Apollo Global Management has confirmed that it suffered a data breach after hackers gained unauthorized access to certain cloud platforms and accessed sensitive personal information.
The incident is the latest development in a broader wave of cyberattacks targeting major U.S. financial institutions and other businesses.
According to reporting published on August 21, Apollo found that unauthorized access to certain cloud platforms occurred between July 6 and July 10. The information potentially affected included names, dates of birth, contact information, home addresses and Social Security numbers.
Apollo said it has notified law enforcement and brought in outside cybersecurity and forensic experts as its investigation continues.
The New York-based asset manager was also among dozens of prominent financial firms recently targeted in a campaign involving phone-based social engineering, highlighting how cybercriminals continue to exploit people as well as technology.
Apollo Confirms Unauthorized Access
Apollo's investigation found that attackers gained unauthorized access to certain cloud platforms during a period of several days in July.
The company later determined that personal information may have been affected.
That information included names, dates of birth, contact details, home addresses and Social Security numbers.
The exposure of sensitive personal information makes the incident particularly significant. While a company may quickly identify that unauthorized access occurred, determining exactly what information was accessed and which individuals were affected can take considerably longer.
Apollo said it reported the matter to law enforcement and engaged external cybersecurity and forensic specialists to investigate.
The investigation is still ongoing.
No Evidence So Far of Identity Theft or Fraud
Apollo said it had not found evidence, at the time of its disclosure, that the stolen information had been made public or used for identity theft or fraud.
The company is offering affected individuals identity-protection and credit-monitoring services.
However, the absence of known misuse at the time of disclosure does not necessarily mean a breach investigation is complete.
Companies dealing with cybersecurity incidents often continue examining logs, systems and potentially affected data after an initial public notification.
Additional details could emerge as Apollo's investigation progresses.
Part of a Wider Campaign Against Financial Firms
The Apollo breach comes after reports that dozens of prominent U.S. financial institutions and other businesses had recently been targeted by hackers using phone-based social engineering tactics.
Reuters previously reported that attackers targeted organizations including private-equity firms, financial companies and other high-value businesses.
The campaign reportedly relied on relatively low-tech methods.
Attackers used phone calls, spoofed numbers and fraudulent websites in attempts to persuade employees to reveal passwords or multi-factor authentication codes.
Among the organizations targeted in the broader campaign were major names from the financial sector, including Apollo, Blackstone, Bain Capital, KKR, TPG, Bridgewater Associates, CME Group and Moody's.
Being targeted does not necessarily mean that every organization suffered a successful breach. Cyberattack campaigns can involve large numbers of attempted intrusions, many of which may be blocked or detected before attackers gain meaningful access.
Apollo's confirmed data breach, however, shows the potential consequences when attackers successfully gain unauthorized access.
How Social Engineering Attacks Work
Social engineering is a cybersecurity tactic that focuses on manipulating people rather than directly defeating a technical security system.
An attacker may impersonate an IT employee, a help-desk worker or another trusted contact.
The goal can be to persuade an employee to reveal credentials, provide authentication codes or approve access that should not have been granted.
The wider campaign targeting financial firms reportedly included phone calls designed to convince employees that they were speaking with legitimate technology support personnel.
This approach is sometimes described as voice phishing, or vishing.
The effectiveness of these attacks highlights a major challenge for modern organizations: even companies with sophisticated cybersecurity technology can remain vulnerable if attackers successfully deceive an employee.
Why Financial Firms Are Major Targets
Financial institutions and investment companies manage significant amounts of sensitive information.
That can include employee records, client information, financial data and confidential business communications.
For cybercriminals, this information can be valuable even when an attack does not directly result in the theft of money.
A serious data breach can also create substantial costs for the affected organization.
Those costs may include forensic investigations, customer notifications, identity-protection services, legal expenses, regulatory scrutiny and potential reputational damage.
The financial sector is also highly interconnected. Large asset managers and investment firms often work with outside technology providers, business partners and other organizations.
That makes cybersecurity an operational issue that can extend beyond a single company.
