Apollo Global Management became the first major financial firm to confirm a data breach from a wave of social engineering attacks that has targeted private equity, law firms and rating agencies since July.
Apollo Global Management became the first major financial firm to confirm a data breach from a wave of social engineering attacks that has targeted private equity, law firms and rating agencies since July.

Apollo Global Management confirmed Friday that attackers breached its cloud platforms in early July, exposing Social Security numbers and other personal data at the $1.05 trillion asset manager.
"Similar to other financial services firms, Apollo recently experienced a social engineering incident," Matthew Breitfelder, global head of human capital at Apollo, said in a breach notification filed with California authorities. "Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols and launched an investigation."
The unauthorized access occurred between July 6 and July 10, with the company determining Aug. 12 that names, dates of birth, contact information, home addresses and Social Security numbers were compromised. Apollo said it has found no evidence the data was posted online or used for identity theft or fraud, and the investigation remains ongoing.
Apollo is the first victim to formally disclose that sensitive personal data was compromised in a campaign Google researchers attributed to BlackFile, a threat group affiliated with the cybercrime network The Com. The group has split its extortion operations across four brands — Redact, Pink, Helix and Falcon — with ransom demands that often start around $3 million and are negotiated down to less than $1 million.
The breach follows warnings from Google Threat Intelligence Group and Mandiant that data-theft extortion groups have been impersonating IT help-desk personnel in voice-phishing campaigns targeting professional, legal and financial services organizations. Reuters reported earlier this month that hackers created malicious websites designed to steal employee credentials from major financial and private equity firms, including Apollo, Blackstone, Bridgewater Associates, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's.
The FBI said in May it has seen a group called Silent Ransom Group conduct data-theft and extortion operations since at least 2022, posing as IT department employees since spring 2026. The operations have consistently targeted U.S.-based law firms as well as companies in the insurance, finance and healthcare industries.
Private equity firms hold outsized amounts of confidential corporate and financial information — merger terms, debt financing structures, portfolio-company operations and litigation strategy. Google researchers suggested the attackers' focus on firms involved in mergers, acquisitions and capital deployment reflects an attempt to obtain information with significant leverage for extortion.
A successful intrusion can expose more than employee records. It can reveal confidential business documents, transaction information and other commercially sensitive material that attackers can threaten to publish unless a ransom is paid. Google reported that some ransom demands associated with the campaign ranged from roughly $750,000 to $3 million, and one cryptocurrency wallet linked to a group received about $10 million in bitcoin during the first months of 2026.
The Apollo incident shows how sophisticated cybersecurity infrastructure can be undermined when attackers manipulate employees rather than exploit software vulnerabilities. Attackers impersonate IT support staff by phone, direct victims to fraudulent login pages designed to capture passwords and multi-factor authentication codes, then use those credentials to access corporate cloud environments.
For financial firms managing trillions in assets, employee authentication and identity security have become critical components of overall cybersecurity. Apollo's own regulatory disclosures acknowledge that cyberattacks can affect its systems and business operations despite security measures designed to prevent unauthorized access.
The incident could draw additional scrutiny from regulators, investors and business partners, particularly if the investigation reveals that sensitive corporate information beyond personal data was compromised. Apollo will need to notify affected individuals where required and potentially provide credit-monitoring or identity-protection services.
For the broader financial industry, the episode is a reminder that cybersecurity risks extend beyond technical vulnerabilities. Employees, authentication systems, cloud platforms and third-party services can all become entry points, and protecting identities has become as important as defending networks.
This article is for informational purposes only and does not constitute investment advice.