Apollo reports cloud data theft tied to social engineering

Apollo Global Management has confirmed that attackers accessed its cloud environment between July 6 and July 10 and removed personal information. In a notification filed with the California attorney general, Apollo human resources chief Matthew Breitfelder said the intrusion resulted from a social engineering attack.
The stolen data included names, dates of birth, contact information, home addresses and Social Security numbers. The filing does not specify whether the affected individuals were Apollo employees, people connected with portfolio companies, or another group. Apollo also did not say in the filing whether it paid a ransom.
The incident affects one of the world’s largest private equity firms, with $938 billion in assets under management. Apollo had about 5,000 employees as of February 2026, based on its public regulatory filings.
A campaign aimed at financial firms
The confirmed breach followed a warning from Google security researchers about an extortion campaign focused on private equity companies and large financial organizations. Reuters had reported that Apollo was among the targets, alongside Blackstone, Bridgewater and Bain Capital, while the extent of successful compromises was then unclear.
The methods described in Google warning on vishing against financial firms rely on vishing-style social engineering: attackers call employees while posing as IT help desks or support staff. They seek to persuade targets to enter passwords and multi-factor authentication codes into spoofed sign-in portals, giving the attackers a route into corporate networks.
Data theft and extortion risk
Google has associated the activity with names including Falcon, Helix, Pink and Redact. After obtaining data, the groups attempt to extort victims for payment or threaten publication on a leak site. Google said some attacks in the wider campaign produced ransoms of up to $750,000.
Apollo spokesperson Giovanna Falbo did not immediately provide comment to TechCrunch or answer questions about the incident, including whether the company had made a ransom payment. That leaves key operational details, including the number of people affected and the attackers’ next steps, undisclosed.
Business implication
For financial firms and their portfolio companies, the case underscores that help-desk impersonation can bypass conventional password and MFA expectations. Businesses should ensure staff verify support requests through trusted channels, avoid entering credentials or MFA codes into unsolicited portals, and restrict cloud access to the minimum required for each role.

