TechNewsReel
Live

Apollo Global Management Confirms Data Breach via Social Engineering

The asset manager disclosed that Social Security numbers and contact details were stolen from its cloud systems.

TechNewsReel Newsroom · August 24, 2026

Apollo Global Management has confirmed a data breach involving the theft of personal information from its cloud systems. The firm disclosed the incident in a regulatory filing with the California Attorney General.

According to the filing, the breach occurred over a five-day window between July 6 and July 10. The attackers utilized social engineering tactics to gain unauthorized access to Apollo's cloud environment. Once inside, the actors exfiltrated sensitive personal data, including names, birth dates, home addresses, and Social Security numbers.

The Vulnerability of Cloud Infrastructure

Apollo Global Management operates as one of the world's largest alternative asset managers, overseeing vast portfolios for institutional investors and high-net-worth individuals. The use of social engineering—where attackers manipulate individuals into divulging credentials or granting access—highlights a persistent weakness in corporate security: the human element. Despite sophisticated cloud security protocols, a single compromised credential can provide a gateway to sensitive data repositories.

Industry Implications

A breach at a firm of Apollo's scale carries significant security risks for its clientele. The theft of Social Security numbers and home addresses provides bad actors with the necessary components for identity theft and targeted phishing campaigns. In the financial sector, where discretion and security are paramount, such incidents can erode trust among institutional partners and high-profile investors who expect rigorous data stewardship.

Unresolved Details

While the nature of the stolen data is confirmed, several key details remain unknown. Apollo has not yet disclosed the total number of affected individuals, nor has it specified whether the compromised data belonged to internal employees or individuals associated with its various portfolio companies. Additionally, it remains unconfirmed whether the attackers demanded or received a ransom in exchange for the data or for the promise of its deletion.

Get a notification when a big story breaks. A few a day at most — no spam.