Skip to content
22 August 2026

Apollo Global Management Data Breach: Hackers Steal Sensitive Information

Apollo Global Management has confirmed a data breach where hackers stole personal information from its cloud systems, highlighting the growing threat of social engineering attacks in the financial sector.

Apollo Global Management Data Breach: Hackers Steal Sensitive Information

In a significant development, Apollo Global Management one of the world’s largest private equity firms, has confirmed a data breach that exposed sensitive personal information. The breach, which occurred between July 6 and July 10 is part of a broader wave of cyberattacks targeting financial institutions and private equity firms.

The breach was disclosed in a letter filed with California’s attorney general, revealing that hackers used social engineering tactics to gain access to Apollo’s cloud environment. The stolen data includes names, birth dates, contact information, home addresses, and Social Security numbers. The company has not specified whether the affected individuals are employees or individuals at companies it owns.

Apollo Joins a Growing List of Financial Sector Victims

Apollo is not alone in facing such cyber threats. Security researchers at Google have identified a coordinated campaign targeting private equity companies and financial giants. The hackers, known by various names including Falcon, Helix, Pink, and Redact employ social engineering attacks to trick employees into revealing their passwords and multi-factor authentication codes.

These attacks often involve impersonating IT helpdesks or support personnel, convincing employees to enter their credentials into spoofed login portals. Once inside, the hackers steal data and then extort the companies, demanding ransoms or threatening to publish the data on their leak sites. Some of these attacks have reportedly netted the hackers ransoms as high as $750,000.

The Broader Implications of the Apollo Data Breach

The Apollo data breach underscores the vulnerabilities in the financial sector’s cybersecurity infrastructure. As one of the world’s largest private equity firms, with $1.05 trillion in assets under its management, Apollo’s breach highlights the potential risks for both the company and its stakeholders.

In response to the breach, Apollo has taken several steps to mitigate the damage. The company notified law enforcement, engaged leading cybersecurity and forensic experts, enhanced its security protocols, and launched an investigation. Apollo has also offered affected individuals 24 months of complimentary credit monitoring and identity protection services.

Despite these measures, the breach raises important questions about the effectiveness of current cybersecurity practices. The use of social engineering tactics, which exploit human psychology rather than technical vulnerabilities, demonstrates the need for comprehensive security training and awareness programs within organizations.

Lessons Learned and Future Considerations

The Apollo data breach serves as a stark reminder of the evolving nature of cyber threats. Organizations must adopt a proactive approach to cybersecurity, implementing robust measures to protect against social engineering attacks. This includes requiring phishing-resistant multi-factor authentication for privileged accounts, restricting and monitoring help desk password resets, and verifying identity through out-of-band procedures.

Individuals affected by the breach should take immediate steps to protect their personal information. This includes activating the offered monitoring services, placing a credit freeze with major bureaus, reviewing account activity, and remaining vigilant for unsolicited calls or messages requesting credentials or personal data.

As the financial sector continues to grapple with these challenges, the Apollo data breach highlights the critical need for enhanced cybersecurity measures and ongoing vigilance against sophisticated cyber threats.