Cyber Incident Victim: Apollo Global Management
Timeline
Summary
Apollo Global Management suffered a data breach after hackers gained unauthorized access to certain cloud platforms and obtained personal information including names, dates of birth, contact details, home addresses, and social security numbers. The firm notified law enforcement, engaged external cybersecurity experts, and is offering affected individuals complimentary identity protection and credit monitoring while noting that there is currently no evidence the stolen data has been posted publicly or used for fraud. The incident is part of a broader campaign targeting financial companies that used phone calls and fraudulent websites to harvest credentials, with similar breaches reported at other firms such as Uber Freight and Levi Strauss.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On August 21, 2026, Apollo Global Management disclosed that it had suffered a data breach the previous month, with unauthorized access to certain of its cloud platforms occurring between July 6 and July 10, 2026. The firm said it learned of the breach after detecting the intrusion and promptly notified law enforcement authorities. In response, Apollo engaged external cybersecurity and forensic experts to conduct a thorough investigation of the incident. The disclosure was made in a letter to affected individuals signed by Matthew Breitfelder, the company’s Head of Human Capital.

According to the company’s early August assessment, the information potentially exposed in the breach included names, dates of birth, contact information, home addresses, and social security numbers of individuals associated with the firm. Reuters reported that internet intelligence data showed hackers had created fraudulent websites designed to steal passwords from employees of private equity firms and financial companies, a tactic that complemented the use of phone calls to target victims. Apollo noted that the intrusion was part of a broader campaign in which dozens of prominent U.S. financial institutions and other businesses were targeted by ransom‑seeking hackers relying on low‑tech social engineering methods. Despite the sophistication of modern defenses, the firm acknowledged that such phone‑based schemes remain highly effective against the financial sector.
Apollo stated that, as of the date of the letter, its investigation had not uncovered any evidence that the stolen data had been publicly posted or used for identity theft or fraud. To mitigate potential harm, the firm began offering affected individuals complimentary third‑party identity protection and credit monitoring services. The letter from Matthew Breitfelder emphasized that the company remains committed to safeguarding personal information and will continue to cooperate with authorities. The incident was mentioned alongside similar disclosures from Uber Freight and Levi Strauss, which also reported investigating unauthorized access to their systems earlier in August 2026.