- Security Incident: Apollo Global Management confirmed a data breach involving unauthorized access to cloud platforms that took place in July 2026.
- Methodology: The breach was executed via vishing social engineering tactics attributed to the threat group BlackFile, exposing personal identifiable information.
Breach Confirmation and Financial Impact
Apollo Global Management has officially confirmed a security incident involving unauthorized access to its internal cloud platforms. The breach occurred between July 6 and July 10, 2026, affecting the digital infrastructure of the firm. As a major player in the financial sector, the Apollo Data Breach involves a firm that manages approximately $938 billion in assets. The organization identified the specific window of intrusion and began assessing the scope of the data exposure shortly thereafter.
Social Engineering and Threat Attribution
The method used to gain access to the cloud environment was a form of social engineering known as vishing, or voice phishing. In this specific campaign, attackers contacted employees while posing as members of the internal IT help desk to acquire valid credentials. Google Cloud’s Mandiant unit and the Threat Intelligence Group have conducted research into these vishing campaigns, attributing the broader activity to a threat group identified as BlackFile or The Com. This threat actor is known to operate under multiple monikers, including Falcon, Helix, Pink, and Redact.
Exposed Information and Official Response
The private equity firm Apollo confirms data containing personal identifiable information (PII) was exposed during the July intrusion. The categories of compromised data include full names, dates of birth, home addresses, and contact details. Furthermore, the firm confirmed that Social Security numbers were included in the set of exposed records. Apollo reached a final determination regarding the specific categories of data impacted on August 12, 2026. Following this internal review, the company filed a formal notification with the California Department of Justice on August 21, 2026. The official disclosure of the incident was signed by Matthew Breitfelder, the Global Head of Human Capital at Apollo.
Industry Context and Mitigation Efforts
As of late August 2026, Apollo stated that there is no evidence suggesting the compromised data has been posted on public forums or used for identity theft or fraud. Despite this, the firm is providing complimentary identity protection and credit monitoring services to individuals whose personal information was involved in the breach. This incident is part of a larger trend where Apollo Global reveals data breach alongside reports of similar reconnaissance or attacks targeting other high-profile financial and professional service firms. Entities such as Blackstone, KKR, and Citadel have also been identified as targets in this recent wave of cyber activity focused on the financial services sector.
