Apollo Global Management disclosed a data breach after attackers gained unauthorized access to certain cloud platforms and stole personal information from its systems. The firm said the intrusion occurred between July 6 and July 10 and exposed data including names, dates of birth, contact details, home addresses, and Social Security numbers, according to its filing with the California attorney general.
The breach appears linked to a broader extortion campaign targeting major U.S. financial institutions and private equity firms. Reporting tied the activity to social engineering tactics including fake IT helpdesk calls, spoofed login portals, and theft of passwords and multi-factor authentication codes. Apollo said it has notified law enforcement, engaged outside cybersecurity and forensic specialists, and is offering affected individuals identity protection and credit monitoring while the investigation continues.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
Apollo said it determined on Aug. 12 that the intrusion had compromised personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers. This provided a specific date for when the company confirmed the scope of exposed information.
Apollo said it learned earlier in August that the potentially impacted information included names, dates of birth, contact information, home addresses, and Social Security numbers. This clarified the scope of the data exposed in the intrusion.
Apollo Global Management said attackers gained unauthorized access to certain cloud platforms between July 6 and July 10 using a social engineering attack. The attackers stole personal information including names, dates of birth, contact information, home addresses, and Social Security numbers.
Apollo said affected individuals would receive complimentary third-party identity protection and credit monitoring services. The company also said it had not found evidence at the time of reporting that the stolen data had been publicly posted or used for fraud.
Apollo confirmed the data breach in a letter filed with the California attorney general. The disclosure said attackers used social engineering to access Apollo's cloud environment and steal personal information.
Following the breach, Apollo notified law enforcement and engaged outside cybersecurity and forensic experts to investigate. The company said its investigation remained ongoing.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcesecuritymagazine.com
Open sourcemalware.news
Open sourcesecurityweek.com
Open sourcecyberscoop.com
Open sourcebusinessinsurance.com
Open sourcetechcrunch.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.