Skip to content
Social engineeringContained

Apollo Global Management data breach

Apollo Global Management disclosed that a phone-based social-engineering attack gave intruders access to its cloud systems for four days in July 2026, exposing names, dates of birth, contact details, home addresses and Social Security numbers as part of a wider campaign targeting financial firms.

Victim
Apollo Global Management, Inc.

On 21 August 2026, Apollo Global Management, Inc. — one of the world's largest alternative-asset managers and private-equity firms — confirmed that a phone-based social-engineering attack had given intruders access to certain of its cloud platforms for four days in July, exposing sensitive personal data. The disclosure came amid a broader hacking wave targeting large financial institutions during the summer of 2026.

According to Apollo and security reporting, an unauthorized user had access to certain cloud systems from 6 to 10 July 2026. Rather than a technical exploit, the attackers used a help-desk impersonation scheme — calling employees and posing as IT support to trick them into granting access. The campaign has been tracked under several names, including Falcon, Helix, Pink and Redact, associated with a cluster of actors known for voice-phishing enterprise cloud tenants.

What happened

On 12 August 2026, Apollo determined that the information involved included individuals' names, dates of birth, contact information, home addresses and Social Security numbers. The firm reported the breach to the California Attorney General on 20 August and mailed notification letters to affected individuals on 21 August. Apollo said it found no evidence that the compromised personal information had been made public or used for fraud.

The incident stood out less for its technical sophistication than for its method: attackers walked in through the help desk. It reinforced a pattern seen repeatedly across 2026, in which financial and enterprise targets were breached not through unpatched software but through human-targeted deception aimed at cloud-identity access.

Impact

  • Exposed personal data included names, dates of birth, contact details, home addresses and Social Security numbers.
  • Access was limited to a four-day window (6-10 July 2026) in certain cloud platforms; Apollo reported no evidence of public exposure or fraud.
  • Affected individuals face heightened identity-theft and targeted-fraud risk, and the breach prompted class-action interest.

Why it matters

The Apollo breach is a clear example of how social engineering against the help desk has become a leading path into well-resourced financial firms. When attackers can talk their way to cloud-identity access, defenses built around patching and perimeter controls do little; the decisive control is rigorous identity verification for support and reset workflows, paired with phishing-resistant MFA. For a private-equity manager holding sensitive data on employees, investors and portfolio companies, even a short window of unauthorized cloud access can expose durable identifiers with long-lived fraud value.

Timeline

  1. An unauthorized user gains access to certain Apollo cloud platforms via a phone-based social-engineering scheme.

  2. The unauthorized access ends after four days.

  3. Apollo determines the exposed data includes names, dates of birth, contact details, home addresses and Social Security numbers.

  4. Apollo reports the breach to the California Attorney General.

  5. Apollo mails notification letters to affected individuals and the breach is widely reported.

Sources

  1. techcrunch.comhttps://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/
  2. pymnts.comhttps://www.pymnts.com/cybersecurity/2026/apollo-global-management-social-engineering-attack-data-breach/
  3. securitymagazine.comhttps://www.securitymagazine.com/articles/102509-social-engineering-scheme-led-to-apollo-data-breach
  4. databreaches.nethttps://databreaches.net/2026/08/24/personal-information-exposed-in-apollo-global-data-breach/

Related incidents