decrypted · 25 august 2026 · ransomware and cybercrime · vulnerabilities and patching · supply chain

Apollo's breach shows a phone call still beats MFA

Apollo Global Management, the private equity firm that manages roughly a trillion dollars, disclosed on 21 August that attackers had reached into its cloud systems between 6 and 10 July. Nobody wrote an exploit. Someone rang Apollo staff, claimed to be internal IT support, and walked them through a fake login page that harvested passwords and multi-factor codes. Apollo did not spot the intrusion until 12 August. Names, dates of birth, home addresses and US Social Security numbers were among the data taken. It is a small, unglamorous story next to a critical-severity remote code execution flaw, and that is exactly why it belongs in this bulletin: it is also the far more common way organisations actually get breached.

A phone call, not a zero-day

The Register, citing security researchers, linked the intrusion to a group tracked as UNC6671, part of a wider wave of social-engineering attacks against financial firms this year. The technique needs no vulnerability at all: convince one employee, on their personal phone, that you are the help desk, and multi-factor authentication becomes a formality the attacker completes alongside them. Apollo says it has found no evidence the data has been posted or misused, and is offering those affected two years of credit monitoring. That is the right response after the fact. It does not change what let the attacker in.

The lesson UK retailers already paid for

This is the same playbook that hit Marks & Spencer, Co-op and Harrods in April 2025, when Scattered Spider persuaded an outsourced help desk to reset multi-factor authentication on a privileged account. The Cyber Monitoring Centre put the combined cost at between £270 million and £440 million. The NCSC's guidance afterwards was blunt: verify identity properly before any credential or MFA reset, and move privileged accounts to phishing-resistant MFA, such as hardware keys or passkeys, that cannot be read out over a phone or typed into a fake page. A one-time code defeats guessing and does little against a convincing human. The design choice that matters is not which MFA app you buy, it is whether your reset process can be talked around by anyone fluent in corporate jargon. Apollo is the latest reminder that fix has not travelled nearly as far as the incidents demanding it.

Also this week

Oracle WebLogic's maximum-severity flaw joins CISA's exploited list. CVE-2026-21962, a CVSS 10.0 flaw in the Oracle HTTP Server and WebLogic Server Proxy Plug-in, was added to CISA's Known Exploited Vulnerabilities catalogue on 24 August. It lets an unauthenticated attacker send a crafted request to the proxy servlet and execute code on the server behind it, and has been under attack since proof-of-concept code appeared in January, with one honeypot study logging over 140,000 attempts in under two weeks. The plug-in exists to enforce access control at the network edge; when that layer itself can be tricked, everything behind it is exposed. Patch now rather than wait for a deadline to force the issue.

An npm worm is still spreading through developer machines. ChainDrop, the latest wave of the Shai-Hulud campaign, compromised the maintainer of the widely used keyv package on 4 August and has since poisoned over 400 packages with a combined 1.3 billion downloads a month, according to Elastic Security Labs. It runs automatically via npm's preinstall scripts and hunts for cloud, GitHub and AI-tooling credentials. Disabling preinstall scripts by default and pinning versions remain the cheapest defences against an ecosystem that still trusts code to run itself on arrival.

Microsoft's Copilot told researchers how to break it. Varonis disclosed CoSnitch, three flaws in Copilot Personal that let a single crafted link silently pull email, calendar and Drive data through an undocumented autorun parameter, patched on 18 August after an eight-month wait. Researchers found the parameter by repeatedly asking Copilot why prompts couldn't run without confirmation, until it told them how they could. No exploitation was found in the wild, but a chatbot that reveals its own attack surface under polite questioning is a design lesson in itself.

Sources

If your incident response plan assumes MFA can't be talked around, get in touch and let's pressure-test it.

More like this

Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.

Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.