Full-Time
Manages private equity, venture, credit globally
$130k - $155k/yr
Boston, MA, USA
In Person
See people who can refer or advise you
Bain Capital is a private investment firm that manages multiple asset classes including private equity, venture capital, public equity, credit, and real estate. It works by making long-term investments in companies across a wide range of industries and geographies, and then actively partnering with the management teams of portfolio companies to drive growth and improve operations over time. The firm uses a long-term investment horizon and an active-ownership approach to build value for its investors. What sets Bain Capital apart is its multi-asset scale and global presence, combined with hands-on collaboration with portfolio companies and a strong emphasis on social responsibility through charitable initiatives. The goal is to deliver sustained, long-term value for investors and partners while contributing to communities through its charitable programs.
Company Size
1,001-5,000
Company Stage
N/A
Total Funding
$17.6B
Headquarters
Boston, Massachusetts
Founded
1984
See people who can refer or advise you
Help us improve and share your feedback! Did you find this helpful?
Professional Development Budget
Conference Attendance Budget
Apollo discloses data breach from ongoing wave of attacks hitting financial sector. The private equity firm said attackers broke into some of its cloud platforms during a five-day period in early July, compromising sensitive personal data. August 21, 2026 Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. Attackers gained unauthorized access to some of the private equity firm's cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment. Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon. "Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation," Matthew Breitfelder, global head of human capital at Apollo, wrote in the disclosure notice. As part of its ongoing investigation, Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised. The company did not say how many people were impacted, but noted it's thus far found no evidence any data was posted online or used for identity theft or fraud. Apollo is one of the world's largest private equity firms, with $1.05 trillion in assets under its management at the end of June, according to a regulatory filing. Researchers previously told CyberScoop some of Apollo's largest competitors, including Blackstone and Bain Capital, were also targeted with malicious infrastructure, but it's unclear if those firms were compromised. BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the beginning of this year. The extortion group shifts from one sector to the next, impersonating IT support in voice-phishing and social-engineering attacks before threatening its alleged victims with extortion demands, which often start around $3 million and are typically negotiated down to less than $1 million. Google researchers also previously said some of the group's recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com.
Details emerge on BlackFile's recent attacks on financial companies. BlackFile's four affiliate groups are still targeting victims, including medical technology organizations. Several potential victims received new extortion demands last week, according to Google. August 17, 2026 A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers. BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com, has been active since the start of the year, shifting its focus from one sector to the next. "We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space," Austin Larsen, principal threat analyst at GTIG, told CyberScoop. The extortion group impersonates IT support in voice-phishing and social engineering attacks, and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon. Several organizations received new extortion demands from Redact in the last week, according to Google. BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, retail and hospitality. "BlackFile does go after some of the largest organizations in the sectors that they go for. They're not going after small companies," Larsen said. "This is big-game hunting." The group's extortion demands often start around $3 million and payments, including several in the past few weeks, have typically been negotiated down to less than $1 million, according to Google. Flashpoint researchers told CyberScoop they have observed malicious infrastructure targeting Blackstone, Bain Capital, Moody's, CME and Apollo, but it's unclear if any of those firms were compromised. BlackFile's steady pace of activity underscores the persistent threat it poses, as it targets an average of 1.5 new victims daily, researchers said. Some of the group's recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com, according to Google. The attackers use hundreds of callers, often lower-level people that are recruited for a small fee or an opportunity to earn goodwill with the group, who make the voice phishing calls to obtain initial access. Larsen estimates less than a dozen core operators run the different brands under the BlackFile umbrella. "From the intrusion data that we're seeing, this does appear to be essentially the same group," he said, adding that different people may be operating the various brands, but they're all linked back to the same threat cluster using shared infrastructure. Mandiant incident responders encounter BlackFile often, having been engaged by more than two dozen organizations successfully compromised by the threat group since January. New victims in the financial sector were calling Mandiant in for help earlier this month. Voice-based phishing attacks for data theft extortion aren't sophisticated or novel, but BlackFile and other cybercrime groups consistently prove their continued effectiveness across virtually any sector or organization. "They're really hitting on the human weakness element here," Larsen said.
