Apollo Global Management has told people that hackers reached their names, dates of birth, contact details, home addresses and Social Security numbers. The private equity firm set out the incident in a notification letter dated 21 August and posted on the California attorney general’s website.
The letter opens the account of what happened with a comparison. “Similar to other financial services firms, Apollo recently experienced a social engineering incident.”
The dates in the letter
Apollo says there was unauthorised access to certain cloud platforms between 6 and 10 July. That is four days.
The firm then gives a second date. “During our investigation, we learned on August 12, 2026 that the information potentially impacted by this incident included your name, date of birth, contact information, home address, and your Social Security Number.”
The letter went out on 21 August. Six weeks separate the start of the access from the notice.
What Apollo says it did
“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” wrote Matthew Breitfelder, Apollo’s global head of human capital.
A line further down the letter addresses California and Wyoming residents. It reads: “This notification was not delayed by law enforcement.”
What the letter does not say
It does not name the attacker. It does not say how many people received it. It does not say who they are, whether staff at Apollo, staff at companies Apollo owns, or investors.
It names no cloud platform, and it does not describe how the attackers got in beyond the phrase “social engineering incident”. Apollo declined to comment to <a href="https://www.bloomberg.com/news/articles/2026-08-21/apollo-reports-data-breach-from-social-engineering-incident” rel=”nofollow noopener” target=”_blank”>Bloomberg. A spokesperson did not answer TechCrunch’s questions, including whether the firm paid a ransom.
Nor does the list of stolen data include payment details. The categories Apollo names stop at identity information, and no bank or card data appears among them.
The document on the file
What Apollo filed in California is the blank version of the letter. The name field reads “Dear :” and the enrolment code is missing. A print marker sits above the address block.
The file is called L01 Template_CA.pdf. It is the mail-merge master rather than any individual’s copy, which is standard practice for these filings.
Who is sending the letter
The return address is not Apollo’s. Letters go out from “Apollo c/o Cyberscout, P.O. Box 3826, Suwanee, GA 30024”, while the letterhead carries Apollo’s address at 9 West 57th Street in New York.
Cyberscout is providing the credit monitoring. The letter describes it as “a TransUnion company specializing in fraud assistance and remediation services”. TransUnion is one of the three credit bureaus the same letter tells recipients to contact.
The terms of the monitoring offer
The services run for twenty-four months from the date of enrolment, not from the date of the breach. Recipients have 90 days from the letter to enrol.
Enrolment needs an internet connection and an email account. The letter notes it “may not be available to minors under the age of 18 years of age”. A help line runs for 90 days, 8am to 8pm Eastern, weekdays only.
Which states got the letter
The version filed in California carries notices for residents of seven jurisdictions. They are California, the District of Columbia, Maryland, New York, North Carolina, Rhode Island and Wyoming.
Rhode Island residents are told they have the right to obtain any police report filed about the incident.
The campaign around it
Google warned in July that a group it tracks as UNC6671, also called BlackFile, was targeting private equity and financial firms. Reuters reported that Apollo was among the companies targeted, alongside Blackstone, Bridgewater and Bain Capital, without establishing whether any attack had succeeded.
Apollo has not attributed its breach to that group. The Register notes that the notification links the incident to attacks elsewhere without naming anyone.
Google says the group calls employees while posing as colleagues or IT support, then steers them to spoofed login pages that harvest passwords and multi-factor codes. It puts some ransom payments at $750,000. The desk covered the phone-call campaign on 7 August.
The same method elsewhere this month
Levi Strauss said social engineers compromised three employees’ company-issued computers and took corporate data. The desk covered the Levi’s breach on 10 August.
RingCentral lost 1.6 million records after a phone call. The desk covered that leak on 15 August. Point72 told investors it had been attacked. Hackers also tried Millennium Management, Two Sigma and Citadel
How big Apollo is
TechCrunch puts Apollo’s assets under management at $938bn. The Register describes the firm as a $1tn investment giant. Apollo’s regulatory filings put its headcount at around 5,000 as of February 2026.
TechCrunch disclosed its own connection in its report. Until 2025 it was a subsidiary of Yahoo, an advertising technology company owned by Apollo.
The firm has appeared on this desk twice in three months for reasons unrelated to security. Its economists published research on AI and wages two days ago, which the desk covered as Apollo on paychecks. In May it worked with Blackstone on a $36bn debt deal to buy Anthropic chips.
What Apollo tells recipients to do
The letter asks people to review account statements, monitor credit reports, and consider a fraud alert or a security freeze. It reproduces contact details for Equifax, Experian and TransUnion.
It closes on the state of the inquiry. “Our investigation remains ongoing, and you may receive additional updates from us.”
What has not happened yet
No group has claimed the attack. TechRadar reported at the time of writing that the data had not surfaced on any leak site.
Apollo says the same in its own words. “We have no evidence that your information has been publicly posted or used for identity theft or fraud at this time.”
Get the TNW newsletter
Get the most important tech news in your inbox each week.
