August 21, 2026: Private equity giant Apollo Global Management confirmed a July cloud breach in a California Attorney General filing and customer/employee notice summarized by TechCrunch and Reuters. Hackers used social engineering to reach certain cloud platforms between July 6 and July 10, taking names, dates of birth, contact details, home addresses, and Social Security numbers. No public headcount yet. Canonical row: apollo-global-cloud2026.
Wall Street spent early August watching a Google Threat Intelligence warning about help-desk phone scams aimed at private equity and other financial firms. Apollo’s name was already on the target list. On August 21 the firm stopped being a maybe and became a confirmed hit — with SSNs in the notice, not just emails.
What this is not, yet, is a published census. Apollo has not said how many people were in the cloud export, or whether they were employees, LPs, portfolio contacts, or a mix. Treat every “I was affected” rumor on social media as unverified until you have Apollo’s letter in hand.
What happened in the Apollo data breach
According to the California AG sample notice described by TechCrunch, Apollo HR chief Matthew Breitfelder said attackers used a social-engineering attack to gain access to Apollo’s cloud environment between July 6 and July 10, 2026. The firm later determined that personal information potentially impacted included names, dates of birth, contact information, home addresses, and Social Security numbers.
Reuters’ August 21 account matches the same window: unauthorized access to certain cloud platforms, law enforcement notified, outside forensics engaged. Apollo spokesperson Giovanna Falbo did not immediately answer TechCrunch’s questions about ransom payment.
Apollo manages roughly $938 billion in assets and employs on the order of 5,000 people per February 2026 regulatory context cited by TechCrunch. Those figures explain the stakes; they are not the breach headcount.
How the attack likely worked
Google’s August research on the wider campaign — actors tracked under names including Falcon, Helix, Pink, and Redact — describes phone calls that impersonate IT help desks, push victims toward spoofed login pages, and harvest passwords plus MFA codes. Once inside, the same crews steal cloud data and extort. Google said some ransoms reached about $750,000.
Apollo’s CA letter frames its own intrusion as social engineering into the cloud environment. That aligns with the campaign Google and Reuters mapped across names that included Apollo, Blackstone, Bridgewater, Bain Capital, KKR, TPG, CME Group, Clearlake, and Moody’s — with Apollo now the clearest public confirmation that at least one listed firm was successfully breached.
To be clear: sharing a target list is not the same as proving every firm on it lost data. Only Apollo’s notice, among that Reuters set, is indexed here as a confirmed personal-data theft at time of writing.
What data was exposed
- Names
- Dates of birth
- Contact information
- Home addresses
- Social Security numbers
The notice does not spell out whether the population is primarily employees, former employees, limited partners, or people tied to portfolio companies. That ambiguity matters for phishing: a convincing “Apollo benefits / LP portal / portfolio HR” lure can be tailored once an attacker knows which list they hold.
What Apollo has not publicly said: card numbers, trading systems compromise, or a definitive individual count. BreachHistory sets recordsAffected to 0 pending a regulator or company census.
Who is at risk
People who receive an Apollo notice — freeze credit, watch tax filings, and treat any SSN-citing call as hostile until verified. ~5,000 employees are an obvious candidate population, but do not assume you were spared if you only “work at a portfolio company.” LPs and deal counterparties whose PII sat in HR or CRM cloud apps could be in scope. Anyone who shares a surname and DOB with an Apollo contact should still ignore cold calls that claim to be “Apollo IT resetting MFA after the breach.”
How this fits the August 2026 Wall Street wave
Reuters reported in early August that ransom-seeking hackers were targeting dozens of prominent U.S. financial institutions with phone-based social engineering. Google’s UNC6671-style write-up framed the same pattern against financial services and enterprise cloud environments. Apollo’s confirmation is the first major PE disclosure in that cluster with a dated cloud-access window and an SSN category list.
