23 August 2026
Executive Summary
Businesses are spending enormous amounts on increasingly sophisticated cybersecurity.
Attackers are still succeeding with something remarkably simple:
talking to an employee.
Apollo Global Management disclosed on Friday that attackers gained unauthorised access to certain cloud platforms between 6 and 10 July, exposing personal information including names, dates of birth, addresses, contact information and Social Security numbers. Apollo says its investigation remains ongoing and it has found no evidence so far that the stolen information has been publicly released or used for fraud or identity theft.
The Apollo incident comes amid a wider campaign against financial institutions, private-equity firms and other major companies. Reuters previously found that attackers had created fraudulent websites for more than 200 organisations and were using telephone impersonation, fake IT-support interactions and credential theft to target employees.
It is important not to overstate the connection: Apollo has confirmed unauthorised cloud access, but Reuters has not established publicly that a telephone call was the specific mechanism used in the successful Apollo breach.
The wider lesson nonetheless stands:
The strongest technical security control can fail if an attacker persuades an authorised human to open the door.
UK Impact
This is highly relevant to UK organisations because many modern cyber controls rely on employees recognising unusual requests.
Attackers may impersonate:
- IT support.
- Senior executives.
- Banks.
- Suppliers.
- Cloud providers.
- Password-reset teams.
- Security departments.
They may already know enough about the employee or organisation to sound convincing.
The risk is particularly significant when employees are asked to:
- Reset passwords.
- Reveal authentication codes.
- Approve MFA requests.
- Install software.
- Visit authentication websites.
- Change payment details.
- Grant remote access.
Cybersecurity therefore cannot rely entirely on an employee deciding whether the voice at the other end of the telephone sounds genuine.
Global Impact
Reuters’ investigation into the wider campaign found that major financial firms including private-equity groups, ratings organisations and market infrastructure providers had been targeted.
Attackers used spoofed telephone numbers and websites designed to mimic legitimate corporate login pages.
This produces an uncomfortable security reality.
Businesses can invest in:
- Firewalls.
- Endpoint detection.
- Artificial-intelligence monitoring.
- Encryption.
- Multifactor authentication.
and still remain vulnerable to somebody persuading an employee to authenticate the attacker.
That means the weakest point in the security architecture may not be software.
It may be a business process.
Our View
Businesses should redesign sensitive support processes so that security does not depend entirely upon employees recognising impersonation.
Companies should ask:
- Can IT support request passwords or MFA codes?
- How does an employee independently verify a help-desk caller?
- Can password resets be initiated by telephone?
- Are privileged-account resets subject to dual approval?
- Can MFA enrolment be changed without additional verification?
- Are senior executives subject to the same controls?
- Do staff know how to terminate a suspicious call and reconnect independently?
- Are suppliers allowed remote access?
- Can identity verification rely on information attackers could obtain from LinkedIn or social media?
- Are unusual cloud logins automatically escalated?
- Can a compromised account access large quantities of personal data?
The best instruction may be extremely simple:
Never authenticate the person who contacted you using the communication channel they chose.
Hang up.
Use a known internal number or system.
Verify independently.
In sophisticated cyber environments, one of the most valuable security controls may still be a second telephone call.
Risk Indicator: HIGH
Does This Risk Affect Your Business?
Invictus Risk Solutions helps businesses find practical solutions to insurance, risk and commercial challenges.
From individual businesses to major international organisations, risk is our business.
TALK TO INVICTUS →Disclaimer
The information contained within these Market Alerts is provided for general market awareness and informational purposes only. It does not constitute financial, legal, investment, regulatory or insurance advice. Whilst every effort has been made to ensure accuracy at the time of publication using multiple reputable and independently verified sources, geopolitical events, legislation, regulation and market conditions may change rapidly. Readers should obtain appropriate professional advice before acting upon any information contained herein.
Invictus Risk Solutions LLP – Helping organisations stay ahead of emerging risks through informed insight and independent analysis.
