Apollo Global Management has disclosed that hackers accessed certain cloud platforms in a July social engineering incident that exposed personal information belonging to individuals whose data it manages.[2][1][8]
In notification letters filed with the California attorney general, the private equity giant said the attackers gained unauthorized access to parts of its cloud environment between July 6 and July 10.[2][1][8]
The disclosure makes Apollo one of the first major private equity firms to confirm that sensitive personal data was compromised in an ongoing wave of attacks targeting the financial sector.[2][9][10]
Apollo said it detected the incident recently, notified law enforcement and engaged external cybersecurity and forensic experts to investigate and contain the breach.[2][4][8]
According to the notice, the firm determined on August 12 that potentially affected information includes names, dates of birth, contact details, home addresses and Social Security numbers.[4][8]
The company said it has seen no evidence so far that the data has been publicly posted or used for identity theft or fraud, and is offering affected individuals complimentary identity protection and credit monitoring services.[4][8]
Apollo, which manages roughly one trillion dollars in assets, said the breach involved only a subset of systems and that no client funds were impacted.[2][5][7]
The firm has not publicly specified how many people were affected or whether the compromised records relate to employees, investors or individuals connected to portfolio companies.[1][2]
The incident comes amid a broader campaign in which an extortion group tracked as UNC6671 and linked to the now-retired BlackFile brand has targeted hedge funds, private equity firms, law firms, financial rating agencies and other financial organizations.[10][11]
Researchers at Google’s Threat Intelligence Group and Mandiant reported that since early summer the crew has pivoted from earlier activity in manufacturing, healthcare, real estate, transportation and hospitality to focus on high-value financial and professional-services targets.[10][11][14]
Security analysts have observed phishing infrastructure and credential-harvesting domains tailored to staff at firms including Blackstone, Bain Capital, KKR, TPG, CME Group and Apollo, though most of those organizations have not confirmed any successful intrusions.[9][6][13]
The threat actors rely heavily on social engineering, impersonating corporate IT support staff in voice-based phishing calls and directing employees to fake login pages that capture credentials and multi-factor authentication codes for cloud services such as Salesforce and Microsoft 365.[14][15]
Once they obtain valid login details, the attackers move quickly to access cloud-hosted data and then threaten to leak stolen information unless a ransom is paid, according to recent analyses of the group’s activity.[10][11]
Some victims have reported escalating harassment, including aggressive messaging and offline intimidation, as the group seeks to increase pressure during extortion negotiations.[6][10]
For organizations in the financial sector, the Apollo incident underscores how credential theft and cloud account abuse can lead directly to large-scale exposure of sensitive personal data even without the use of novel exploits.[2][10]
Security teams are urging companies to tighten identity verification for IT support requests, implement call-back procedures, monitor for anomalous cloud logins and enforce phishing-resistant multi-factor authentication wherever possible to reduce the impact of similar social engineering campaigns.[14][15]
References
- Private equity firm Apollo confirms data breach amid hacking wave …
- Apollo Global confirms data breach after hackers target financial firms
- Apollo Reports Data Breach Incident Affecting Personal Information
- Apollo Confirms Breach as Hackers Target Financial Titans – Roic AI
- Details emerge on BlackFile’s recent attacks on financial companies
- JUST IN: $938 billion asset manager Apollo Global …
- TDTDDTDTAFFDAAFTTDFFTAT…
- Hackers targeted US private equity, other firms including …
- Hedge fund cyberattacks tied to BlackFile-linked UNC6671 …
- BlackFile Becomes REDACT: Private Equity Firms Face …
- Blackstone, KKR and CME targeted in vishing wave tied to BlackFile …
- Cybersecurity Weekly Briefing, 1 May – Telefónica Tech
- Ankura CTIX FLASH Update – April 28, 2026