Readers tracking other 2026 finance and PE-adjacent incidents on BreachHistory — for example smaller confirmed file thefts like Five States Energy — will recognize the same lesson at a larger brand: the help-desk call is the vulnerability, not a exotic zero-day.
Separately, TechCrunch notes it was an Apollo-owned Yahoo subsidiary until 2025. That ownership trivia does not expand the breach scope; it only explains why TC covered the filing so closely.
What Apollo and regulators have said
Primary sources: California AG breach report sb24-628551, TechCrunch’s August 21 summary of the HR letter, and Reuters’ same-day brief. Apollo notified law enforcement and hired outside cybersecurity help. No public CNIL-style European filing was required for this U.S. firm’s California notice; watch other state AGs for additional snapshots.
As of indexing, Apollo had not published a detailed consumer FAQ with a headcount or a definitive statement on ransom.
Action items if you may be in Apollo’s notice list
- If you get a letter, read the exact data categories and the enrollment window for any credit monitoring Apollo offers — then decide whether to use it.
- Place a credit freeze with Equifax, Experian, and TransUnion. SSNs in a PE firm breach are tax- and credit-fraud fuel.
- Get an IRS IP PIN if you are a U.S. taxpayer and your SSN may be in scope.
- Ignore inbound calls or texts claiming to be Apollo IT, HR, or “Helix ransom recovery.” Hang up. Use a known Apollo number or your internal directory.
- Employees: re-verify MFA on cloud apps through official SSO only. Do not approve push prompts you did not initiate.
- Portfolio-company staff: ask your own IT whether Apollo or a shared vendor held your PII; do not assume “I’m not on Apollo’s payroll” equals safe.
- Watch for W-2 phishing in the next tax season that cites Apollo or a portfolio brand by name.
- Keep the TechCrunch and CA AG links; do not download alleged Apollo dumps from forums “to check yourself.”
Phishing patterns to expect after an Apollo headline
Private equity breach news produces a specific scam dialect. Attackers call saying they are from “Apollo Service Desk” and need you to “re-enroll MFA after the July cloud incident.” They already know your name and maybe your DOB from the dump — or from LinkedIn. The ask is always the same: open a portal, type the password, approve the MFA prompt.
Email variants cite “credit monitoring enrollment” with a lookalike domain. Real monitoring enrollments come from the vendor named in the paper notice, not from a PDF attached to a Gmail thread. If someone demands a wire to “pay the Falcon/Helix ransom on Apollo’s behalf,” that is a secondary fraud — hang up.
For security teams at PE and hedge funds
If Google or Reuters put your firm on the August target list, treat Apollo’s confirmation as a tabletop, not a spectator sport. Kill voice-based password resets that can bypass phishing-resistant MFA. Require hardware keys or number-matching MFA for cloud admins. Log and alert on impossible-travel IdP events after after-hours “IT” calls. Brief reception and help-desk staff that callers will cite the Apollo story by name.
Also inventory which cloud SaaS apps hold SSNs. HRIS and benefits platforms are the obvious ones; deal rooms and LP portals sometimes are not. Apollo’s letter said “certain cloud platforms” — plural. Assume attackers pivot once they have one foothold.
What we still do not know
Headcount. Exact platforms. Whether a ransom was paid. Whether data was posted to a leak site under Helix/Falcon/Pink/Redact branding. Whether portfolio companies must send their own notices. BreachHistory will revise apollo-global-cloud2026 when a census, leak-site listing, or additional AG filings land.
Until then, the honest summary for searchers of “Apollo data breach 2026” or “Apollo Global Management Social Security numbers” is simple: the firm confirmed a July 6–10 cloud intrusion via social engineering; SSNs and home addresses are in the official category list; the number of people is not public yet; and the wider Wall Street phone-scam campaign is the right context, not a random one-off malware story.
Employees who never open Apollo’s consumer-facing site should still read the internal notice carefully. Cloud HR systems often hold contractor and former-employee rows for years. If you left Apollo in 2024 and get a 2026 letter, that is expected — not proof the letter is fake.
