Apollo Global Management Confirms Personal Data Breach Following Cloud Cyberattack
A routine-looking support interaction opened the door to a far more serious incident, leaving sensitive records exposed. The full scope remains unclear.
Apollo Global Management has confirmed a personal data breach following a cyberattack on the company’s cloud infrastructure. As a result of the incident, attackers obtained a substantial amount of sensitive information, including names, dates of birth, contact details, home addresses, and U.S. Social Security numbers.
The unauthorized access lasted from July 6 to July 10. In a notice filed with the California Attorney General, Apollo’s head of human resources, Matthew Breitfelder, stated that the attackers used social engineering techniques to gain access to the company’s systems.
What data may have fallen into hackers’ hands
In its filings, Apollo did not specify who the stolen information belonged to. It may involve both the company’s own employees and individuals associated with businesses in its investment portfolio.
Apollo Global Management manages $938 billion in assets and is among the largest players in the private equity market. According to public regulatory filings, the company employed around 5,000 people as of February 2026.
Hacker attacks on private equity and <a href="https://bitcomme.com/financial-reporting-developments-ebp-fasb-sec-updates/” title=”Financial Reporting Developments: EBP, FASB, & SEC Updates”>financial firms
The data breach at Apollo occurred amid a broader wave of attacks targeting the financial sector. Several weeks before the incident was confirmed, Google researchers warned of an extortion campaign aimed at financial institutions and private equity funds.
Blackstone, Bridgewater, and Bain Capital were also named as potential hacker targets. However, there was no information at the time indicating that the attackers had successfully infiltrated those companies’ systems.
According to Google, groups tracked under the names Falcon, Helix, Pink, and Redact frequently use phone calls to target employees. The attackers pose as IT support specialists and try to convince victims to enter their password and multi-factor authentication code on a fake login page.
After gaining access to a corporate network, cybercriminals steal data and demand money, threatening to publish the information on leak sites. In some cases, the ransom demands reached $750,000.
Apollo spokesperson Giovanna Falbo did not respond to a request for further details about the cyberattack, including whether the attackers demanded a ransom and whether the company made any payments.
- Apollo Global Management has agreed to acquire easyJet after Castlelake exited the takeover race, with backing from founder Stelios Haji-Ioannou and his family.
- The Ombudsman says Monobank likely breached banking secrecy by publishing a client’s photo and account block details, prompting NBU and ombudsman probes and legal threats.
- Levi Strauss reported a cybersecurity incident in which social engineering targeting three employees enabled unauthorized access to company systems and the extraction of some corporate information.
