Apollo Global Confirms Data Breach After Hackers Access Personal Information

Apollo said unauthorized users accessed cloud platforms between July 6 and July 10, potentially exposing names, birth dates, contact details, home addresses and Social Security numbers.

John Miller
Written by John Miller
Published
Share

Apollo Global Management has confirmed a data breach after unauthorized users accessed certain cloud platforms in July, exposing personal information that may include names, dates of birth, contact details, home addresses and Social Security numbers.

The access occurred between July 6 and July 10, according to Apollo’s notice to affected individuals. The California Attorney General’s breach-notification page lists Apollo Management Holdings, L.P. as the reporting organization and July 6 as the known breach date. Apollo said the incident involved social engineering rather than a publicly identified software vulnerability.

As of the notice, Apollo said it had not found evidence that the affected information had been publicly posted or used for identity theft or fraud. The firm notified law enforcement, brought in outside cybersecurity and forensic specialists and is offering affected individuals complimentary third-party identity protection and credit monitoring services.

What Apollo says was accessed

Apollo’s investigation found unauthorized access to certain cloud platforms over a five-day period. The company later determined that the information potentially affected could include names, birth dates, contact information, home addresses and Social Security numbers. Those categories can create meaningful identity-theft risk because they combine basic identifying information with data that can be difficult to change.

Several important details remain undisclosed. Apollo has not publicly identified how many people were affected in the materials reviewed for this story, and the California notice page does not provide a total. The public disclosures also do not specify whether the exposed records belonged primarily to employees, investors, business contacts or another group. That distinction matters for understanding the practical scope of the breach, but the available notice does not support a narrower description.

Apollo has also not publicly named the cloud platforms involved. It described the event as a social-engineering incident, which points to deception of a user or employee rather than proof that an attacker broke through a flaw in the underlying cloud provider. The company has not disclosed the exact sequence used to obtain access, so it would be premature to attribute the breach to a specific hacking group or to a particular identity platform.

The incident affects a firm operating at large financial scale. Apollo reported about $1.05 trillion of assets under management as of June 30, 2026, in its latest quarterly results. Its businesses span asset management and retirement services, meaning its operations depend on information systems that handle confidential data across employees, investors, policyholders and other parties.

The breach fits a wider social-engineering campaign

The timing overlaps with a broader wave of attacks against financial and professional-services companies. Reuters reported earlier in August that Apollo was among numerous firms targeted by ransom-seeking hackers using phone calls and fake login sites to obtain employee credentials. At that point, it was not clear from the reporting whether the effort against Apollo had succeeded.

Google Threat Intelligence Group separately documented a campaign that had shifted toward financial services, private equity and professional-services firms by July. In an August 6 threat-intelligence report, Google said a group it tracks as UNC6671 used voice phishing to impersonate IT help-desk staff and direct employees to spoofed authentication pages. Those pages were designed to intercept credentials and multi-factor authentication tokens before attackers moved into cloud environments.

Google said the group had used several extortion brands, including Redact, Pink, Helix and Falcon, and had focused on data theft from software-as-a-service environments. Its researchers described automated exfiltration from platforms including Microsoft 365 and Okta after attackers established persistent access. By July, the observed targeting had narrowed toward private equity firms, law firms and financial rating agencies.

Those findings are useful context for Apollo’s disclosure, but they do not establish attribution. Apollo has not publicly named UNC6671 or any other group as responsible, and Google’s report does not identify Apollo as a confirmed victim. The overlap is in timing, industry focus and use of social engineering, not a verified statement that the same operators carried out this breach.

The distinction matters because social-engineering campaigns are often designed to look similar. Attackers may pose as internal support staff, create company-branded login pages and pressure employees to complete an urgent security or account change. Different criminal groups can use the same playbook, and infrastructure or branding can change quickly after a successful intrusion.

Apollo’s investigation is still open

Apollo’s response so far centers on investigation, law-enforcement notification and protection for affected individuals. The company said outside cybersecurity and forensic experts were engaged after the unauthorized access was identified. Free identity-protection and credit-monitoring services are intended to help people detect suspicious activity if exposed data is later used for fraud.

The absence of detected misuse at the time of the notice does not mean the information has no future value to criminals. Social Security numbers, birth dates and home addresses can remain useful long after a breach, which is why monitoring and fraud alerts are common parts of post-incident response. Apollo did not say that every affected person had every listed data element exposed, only that the potentially impacted information could include those categories.

The breach also tests cybersecurity risks Apollo has already described to investors. In its February 2026 annual report, the firm said it relied on information systems to process and maintain confidential data and warned that theft or exposure of personally identifiable information could lead to remediation costs, litigation, regulatory action and reputational harm. At that time, Apollo said it was not aware of security incidents that had materially affected, or were reasonably expected to materially affect, its operations or financial condition.

That earlier risk disclosure should not be read as a judgment about the financial materiality of the July incident. Apollo has not publicly said in the breach notice that the event caused a material impact on its operations or financial condition. The immediate confirmed issue is narrower: unauthorized access occurred, sensitive personal information was potentially affected, and the company is still investigating.

The next useful disclosures would be the size and composition of the affected population, the cloud systems involved and whether Apollo identifies a specific threat actor or additional data categories. For now, the California filing confirms the breach date and reporting entity, while Apollo’s notice establishes the types of personal information at risk and the remediation steps already under way.

John Miller

About the author

John Miller

Economics Contributor

John Miller writes about the economic forces behind markets and financial decisions. He covers inflation, interest rates, employment, supply and demand, public policy and the channels through which economic changes affect investors, borrowers and households.

View author profile