Full Breakdown
Apollo Global Management Confirms Social-Engineering Data Breach
8/22/2026, 2:02:46 AM
Breach Overview
Between July 6 and July 10, 2026, Apollo Global Management’s cloud environment was accessed by attackers who used a social-engineering scheme that impersonated IT support staff. The intrusion allowed the theft of personal information, including names, dates of birth, home addresses, contact details and Social Security numbers. Apollo disclosed the breach in a notification filed with California’s attorney general and indicated that, to date, no evidence shows the data has been posted online or used for identity theft.
Broader Hacking Campaign Targeting Financial Firms
The incident occurred amid a wave of extortion-focused attacks on private-equity and financial institutions. Google’s Threat Intelligence Group has identified multiple threat-actor brands—Falcon, Helix, Pink and Redact—that employ voice-phishing and credential-harvesting tactics. Cyberscoop attributes the campaign to BlackFile, a group linked to the broader The Com network, which reportedly splits extortion operations across those four brands. The attackers typically demand ransom payments that can start around $3 million and are often negotiated down to under $1 million; some earlier incidents yielded ransoms as high as $750,000.
Scope of Compromised Data and Financial Metrics
- Personal data compromised: names, dates of birth, home addresses, contact information, Social Security numbers.
- Employee base: approximately 5,000 staff members as of February 2026.
- Assets under management: reported as $938 billion in one filing and $1.05 trillion in another filing at the end of June 2026.
- Financial performance: Apollo announced record second-quarter results on August 4, 2026, highlighting strong growth in its Asset Management and Retirement Services divisions.
Apollo’s Immediate Actions
Apollo’s global head of human capital, Matthew Breitfelder, said the firm promptly notified law enforcement, engaged leading external cybersecurity and forensic experts, enhanced its security protocols and launched a full investigation. The company also reported that it has not found any evidence of the stolen data being posted publicly or exploited for fraud.
Verbatim Quotes
- “Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” — Matthew Breitfelder, human resources chief
- “Similar to other financial services firms, Apollo recently experienced a social engineering incident,” — Matthew Breitfelder, human resources chief
Conflicting Reports and Gaps
- Assets under management: Apollo’s disclosures list two different figures—$938 billion and $1.05 trillion—without clarification of the discrepancy.
- Attribution of the threat group: Google’s intelligence references multiple brand names (Falcon, Helix, Pink, Redact), while Cyberscoop attributes the campaign to BlackFile. Both characterizations appear in source material.
- Number of individuals affected: Apollo has not disclosed how many people’s data were compromised, and no public evidence of data release has been identified.
What’s Next
Regulatory bodies are expected to review the breach, and Apollo may face inquiries regarding its security controls and potential reputational impact. The firm has indicated that further updates will be provided as the investigation progresses and as any additional mitigation measures are implemented.
