Apollo confirms data breach after cloud intrusion

The private equity firm said hackers used social engineering to access cloud systems and steal personal data during a four-day window in July.
Apollo Global Management has confirmed a data breach after hackers accessed its cloud environment and stole personal information. The private equity firm said the intrusion took place during a four-day window in July. It adds to a broader wave of attacks aimed at major financial companies. For Apollo, one of the world’s largest private equity firms with $938 billion in assets under management, the disclosure carries weight beyond a routine security incident.
Apollo says social engineering opened the door
According to a letter filed with California’s attorney general, Apollo human resources chief Matthew Breitfelder said the attackers used social engineering to gain access to the company’s cloud environment between July 6 and July 10.
Social engineering relies on tricking people rather than breaking software directly. In the broader campaign described by Google, attackers call employees while posing as IT helpdesk staff or support agents, then try to persuade them to enter passwords and multi-factor authentication codes into fake login pages. That can hand over access to corporate systems without exploiting a technical flaw.
Apollo said the hackers took names, birth dates, contact information including home addresses, and Social Security numbers.
The company’s letter does not say exactly whose data was taken. It remains unclear whether the affected people were Apollo employees, people connected to companies it owns, or another group.
The breach follows warnings about attacks on finance firms
The incident surfaced about a month after security researchers warned about a hacking campaign aimed at financial and private equity firms. Reuters had previously reported that Apollo was among the companies targeted, along with Blackstone, Bridgewater, Bain Capital and others, though it was not clear at the time whether those attempts had succeeded.
Google has said the attackers are known by several names, including Falcon, Helix, Pink and Redact. The company also said the group’s method depends heavily on deception: hackers contact employees, pose as internal support, and try to collect access credentials and authentication codes.
After getting in and stealing data, the attackers then try to extort the company. Google said some of the attacks have brought in ransoms of as much as $750,000, as IT-PUB News notes.
Apollo has not said whether it paid any ransom in this case. When TechCrunch asked for comment, Apollo spokesperson Giovanna Falbo did not immediately respond to questions about the breach or whether the company paid the hackers.
The stolen data makes the breach more serious
The information Apollo says was taken is particularly sensitive. Names, birth dates, home addresses and Social Security numbers can be used in identity theft, fraud and other forms of abuse.
That makes this more than a routine security problem. For a company of Apollo’s size, the disclosure raises questions about how much personal data is stored in cloud systems and how exposed those systems can be when attackers target employees instead of software vulnerabilities.
Apollo said it had around 5,000 employees as of February 2026, according to public regulatory filings. But it did not specify whether the stolen data belonged to staff, clients, or people tied to businesses in its portfolio.
The case also shows how cloud access can become a weak point when attackers successfully impersonate trusted support staff. Rather than forcing their way in, they try to convince someone to let them in.
A broader extortion campaign is hitting major firms
Apollo’s disclosure fits into a wider pattern that has already drawn attention across cybersecurity and finance. The campaign described by Google has targeted some of the biggest names in private equity and financial services, suggesting attackers are focusing on organizations that hold valuable data and may be able to pay large ransoms.
Reports that some of these attacks have led to six-figure payments help explain why the campaign has become a serious concern. Social engineering can be profitable enough to keep spreading, especially when it is aimed at companies holding large amounts of sensitive personal and business information.
For Apollo, the breach is a public reminder that even large, well-resourced firms can be exposed through human-targeted attacks. And in this case, the company still has not said whose personal data was taken.