Apollo Global Management reports unauthorized access to cloud platforms

1 hour ago 14

Apollo Global Management confirmed on August 21, 2026, that attackers gained unauthorized access to its cloud platforms over a four-day window between July 6 and July 10. The breach exposed personal data including names, dates of birth, home addresses, contact information, and Social Security numbers.

Notably, no financial account details or proprietary business information were compromised.

What happened and how

The attackers did not need sophisticated malware or zero-day exploits. They used phishing, the digital equivalent of a convincing phone call from someone pretending to be your IT department.

According to the investigation, the campaign relied on social engineering tactics: impersonating websites designed to mimic legitimate Apollo infrastructure, combined with phone-based deception to extract employee credentials. Once inside, the attackers had roughly four days before being detected.

Apollo has retained external cybersecurity experts to assist with the investigation and has begun notifying both affected individuals and the relevant regulators. As a remediation measure, the firm is offering 24 months of complimentary credit monitoring and identity protection services to those affected.

Preliminary findings suggest the stolen data has not been publicly released or used for fraud, though investigators caution that absence of evidence is not evidence of absence, particularly in the early stages of a breach investigation.

The six-week gap between the intrusion window and public disclosure, July 10 to August 21, is itself worth noting.

A coordinated campaign across private equity

Apollo was not the only target. The same campaign hit several other major financial institutions, including Blackstone, KKR, and Bain Capital.

Apollo is publicly traded on the NYSE under the ticker APO and is one of the largest alternative asset managers in the world. Yet basic phishing techniques proved effective enough to breach their cloud environment.

What this means for the industry

Apollo’s response, bringing in outside experts, notifying regulators promptly, and offering two years of credit monitoring, reflects the current standard playbook for breach management.

Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

Read Entire Article