Private equity giant Apollo Global Management has confirmed a data breach in which hackers stole personal information from the company’s cloud systems. The breach occurred between July 6 and July 10, according to a letter filed with California’s attorney general, and comes amid a wave of cyberattacks targeting major financial firms.
Apollo’s human resources chief, Matthew Breitfelder, said the hackers used a social engineering attack to gain access to the company’s cloud environment. The stolen data includes names, birth dates, contact information such as home addresses, and Social Security numbers. The letter does not specify whether the affected individuals are Apollo employees or people associated with companies it owns.
Also read: Calendly launches AI meeting note-taker, plans Callie assistant to automate post-meeting work
Apollo’s disclosure and the broader hacking campaign
Apollo, one of the world’s largest private equity firms with $938 billion in assets under management, disclosed the incident in a regulatory filing. The company has around 5,000 employees as of February 2026, according to public filings. When reached for comment, Apollo spokesperson Giovanna Falbo did not immediately respond to questions about the breach, including whether a ransom was paid.
The confirmation comes weeks after security researchers at Google warned that hackers were targeting private equity companies and financial giants in a widespread extortion campaign. Reuters reported that Apollo was among the companies targeted, along with Blackstone, Bridgewater, Bain Capital, and others, though it was unclear at the time whether any had been successfully breached.
Also read: Peacock hikes prices across all streaming plans — here’s what subscribers will pay
How the attackers operate
Google’s researchers said the hackers, who operate under names like Falcon, Helix, Pink, and Redact, rely heavily on social engineering. They call employees, posing as IT helpdesk or support staff, and trick them into entering passwords and multi-factor authentication codes on spoofed login portals. Once inside, they steal data and then extort the company, threatening to publish the stolen information on a leak site unless a ransom is paid. Some attacks have netted ransoms as much as $750,000, according to Google.
This pattern is consistent with a broader trend of cybercriminals targeting high-value financial institutions, where the potential payoff from extortion is significant. The attack on Apollo highlights the vulnerability of even the largest financial firms to relatively low-tech social engineering tactics.
What this means for the industry and affected individuals
The breach raises serious concerns about data security in the private equity sector, which manages vast amounts of sensitive financial and personal data. For the individuals whose information was stolen, the exposure of Social Security numbers and home addresses increases the risk of identity theft and financial fraud. Apollo has not yet disclosed the total number of affected individuals, nor has it announced any specific remediation steps beyond the regulatory filing.
The incident also underscores the growing threat of extortion-based cyberattacks. While many companies focus on defending against sophisticated malware, this campaign demonstrates that a well-crafted phone call can be just as effective. The fact that Apollo, a firm with significant cybersecurity resources, fell victim to this tactic suggests that other firms may be equally vulnerable.
For the broader financial industry, this breach serves as a reminder that social engineering remains one of the most effective attack vectors. Companies are likely to increase employee training and tighten multi-factor authentication protocols in response. Apollo’s disclosure may also prompt other targeted firms to come forward, as the pressure to disclose breaches grows from regulators and investors.
As the investigation continues, affected individuals should monitor their financial accounts and consider credit monitoring services. Apollo has not yet announced whether it will offer such services to those impacted, but it is a common step following a breach of this nature.
This is a developing story, and more details are expected to emerge as Apollo and law enforcement investigate the incident.
Disclaimer: This article is for informational purposes only and does not constitute financial advice. The cryptocurrency and financial markets are volatile and uncertain. Readers should conduct their own research before making any investment decisions.