Apollo Global Management discloses unauthorized cloud access, data breach

Abstract representation of phishing with the text on a textured dark surface.

In brief

  • Apollo Global Management confirmed unauthorized cloud access July 6-10, 2026, exposing employee and client personal data
  • Phishing and social engineering extracted employee credentials; no financial account details were compromised
  • Company offering 24 months complimentary credit monitoring and identity protection to affected individuals
  • Same phishing campaign targeted Blackstone, KKR, and Bain Capital in coordinated financial sector attack

The Attack Vector

Attackers used phishing and social engineering tactics, including impersonating websites and phone-based deception to extract employee credentials. The method was simple but effective—a convincing impersonation of an IT department requesting login information. No financial account details or proprietary business information were compromised in the breach, according to the firm's disclosure.

The intrusion window lasted only four days. Yet the gap between the July 10 discovery and the August 21 public announcement—six weeks—raised questions about internal communication protocols and regulatory notification timelines.

Scope and Response

Apollo has retained external cybersecurity experts to assist with the investigation and has begun notifying affected individuals and regulators. Preliminary findings suggest the stolen data has not been publicly released or used for fraud, though investigators cautioned that absence of evidence is not evidence of absence in the early stages of a breach investigation.

The firm is offering 24 months of complimentary credit monitoring and identity protection services to affected individuals. This remediation measure is standard practice for breaches involving Social Security numbers and personal identifiers.

Broader Pattern

Apollo was not the only target. The same phishing campaign hit several other major financial institutions, including Blackstone, KKR, and Bain Capital. The coordinated nature of the attacks suggested a sophisticated threat actor targeting the alternative asset management sector specifically.

"They used phishing, the digital equivalent of a convincing phone call from someone pretending to be your IT department." — Source document on Apollo breach investigation