Apollo Global Management disclosed that hackers entered the corporate cloud environment in early July through social engineering and stole a large amount of personal information. Shortly before the incident, security researchers warned that hackers were concentrating on extortion attacks against private equity companies and large financial institutions.

Disclosure file confirms invasion time

The announcement indicates that the attack took place between 6 July and 10 July. In a paper submitted to the Attorney General of California, the Apollo Human Resources Manager Matthew Breitfeld stated that the attackers had obtained access to the company cloud system through social engineering.

The stolen information includes the name, date of birth, contact information, home address and social security number. The document does not specify whether the affected persons are Apollo employees or related persons in the enterprises they invest or control.

After the attack on the financial institution

A few weeks before the invasion was confirmed, Google researchers had warned that a new hacker operation was carrying out widespread extortion against private institutions and financial giants. Reuters had previously reported that Apollo, Blackstone, Bridgewater and Benn Capital were on the list of targets, but it was not clear at that time that any company had been successfully broken down.

According to researchers, the attackers usually demand ransoms from businesses after stealing data, or threaten to publish the data to a leaked website. According to Google, ransoms in some cases amounted to $750,000.

Apollo didn't say if he paid the ransom.

TechCrunch stated that the Apollo spokesman had not responded immediately to further questions, including whether the company paid ransoms to hackers. The current disclosures also do not indicate the number of persons involved in the incident.

Apollo is one of the world ' s largest private institutions, managing assets of approximately $938 billion. According to the company ' s public regulatory documents, as of February 2026 the total number of employees was approximately 5,000.

Additional information:Public confirmation of the incident meant that previous targeted attacks around the financial and private sector had evolved from a “potential target” to actual data leakage by at least some companies.