Personal Information Exposed in Apollo Global Data Breach
Apollo Global Management, a massive private equity firm, says attackers tricked their way into some of its cloud systems and may have taken employee or client names, contact details, and Social Security numbers. Apollo has not seen the stolen data posted online or used for fraud so far.
- Report priority
- Medium
- Involves
- Apollo Global Management
What is known
Attackers used a phone-based social engineering trick, posing as IT help desk staff to talk an employee or contractor into handing over access, and used that access to get into Apollo's cloud platforms between July 6 and July 10, 2026.
What to do
Watch for an official breach notification letter from Apollo naming your specific records.
If you receive a notice from Apollo, enroll in the free identity protection and credit monitoring services it is offering, and watch your credit reports and accounts for unfamiliar activity. There is no software patch since this was a phone-based break-in, not a technical bug.
Reported details
A cybercrime group calling itself BlackFile calls into a company's IT help desk line, posing as an employee who is locked out of an account. The staffer resets credentials or approves a login, handing the caller a way into the company's cloud accounts. Once inside, the group can browse and copy files containing employee and client records before the company notices.
The intrusion at Apollo Global Management fits a broader vishing (voice phishing) campaign run by a group tracked as UNC6671, BlackFile, Cordial Spider, and CL-CRI-1116. The group impersonates IT help desk staff by phone to get employees to reset credentials or approve multi-factor prompts, then pivots into cloud platforms to exfiltrate data for extortion rather than deploying ransomware. Google's Threat Intelligence Group reported the group collected over 10 million dollars in Bitcoin ransom payments between January and May 2026. Other private equity and hedge fund firms have been named as targets of the same infrastructure, but Apollo is the only one with a confirmed data compromise as of this report.