Apollo Global Management Data Breach from Social Engineering Attack

Apollo Global Management Data Breach from Social Engineering Attack

First seen 21 Aug 2026, 14:17 UTC ClassactionTechcrunchFtCyberscoopOodaloop+19 71.0

Article Content

Browse articles
ThreatCluster

Apollo Global Management confirmed a data breach resulting from a social engineering attack that occurred between July 6 and July 10, 2026. Hackers gained unauthorized access to the firm's cloud systems, compromising sensitive personal data including names, dates of birth, addresses, and Social Security numbers. The firm is the first to disclose that data was stolen amid a broader wave of attacks targeting financial institutions. Apollo has not revealed the number of individuals affected or whether the data belonged to employees or clients. The company has engaged law enforcement and cybersecurity experts to investigate the breach, and it is offering affected individuals credit monitoring services. No evidence has been found indicating that the stolen data has been used for fraud or posted online. The attack is linked to a campaign attributed to the BlackFile threat group, which employs vishing tactics to manipulate employees into revealing sensitive information.

Key Points: • Apollo Global Management confirmed a data breach affecting personal data due to social engineering. • The breach occurred between July 6 and July 10, 2026, with sensitive data including Social Security numbers compromised. • The attack is part of a broader campaign targeting financial institutions, attributed to the BlackFile threat group.

Timeline

2026-07-06
Unauthorized access to Apollo's cloud systems
Hackers gained access to Apollo's cloud platforms, leading to a data breach affecting personal information.
Insurancebusinessmag
2026-08-12
Apollo identifies stolen data categories
Apollo confirmed that names, dates of birth, addresses, and Social Security numbers were compromised in the breach.
Cyberscoop
2026-08-21
Apollo publicly discloses data breach
Apollo confirmed the breach and the nature of the attack in a notice filed with the California attorney general.
Pymnts