Truth that Matters. Stories that Impact

Truth that Matters. Stories that Impact

Technology

Apollo Global Management Confirms Cloud Data Breach Affecting Personal Records

Apollo Global Management has confirmed that unauthorized actors infiltrated its cloud environment and accessed sensitive personal information. The breach, which occurred in July, was disclosed in a formal notification letter submitted to the California Attorney General’s office.

What Happened

According to a filing signed by Apollo’s Chief Human Resources Officer Matthew Breitfelder, cyber attackers utilized a social engineering campaign to compromise the firm’s cloud infrastructure. The unauthorized access took place between July 6 and July 10.

During the intrusion, the perpetrators extracted sensitive personal records, including names, dates of birth, contact details such as residential addresses, and Social Security numbers. The filing did not specify the exact classification or identity of the individuals affected, leaving it unclear whether the data belonged to Apollo’s direct workforce or personnel tied to portfolio companies under its management.

Key Highlights

  • Compromise Window: The cloud network was accessed without authorization between July 6 and July 10.
  • Compromised Information: Stolen records consist of names, contact information, home addresses, dates of birth, and Social Security numbers.
  • Target Scale: Apollo Global Management oversees $938 billion in assets and reported having approximately 5,000 employees as of February 2026 regulatory documents.
  • Broader Threat Context: Google threat researchers had recently sounded alarms about an extortion wave orchestrated by actors referred to as Falcon, Helix, Pink, and Redact.
  • Attack Methodology: Attackers in this wave have been calling corporate personnel while impersonating IT support staff to coax credentials and multi-factor authentication codes via fraudulent login pages.

Why This Matters

The incident illustrates how private equity and financial institutions are being actively singled out for data extortion. Weeks prior to the disclosure, security analysts at Google warned of a campaign directed at high-profile financial firms, with Reuters identifying Apollo alongside peers such as Blackstone, Bain Capital, and Bridgewater as targets.

According to findings from Google, attackers running these campaigns frequently attempt to extort organizations by demanding ransom payments under the threat of releasing stolen records onto leak portals. Google reported that some related intrusions have generated ransom payments reaching up to $750,000.

What to Watch Next

It remains unconfirmed whether Apollo received an extortion demand or paid a ransom following the incident, as company spokesperson Giovanna Falbo did not immediately respond to media inquiries regarding payments. Observers and affected parties will also be watching for further administrative disclosures clarifying the exact population of individuals whose personal records were exposed.

Frequently Asked Questions

When did the Apollo data breach take place?

The unauthorized intrusion into Apollo’s cloud environment occurred over a five-day window between July 6 and July 10.

What specific data was compromised during the incident?

The regulatory filing noted the theft of names, dates of birth, home addresses and contact information, as well as Social Security numbers.

Who was targeted in the breach?

The notification filed with California authorities did not specify whether the impacted individuals were internal Apollo personnel or workers from businesses owned by the private equity firm.

Source: Breach notification filing submitted to the California Attorney General’s Office, with additional reporting from TechCrunch and Reuters.