Manappuram Finance has appointed Ashish Singh as managing director and chief executive officer, effective 1 January 2027. Singh, who has over 25 years of experience in retail banking, will serve a five-year term. He is currently head of retail liabilities at IDFC FIRST Bank. V P Nandakumar, the current managing director and chairperson, will continue in both roles until 31 December 2026, after which he will become non-executive chairperson. The leadership change follows Bain Capital's March 2025 agreement to acquire joint control of the Kerala-based gold loan lender. Bain committed to invest around ₹4,385 crore to acquire an 18 per cent stake through preferential allotment at ₹236 per share. The transaction triggered a mandatory open offer for an additional 26 per cent stake.
Two decades, four owners: Gong Cha and the limits of the licensing model. By Tong Van August 11, 2026 Bain Capital has agreed to acquire Gong Cha from private equity firm TA Associates for an undisclosed sum. The deal is expected to close in the fourth quarter of this year. The bubble tea chain has been sold four times in 12 years. The franchisee that bought the franchisor Gong Cha opened in Kaohsiung in 2006. The turn came in 2012, when Australian former banker Martin Berry and his wife, Kim Yeo-jin, took the master franchise into South Korea. Unison Capital's Korean arm, later UCK Partners, This content is for IR Pro subscribers only. IR Pro - monthly. $5 [+GST] for the first 30 days. (Auto renews at $28+GST per month.) * Unlimited news access * Daily IR Pro content straight to your inbox * Exclusive members only masterclasses (live and on-demand) * Weekly careers advice * Independent research reports and forecasts * Indepth interviews with industry leaders and experts * Weekly and quarterly digital magazines delivered to your inbox Retailer's choice IR Pro - annual. $312 [+GST] per year. (Auto renews annually.) * Unlimited news access * Daily IR Pro content straight to your inbox * Exclusive members only masterclasses (live and on-demand) * Weekly careers advice * Independent research reports and forecasts * Indepth interviews with industry leaders and experts * Weekly and quarterly digital magazines delivered to your inbox
PE firms targeted in wave of social-engineering cyberattacks. * August 7, 2026 * - 9:08 am US private equity firms including Blackstone, Apollo Global Management, KKR, Bain Capital, TPG and Clearlake Capital have been among more than 200 companies targeted in a recent cyberattack campaign, according to a report by Reuters. The report cites data from Google and internet intelligence researchers as revealing that the campaign has focused on stealing employee credentials through highly targeted social-engineering attacks, highlighting the vulnerability of financial firms even as they invest heavily in more sophisticated cybersecurity systems. Other financial institutions identified among the targets include Bridgewater Associates, CME Group and Moody's, while hedge funds including Point72 Asset Management, Two Sigma Investments and Citadel were also reportedly targeted. Google's Threat Intelligence Group said the hackers have recently shifted their attention towards private equity firms, law firms and financial ratings agencies, with the attackers apparently selecting targets based on their ability and willingness to pay a ransom. The campaign has operated under several aliases, including Redact, Pink, Falcon and Helix. Google said the groups appear to share infrastructure, although their exact relationships and identities remain unclear. Rather than relying on highly sophisticated technical exploits, the attackers have used phone calls and impersonated corporate IT help desks to persuade employees to surrender credentials. Targets were contacted on personal mobile phones and told that they needed to urgently update passkeys or multi-factor authentication credentials. In some instances, the attackers were able to make the incoming call appear to originate from the company's genuine help desk number. Employees were then directed to fraudulent websites designed to resemble corporate authentication or support pages. If a target entered their password, the hackers could capture the one-time authentication code generated by an app or sent via text message while remaining on the phone with the victim. This allowed them to take control of the account before ending the call. Austin Larsen, a principal threat analyst at Google's Threat Intelligence Group, said the approach was less technically sophisticated than it was effective. The campaign demonstrates how the human element can remain a significant vulnerability for private equity firms, which hold sensitive information on portfolio companies, investment strategies, transactions and financial data. Google identified 72 malicious websites associated with the campaign, while analysis by Reuters found that many were customised for individual companies. The attackers are understood to have created digital traps targeting more than 200 businesses over a five-week period. Targets extended beyond financial services to include Uber, Zillow, Levi Strauss and law firms such as Paul Hastings and Greenberg Traurig. The campaign appears to have evolved over time, with the attackers initially targeting a broad range of businesses before increasing their focus on financial institutions. Google said some companies had paid ransoms following successful attacks, although it was not possible to establish which organisations had been compromised or paid. Several of the private equity firms named in the data reportedly declined to comment, while others did not immediately respond to requests for information.