Cyber Threat Actor: Redact
| Actor Type | Location | Known Incidents |
Criminal
|
—
|
1 incident |
|---|
Characteristics
Profile
Redact is an alias used by a threat actor that has been observed in a campaign targeting financial and private equity firms. The actor is also associated with the aliases Falcon, Helix and Pink, which appear in the same publicly reported campaign. The alias Redact specifically appeared in connection with a breach disclosed by Apollo in July 2026. Apollo employs roughly five thousand staff and manages about nine hundred thirty‑eight billion dollars in assets. The breach notice filed with California’s attorney general described the intrusion as resulting from employees being tricked into revealing credentials through spoofed helpdesk calls. No other aliases or operational names for this actor are publicly confirmed beyond those mentioned in the campaign reporting.
The campaign’s focus is on the financial sector, particularly private equity firms, as demonstrated by the Apollo incident. The strategic objective appears to be financial gain through the theft of personal data that can be leveraged for ransom demands. Public reporting indicates that ransom demands in this campaign have reached as high as seven hundred fifty thousand dollars. The stolen data in the Apollo breach included names, birth dates, addresses and Social Security numbers of employees and possibly individuals associated with portfolio companies. No evidence links the actor to espionage, disruption or state sponsorship. The actor’s activity has not been attributed to any known criminal consortium or state entity in the available sources.
The actor’s tactics rely on social engineering, specifically spoofed helpdesk calls that trick employees into revealing credentials. Once credentials are obtained, the actor accesses cloud environments to exfiltrate personal data such as names, birth dates, addresses and Social Security numbers. No specific malware families, tooling or post‑exploitation frameworks are described in the available sources. The Apollo breach serves as a representative example of the actor’s operational pattern, illustrating the initial access method and data theft outcome. This example highlights the actor’s reliance on deception rather than technical exploits to achieve its objectives. The available information does not provide further details on additional tools, infrastructure or victimology beyond what has been reported.