The Human Side of Cybersecurity
The recent attacks are a reminder that cybersecurity is not only about software vulnerabilities.Recent AI cybersecurity threats have also highlighted how rapidly digital security risks are evolving.
Companies can use encryption, monitoring systems and other advanced security tools, but employees still receive phone calls, emails and requests for access every day.
Attackers increasingly attempt to take advantage of those human interactions.
A fraudulent call may appear convincing if the attacker knows the name of an employee, understands the company's internal structure or uses a spoofed phone number.
That is why organizations increasingly rely on multiple verification procedures for sensitive requests.
A request to reset credentials or approve unusual access may require confirmation through an independent communication channel rather than relying solely on the initial phone call or message.
For large financial institutions, maintaining those procedures across thousands of employees and multiple technology systems can be a significant challenge.
Why the Apollo Breach Matters
Apollo is a major U.S. asset manager, making the breach significant beyond the individuals whose information may have been affected.
The incident comes during a period of increased concern about cyber threats facing Wall Street, private-equity firms and other financial organizations.
The broader campaign also demonstrates that attackers do not always need highly sophisticated software exploits to create serious problems.
In some cases, a carefully planned phone call or impersonation attempt can become the starting point for unauthorized access.
This creates an ongoing challenge for companies.
Security technology must continue to improve, but organizations also need strong procedures for verifying identity and handling unusual requests.
The Apollo incident illustrates how quickly a human-targeted attack can become a broader data-security problem.
What Happens Next?
Apollo's investigation remains ongoing.
The company may provide additional information as it completes its forensic review and determines the full scope of the incident.
Law-enforcement agencies may also continue examining the wider campaign targeting U.S. financial institutions and other businesses.
For individuals affected by the breach, Apollo said it is providing identity-protection and credit-monitoring services.
The broader implications may extend beyond Apollo.
Financial firms are likely to continue reviewing how employees verify IT support requests, reset credentials and approve access to sensitive systems.
The recent attacks show that even as cybersecurity technology becomes more advanced, relatively simple social-engineering tactics can still pose a serious threat.
Bottom Line
Apollo Global Management's confirmed data breach is the latest sign that major U.S. financial institutions remain attractive targets for cybercriminals.
The company found unauthorized access to certain cloud platforms between July 6 and July 10, with potentially affected information including names, dates of birth, contact information, home addresses and Social Security numbers.
Apollo has notified law enforcement and hired outside cybersecurity and forensic experts to investigate.
At the time of its disclosure, the company said it had not found evidence that the stolen information had been publicly released or used for identity theft or fraud.
The incident is also part of a broader story affecting the financial sector.
Recent attacks have shown how hackers can use phone calls, impersonation and other social-engineering tactics to target some of the country's largest financial organizations.
For businesses, the lesson is increasingly clear: cybersecurity is not only about protecting computers and networks. It is also about protecting the people who use them.
As Apollo's investigation continues, additional information could emerge about the scope of the breach and the wider campaign targeting major U.S. financial firms.
This article is based on publicly available reporting available at the time of publication. Apollo's investigation is ongoing, and additional information may emerge.
Sources
Reuters: Apollo Global confirms data breach after hackers target financial firms
Reuters: Hackers targeted U.S. private equity and other firms including Blackstone and CME
Reuters: Hackers targeted U.S. private equity and other firms including Blackstone and CME
FAQ
What happened in the Apollo Global data breach?
Apollo Global Management said it found unauthorized access to certain cloud platforms between July 6 and July 10, 2026, resulting in the potential exposure of personal information.
What information may have been affected?
The potentially affected information included names, dates of birth, contact information, home addresses and Social Security numbers.
Has Apollo found evidence of identity theft or fraud?
At the time of its disclosure, Apollo said it had not found evidence that the stolen information had been made public or used for identity theft or fraud.
How were financial firms targeted?
The broader campaign reportedly involved phone-based social engineering, including attempts to impersonate IT support personnel and trick employees into revealing credentials or authentication codes.
Why does the Apollo data breach matter?
The incident highlights the continuing cybersecurity risks facing major financial institutions and shows how human-targeted social-engineering attacks can lead to serious data-security incidents.

0 Comments