Apollo Global Management has confirmed a data breach in which hackers accessed its cloud environment and stole personal information, including names, birth dates, contact details, and Social Security numbers. The private equity firm disclosed the incident in a letter filed with California’s attorney general, according to the company’s human resources chief, Matthew Breitfelder. The attackers used a social engineering scheme to break into Apollo’s systems between July 6 and July 10, the letter states.
The letter does not specify whose data was taken, such as Apollo employees or individuals at companies the firm owns. Apollo is one of the largest private equity firms in the world, managing $938 billion in assets. The company had roughly 5,000 employees as of February 2026, based on its public regulatory filings. Apollo spokesperson Giovanna Falbo did not immediately respond to questions about the incident, including whether a ransom was paid.
The confirmed breach follows a warning from security researchers at Google about a hacking campaign targeting private equity and financial firms. Google reported that hackers were using extortion tactics against companies like Apollo, Blackstone, Bridgewater, Bain Capital, and others, though it was previously unclear if any had been successfully compromised. The attackers operate under names including Falcon, Helix, Pink, and Redact, according to Google.
The hackers rely primarily on social engineering, calling employees and posing as IT helpdesk or support staff. Their goal is to trick workers into entering passwords and multi-factor authentication codes on spoofed login pages, granting the attackers access to corporate networks. Once data is stolen, the hackers demand a ransom and threaten to publish the information on a leak site if unpaid.
Google noted that some of these attacks have resulted in ransoms as high as $750,000. The campaign represents a broader trend of cybercriminal activity targeting financial giants in the United States, where sensitive personal data on employees and clients is considered highly valuable. The breach at Apollo highlights the persistent risk that social engineering poses even to sophisticated financial institutions.
Apollo’s disclosure comes at a time when U.S. regulators and companies are increasingly focused on cybersecurity preparedness. The letter to California’s attorney general is a standard step under state notification laws when a breach involves residents’ personal information. The full scope of the data theft, including how many individuals were affected, has not been released.
More cybersecurity news from TechManNews.






