
Blackstone Inc., an alternative investment management company headquartered in New York City, disclosed a cybersecurity incident that exposed the personal information of consumers.
Founded in 1985, Blackstone operates across private equity, real estate, hedge funds and credit, serving both institutional and individual investors.
On July 23, 2026, an unauthorized party briefly gained access to a number of Blackstone employee user accounts. The attacker used that access to obtain copies of files stored in certain cloud-based file repositories.
The investigation into the incident found that some personal information held in the compromised files was affected. The types of information exposed included Social Security numbers and financial account information.
Separately, a threat actor known as BreachLaboratory posted a listing on the open web on Nov. 28, 2025, claiming to be selling 3,300,000 records from Blackstone Inc. The listing described the alleged data as containing phone numbers, genders, birth dates, credit ratings, IP addresses, email addresses and operational experience.
The breach was disclosed to the Massachusetts Office of Consumer Affairs and Business Regulation on Sept. 30, 2026.
Blackstone is offering two years of identity monitoring services at no cost to affected individuals through Kroll. Affected individuals can activate their monitoring by visiting Kroll's enrollment page. Affected individuals received a unique membership number in their notification letter, which is needed to complete enrollment.
Blackstone set up a dedicated call center to answer questions about the incident. Affected individuals can call 844-301-0220 between 8 a.m. and 5:30 p.m. Central Time, Monday through Friday, excluding major U.S. holidays.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)