Apollo Data Breach Exposes Social Security Numbers in Private Equity Hacking Wave
Apollo confirms hackers stole names, addresses, birth dates and Social Security numbers in a cloud breach amid attacks on global private equity firms.
Summary
On August 21, 2026, Apollo Global Management confirmed in a California attorney general filing that social engineering gave hackers access to its cloud environment from July 6 to July 10. Human resources chief Matthew Breitfelder said they stole names, birth dates, home addresses, other contact details, and Social Security numbers. The notice does not identify whether victims were Apollo employees or people at portfolio companies. Apollo, among the largest private equity firms, manages $938 billion and had about 5,000 employees in February 2026.
Google researchers had warned weeks earlier of a widespread extortion campaign targeting financial and private equity companies. Reuters identified Apollo, Blackstone, Bridgewater, and Bain Capital among the targets, although successful breaches were then unconfirmed. Google says groups using the names Falcon, Helix, Pink, and Redact impersonate IT support by phone, directing employees to spoofed portals that capture passwords and multifactor authentication codes. They steal corporate data, demand payment, and threaten publication on a leak site, with some ransoms reaching $750,000. Apollo spokesperson Giovanna Falbo did not immediately answer TechCrunch’s questions, including whether Apollo paid. TechCrunch was a Yahoo subsidiary until 2025, and Apollo owns the advertising technology company.
Positives
- Matthew Breitfelder’s filing specified the July 6 to July 10 intrusion window and every disclosed category of stolen personal information.
- Google researchers warned financial and private equity companies about the extortion campaign weeks before Apollo publicly confirmed its breach.
- California’s attorney general received Apollo’s breach notice, creating a public regulatory record of the cloud intrusion.
Risks & concerns
- Names, birth dates, home addresses, contact information, and Social Security numbers were stolen from Apollo’s cloud environment.
- Apollo’s filing does not identify whether the victims were employees or individuals associated with its portfolio companies.
- Falcon, Helix, Pink, and Redact allegedly capture passwords and multifactor authentication codes through calls impersonating IT support.
- Google says the campaign threatens to publish stolen information and has secured ransoms as high as $750,000.
- Giovanna Falbo did not immediately say whether Apollo paid the hackers or answer TechCrunch’s other questions.