Limited partners should ask their relationship managers which Apollo entities and vendors process LP contact data, and whether those systems were in the forensic scope. Do not accept a vague “we take security seriously” email as a substitute for a yes/no on SSN fields.
Journalists and researchers should avoid republishing sample rows from alleged Apollo dumps. Amplifying identifiable SSNs helps extortion more than the public. Cite the CA AG filing and reputable trade press instead.
If you are a class-action firm already advertising Apollo lawsuits, remember that a filed notice is not the same as a certified class or a known headcount. Readers should treat early lawsuit pages as marketing until dockets and Apollo’s census catch up.
Bottom line: Apollo is a confirmed Wall Street breach with SSNs on the table, inside a documented social-engineering wave. Harden against help-desk calls now. Update the catalog when the count arrives.
Compare this to extortion listings where the company only says it is “investigating,” such as some Helix-branded corporate claims elsewhere in the catalog. Apollo’s California letter crosses a brighter line: unauthorized cloud access dated, data categories named, law enforcement engaged. That is why this Apollo Global Management data breach page leads with confirmation rather than an unverified claim label.
For households: freeze credit even if you only think you might be in scope and are waiting on mail. Freezes are free and reversible. Waiting for a perfect census while an SSN is already circulating is how tax-refund fraud wins.
Finally, do not confuse Apollo Global Management with Apollo.io (the sales-intel company) or ApolloMD (the healthcare staffing firm). Those are separate entities with their own BreachHistory rows. This incident is the New York private-equity firm behind the California AG filing sb24-628551.
Why SSNs at a PE firm hit differently than a retailer breach
Retail dumps often skew toward emails, loyalty IDs, and partial cards. A private equity cloud export that includes Social Security numbers and home addresses is closer to an HRIS or benefits breach — even if the public letter never says the word “employee.” Tax fraud, synthetic identity, and targeted burglary risk rise together. That is why credit freezes and IRS IP PINs belong in the first response, not as year-two afterthoughts.
Home addresses paired with a PE brand also change physical-security advice for executives and deal staff who already face activism or kidnapping risk in some markets. You do not need a leak-site screenshot to justify reviewing travel patterns and package-delivery habits after an SSN-plus-address notice.
How to read Apollo’s silence on headcount
Companies often know a lower bound weeks before they publish a number. State AG filings can lag a full multi-state census. Apollo’s August 21 wave of coverage means more state notices may appear with small resident counts that do not add up to the true total. Summing early AG snapshots is a common mistake — treat them as floors, not the census.
If Apollo later posts a five-digit employee-only figure, portfolio contacts may still need separate letters from portfolio companies. If the figure is larger, expect LP and contractor rows. Until then, BreachHistory keeps recordsAffected at zero rather than inventing a number from Apollo’s ~5,000 headcount.
Campaign naming: Helix, Falcon, Pink, Redact
Google’s public branding for the financial-services social-engineering crews is messy on purpose — the same operators rebrand leak sites. Helix already appears elsewhere in BreachHistory on corporate extortion listings that are not the same as Apollo’s California letter. Do not merge every Helix headline into this PE cloud incident. Use Apollo’s dated July 6–10 window and the CA AG PDF as the canonical facts; treat actor brand names as campaign context only.
If a Helix (or Falcon/Pink/Redact) leak site later posts Apollo file trees, we will update the catalog row and this blog. Until a listing or company confirmation of publication exists, assume extortion contact may have been private.
Recruiters and contractors who once submitted SSNs through Apollo-affiliated ATS tools should ask whether those vendors were in scope. Third-party HR SaaS is often where “cloud platforms” plural becomes literal. A single SSO foothold can reach more than one SaaS tenant.
Compliance teams preparing board decks should separate three questions: (1) Was Apollo breached? Yes, per the CA notice. (2) