Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants | TechCrunch

August 21, 2026 9 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: techcrunch.com

Threat Risk: High
Victim: Apollo Global Management
Incident: Data breach resulting from social engineering and MFA bypass.
Impact: Theft of sensitive PII, including names and Social Security numbers.
Attacker: Falcon, Helix, Pink, and Redact
Analysis: Attackers leveraged vishing and spoofed login portals to bypass MFA and gain access to Apollo’s cloud systems. This incident is part of a broader extortion campaign targeting the private equity sector using highly targeted social engineering. The theft of Social Security numbers and PII poses a significant identity theft risk to the affected individuals.
Recommendations: Implement FIDO2-compliant hardware security keys to prevent MFA bypass via spoofed portals; Conduct targeted social engineering and vishing simulations for employees in high-value roles; Enhance monitoring for unauthorized access patterns within cloud management environments
Source: TechCrunch

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Latest Developments

Update — 2026-08-21 14:53 UTC

Unauthorized access to cloud platforms resulting in a PII data breach. Theft of sensitive personal information including names, birth dates, and Social Security numbers. Attackers utilized a multi-stage approach, combining voice-based social engineering with fraudulent websites to steal employee credentials. This allowed unauthorized access to cloud platforms, resulting in the theft of highly sensitive PII, including Social Security numbers. The trend highlights a persistent vulnerability in the financial sector where human elements remain the weakest link despite advanced AI-driven security.

Corroborating source: lufkindailynews.com

Update — 2026-08-21 22:14 UTC

Social engineering attack leading to unauthorized cloud platform access. Exposure of names, dates of birth, addresses, and Social Security numbers. The attacker utilized social engineering, likely via voice phishing, to gain unauthorized access to corporate cloud platforms. This incident mirrors a broader trend of data theft extortion targeting financial and professional services firms by impersonating IT support. The successful exfiltration of Social Security numbers underscores the critical risk posed by human-centric attack vectors.

Corroborating source: pymnts.com

Update — 2026-08-22 13:03 UTC

Unauthorized access to cloud platforms resulting in a data breach. Theft of sensitive client PII including Social Security numbers, birth dates, and contact details. Threat actors compromised Apollo’s cloud infrastructure over a five-day window, exfiltrating highly sensitive data including Social Security numbers. This incident is noted as part of a broader trend of cyber extortion targeting the financial sector. The breach highlights the critical risk of cloud configuration gaps or credential theft in high-value financial environments.

Corroborating source: finance.yahoo.com

Update — 2026-08-22 15:18 UTC

Unauthorized access to cloud platforms resulting in a data breach. Exposure of sensitive PII, including Social Security numbers, dates of birth, and home addresses. The attack leveraged social engineering to gain unauthorized access to cloud platforms, bypassing traditional malware detections. This incident is part of a broader campaign using AI-generated voice phishing (vishing) to deceive employees at high-value financial institutions. It highlights a critical shift toward targeting the human element through sophisticated impersonation.

Corroborating source: inc.com

Update — 2026-08-22 16:09 UTC

Unauthorized access to cloud infrastructure via a social engineering campaign. Exposure of sensitive PII, including names, birth dates, and Social Security numbers. Attackers used social engineering to impersonate IT support, tricking employees into providing credentials and 2FA codes through counterfeit portals. This incident reflects a broader campaign targeting high-value investment firms, bypassing technical controls by targeting the human element. The breach highlights the vulnerability of traditional MFA to real-time phishing attacks.

Corroborating source: briefs.co

Update — 2026-08-22 16:09 UTC

Data breach of cloud systems via social engineering. Theft of sensitive personal information including Social Security numbers. The breach occurred via a sophisticated social engineering attack where threat actors impersonated IT support to harvest cloud credentials. This incident aligns with a broader trend of extortion campaigns specifically targeting high-net-worth financial institutions. The theft of Social Security numbers significantly increases the risk of identity theft for the affected parties.

Corroborating source: adgully.com

Update — 2026-08-22 16:09 UTC

Data breach resulting from targeted attacks on financial firms. Potential unauthorized access to sensitive corporate and client financial data. Apollo Global Management experienced a data breach as part of a broader campaign targeting the financial services sector. This incident underscores the persistent risk high-value financial assets and sensitive client data pose to sophisticated attackers.

Corroborating source: today.westlaw.com

Update — 2026-08-22 16:09 UTC

Unauthorized cloud platform access via social engineering. Theft of personal information including Social Security numbers, dates of birth, and home addresses. Attackers leveraged phone-based social engineering to gain unauthorized access to cloud platforms, bypassing sophisticated security measures. This incident is part of a broader campaign targeting U.S. financial institutions using similar human-centric vectors. The resulting breach exposed highly sensitive PII, including Social Security numbers.

Corroborating source: brandequity.economictimes.indiatimes.com

Update — 2026-08-22 17:11 UTC

Unauthorized cloud platform access via social engineering. Potential exposure of sensitive PII, including Social Security numbers and addresses. Attackers utilized social engineering to gain unauthorized access to the firm’s cloud environment between July 6 and July 10. The breach potentially exposed high-value PII, including Social Security numbers and birth dates, which significantly elevates the risk of identity theft and targeted phishing. This incident underscores how identity-based attacks can bypass technical controls even in well-configured cloud environments.

Corroborating source: cyberpress.org

Update — 2026-08-22 19:13 UTC

Unauthorized access to cloud platforms via social engineering. Exfiltration of sensitive personal data, including Social Security numbers and contact information. Attackers impersonated IT staff to manipulate employees into granting unauthorized access to cloud environments. This incident is part of a broader campaign by UNC6671 targeting high-value financial and professional services firms. The breach highlights a critical gap where technical controls are bypassed through psychological manipulation.

Corroborating source: startupfortune.com

Update — 2026-08-22 19:13 UTC

Unauthorized access to personal client and counterparty data via a social engineering attack. Exposure of sensitive personal information and temporary devaluation of corporate stock. Threat actors leveraged social engineering to infiltrate Apollo Global Management’s systems, gaining unauthorized access to sensitive personal data of clients and counterparties. The incident aligns with a broader trend of targeted attacks against alternative asset managers and hedge funds. This event highlights how cybersecurity failures in the financial sector now translate directly into market volatility and investor scrutiny.

Corroborating source: ad-hoc-news.de

Update — 2026-08-22 20:15 UTC

Unauthorized access to cloud platforms via social engineering. Exposure of highly sensitive PII, including Social Security numbers and contact details. Threat actors leveraged social engineering to bypass security controls and gain unauthorized access to Apollo’s cloud platforms. The breach resulted in the theft of high-value PII, including Social Security numbers, which significantly increases the risk of identity theft and targeted phishing. This incident underscores the volatility of cloud identity management when faced with human-centric attack vectors.

Corroborating source: gbhackers.com

Update — 2026-08-23 22:08 UTC

A data breach involving sensitive personal information via unauthorized cloud environment access. Exposure of names, dates of birth, and Social Security numbers. Attackers leveraged sophisticated vishing and social engineering, impersonating IT support to steal credentials and bypass MFA. This incident highlights a systemic vulnerability in identity verification processes rather than a technical software flaw. The breach was part of a broader campaign targeting over 200 financial institutions using tailored phishing sites.

Corroborating source: securityboulevard.com

Update — 2026-08-24 02:01 UTC

Unauthorized access to cloud platforms via a social engineering attack. Potential exposure of sensitive PII, including Social Security numbers, increasing the risk of identity theft. The breach occurred via a social engineering attack targeting cloud platforms, allowing an unidentified actor unauthorized access for several days in July 2026. Compromised data includes highly sensitive PII such as Social Security numbers and dates of birth. This incident underscores the persistent risk of identity-based attacks against high-value financial institutions.

Corroborating source: globenewswire.com

Update — 2026-08-24 02:11 UTC

Unauthorized access to cloud platforms via social engineering. Exposure of sensitive personal information, including names and Social Security numbers. An unidentified attacker used social engineering to gain unauthorized access to Apollo Global Management’s cloud infrastructure between July 2 and July 8. The breach exposed sensitive PII, including Social Security numbers and dates of birth, emphasizing the vulnerability of cloud environments to identity-based attacks. While no evidence of fraud has surfaced yet, the nature of the stolen data poses a long-term identity theft risk.

Corroborating source: lincolnjournal.com

Update — 2026-08-24 13:21 UTC

Data breach via cloud platform access following a social engineering attack. Exposure of sensitive personal information, including names and Social Security numbers. The attack utilized IT helpdesk-themed vishing to gain unauthorized access to cloud environments. This campaign, attributed to BlackFile/UNC6671, specifically targets high-value financial and professional services sectors across North America, Australia, and the UK. The ability to compromise a firm managing over $1 trillion in assets underscores the potency of these social engineering tactics.

Corroborating source: securityweek.com

Update — 2026-08-24 17:30 UTC

Unauthorized access to cloud platforms via social engineering and MFA bypass. Exfiltration of sensitive personal information including names, dates of birth, and Social Security Numbers. Attackers leveraged social engineering by posing as IT support to trick employees into revealing credentials and MFA codes. This allowed unauthorized access to cloud platforms and the exfiltration of highly sensitive data, including Social Security Numbers. The incident underscores a rising trend of high-precision impersonation attacks targeting the financial services sector.

Corroborating source: cybermagazine.com

Update — 2026-08-24 18:32 UTC

Unauthorized access to cloud platforms via social engineering and credential theft. Exposure of sensitive PII including Social Security numbers and dates of birth. The attack utilized impersonation of IT support to harvest credentials via phishing, granting unauthorized access to cloud platforms. This is part of a wider trend targeting financial institutions to steal highly sensitive PII. The lack of transparency regarding the volume of affected individuals suggests a significant exposure.

Corroborating source: techrepublic.com

Update — 2026-08-25 02:15 UTC

Data breach via social engineering Unauthorized access to the internal systems of a major global investment firm Attackers leveraged psychological manipulation to circumvent security perimeters and gain unauthorized access to Apollo’s internal environment. This incident demonstrates that technical controls alone cannot stop determined actors targeting high-value financial assets. The breach underscores the critical vulnerability of identity-based access in the financial sector.

Corroborating source: theregister.com

Update — 2026-08-25 22:06 UTC

Unauthorized access to cloud platforms resulting in a PII data breach. Exposure of Social Security numbers, birth dates, and residential addresses. Threat actors are bypassing technical security layers by using phone-based social engineering to harvest cloud credentials. This breach highlights a critical trend where human-centric attacks remain highly effective for accessing corporate cloud environments despite heavy investment in software. The incident is part of a broader, coordinated campaign targeting the financial sector and other global enterprises.

Corroborating source: beinsure.com

Leave a Reply

Your email address will not be published. Required fields are marked *