Cyber Incident Victim: Apollo
Timeline
Summary
Apollo confirmed a data breach in which hackers accessed its cloud systems via social engineering and exfiltrated personal data including names, birth dates, addresses and Social Security numbers. The firm disclosed the incident in a letter filed with California’s attorney general, noting that the intrusion occurred after employees were tricked into revealing credentials through spoofed helpdesk calls. Stolen data covered employees and possibly individuals associated with portfolio companies, though the letter did not specify which groups were affected. The firm employs roughly five thousand staff and manages about nine hundred thirty‑eight billion dollars in assets. The breach is part of a broader campaign in which threat actors using aliases such as Falcon, Helix, Pink and Redact target financial and private equity firms with social engineering to steal data and demand ransom, with some demands reaching up to seven hundred fifty thousand dollars. It remains unclear whether any ransom was paid or whether other targeted firms have suffered similar compromises.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 4 actors | Available to members | Available to members |
Description
Apollo Global Management confirmed a data breach in a letter filed with California’s attorney general. The breach involved hackers stealing personal information from the company’s cloud systems. According to the company’s human resources chief Matthew Breitfelder, the intrusion occurred via a social engineering attack that took place between July 6 and July 10. The attackers accessed names, birth dates, contact information including home addresses, and Social Security numbers. The letter did not specify whether the affected individuals were employees of Apollo or persons associated with companies it owns. Apollo reported having approximately 5,000 employees as of February 2026 and managing $938 billion in assets.

The breach is situated within a broader warning from Google about a hacking campaign targeting financial and private equity firms. Google identified the threat actors using aliases such as Falcon, Helix, Pink, and Redact. These actors rely on social engineering tactics, calling employees and posing as IT helpdesk or support staff to trick them into entering passwords and multi‑factor authentication codes on spoofed login portals, thereby gaining access to corporate networks. After exfiltrating data, the hackers typically extort the victim organizations by demanding a ransom or threatening to publish the stolen information on a leak site. Google noted that some of these attacks have yielded ransoms as high as $750,000.
In response to the incident, Apollo filed the required breach notification with California’s attorney general. The company’s spokesperson, Giovanna Falbo, did not provide comment or answer questions when approached by TechCrunch, including whether a ransom was paid. No further details about containment, remediation, or ongoing investigation were disclosed in the available sources. The confirmation adds Apollo to the list of firms that were reportedly targeted in the campaign, alongside Blackstone, Bridgewater, Bain Capital, and others, although the extent of successful breaches at those entities remains unspecified.