as a "social engineering attack" without further detail. The attackers had access for roughly 12 weeks before pulling the encryption trigger. Insight had no public detection during those 12 weeks.
The Apollo breach is not an isolated event. The Insight breach was not an isolated event. Neither is the campaign Google GTIG documented. What these events collectively demonstrate is that the wealth layer of the American economy — the sponsors, the general partners, the trillion-dollar allocation machinery — is being systematically targeted by extortion crews who have concluded that this is where the money is.
What this means for deal teams, right now
The private equity industry has an operating theory about cyber risk: portfolio companies are the exposed surface, the sponsor is the insulated backstop, and the corporate form provides adequate protection between the two. The Bain/PowerSchool ruling directly contradicts the second half of that theory. The Apollo, Blackstone, Bridgewater targeting directly contradicts the first half. The theory needs to be rebuilt.
Six questions every PE deal team and operating partner should be answering by end of month:
- Are we already compromised? Not "do we think we are" — do we have evidence. When was the last time a compromise assessment reviewed sign-in telemetry, mailbox rules, OAuth grants, device registrations, and administrative activity across every executive and finance identity in the firm? Not the portfolio. The firm itself.
- What is our helpdesk actually verifying? If an attacker knows an employee's name, start date, department, and reporting chain — information that is on LinkedIn — is there any procedure that stops a credential reset? Have we tested the procedure by having someone try it?
- What is the reset radius when one session token is stolen? If an executive session is compromised for four hours, what did they touch? What have we forced-logged-out of? What cloud platforms retain long-lived tokens?
- What does our LP disclosure actually say about identity controls? Have we read it against the Apollo timeline? Have we read it against the Bain/PowerSchool ruling? Would we be comfortable defending our language in a deposition six months from now?
- What is our sponsor-liability posture across the portfolio? How much operational control do we exercise over portfolio company cybersecurity? Do we direct workforce decisions, capex approvals, vendor selection, offshoring decisions in ways that could be characterized as agency? If yes, are those decisions defensible against a Bain-style theory of liability?
- Where would we accept a bounded, fixed-fee engagement to find and remediate what we don't want to hear about, before someone else finds it and publishes it?
That last question is the one Cloudskope advises boards on directly. SARTUS™ is a six-day engagement — three days of assessment across identity, cloud posture, credential exposure, and active-compromise indicators; three days of done-for-you remediation; a consolidated risk register mapped to NIST 800-53 and the CIS Benchmarks; and a fixed fee that does not move. It is the tool for answering questions one through five in a defined window, in a defined budget, before the campaign that hit Apollo hits the next firm on the list.
Related reading:
- How a Phone Call Beats MFA: Anatomy of the Wall Street Vishing Wave — the technical anatomy and hardening playbook
- Apollo Global Management: Breach Library entry — the factual record and disclosure timeline
Apollo Global Management manages roughly $700 billion. It was compromised in five days, via a phone call, through its own helpdesk. Bain Capital manages roughly $185 billion. It is being sued in federal court for cybersecurity failures at a portfolio company, and it was targeted by the same crew that took Apollo.
Cloudskope advises PE deal teams, portfolio company boards, and general counsel on cyber diligence and executive risk. SARTUS is our fixed-fee six-day engagement designed to answer are-we-compromised and close what can be closed inside the deployment window.
.png)
.png)