Skip to content

Apollo Global Management data breach exposes personal information

Apollo Global Management data breach exposes personal information

Apollo Global Management suffered a data breach in July after attackers gained unauthorized access to cloud platforms and obtained personal information, according to a company notification issued Friday.

The New York-based asset manager was among dozens of major US financial institutions and other businesses recently targeted by ransomware-linked hackers.

The attackers have relied heavily on phone-based social engineering to compromise employees and gain access to corporate systems.

Apollo’s investigation identified unauthorized activity across certain cloud platforms between July 6 and July 10.

The company contacted law enforcement after detecting the incident. It also hired external cybersecurity and forensic specialists to investigate the intrusion, determine what information attackers accessed and assess the scope of the breach.

Earlier in August, Apollo learned that the affected information included names and dates of birth. Other exposed records included contact details, residential addresses and Social Security numbers, according to the company.

Internet intelligence data reviewed by Reuters showed hackers had created websites designed to steal login credentials from employees at private equity firms and other financial companies.

The campaign illustrates a persistent problem for financial-sector security teams. Attackers don’t always need sophisticated malware when employees remain reachable by phone and credential-stealing pages.

Phone-based social engineering remains one of the more effective methods for accessing corporate networks, even as financial institutions spend heavily on security software and respond to newer AI-assisted cyber threats.

Attackers often impersonate technical support staff or other trusted contacts. Once they obtain employee credentials, access to cloud applications creates another route into sensitive corporate information.

Apollo said its investigation remains underway. The asset manager hasn’t identified evidence showing the stolen information has appeared publicly. It also hasn’t found indications that attackers have used the compromised data for identity theft or fraud as of its latest notification.

Apollo is providing affected individuals whose information was stolen with complimentary third-party identity protection and credit monitoring services.

Matthew Breitfelder, Apollo’s global head of human capital, disclosed the assistance in the company’s notification letter. The attack sits within a larger campaign targeting major companies.

Cybercriminals recently created credential-stealing infrastructure aimed at employees across hundreds of businesses, according to internet intelligence reviewed by Reuters. Companies targeted in related activity included ride-hailing group Uber and clothing company Levi Strauss.

Uber Freight and Levi Strauss separately disclosed cybersecurity incidents earlier in August. Both companies said unauthorized parties had gained access to their systems and investigations were underway.

The incidents add to concern over social-engineering attacks against financial companies and large corporations, where access to one employee account gives criminals an entry point into cloud systems containing personal or business information.

For asset managers such as Apollo, compromised personal data creates exposure beyond the initial intrusion. Social Security numbers, home addresses and birth dates provide information criminals use in identity fraud and additional phishing attempts.

Apollo’s continuing forensic investigation will determine the broader extent of the July breach and whether attackers accessed further information beyond the personal records already identified.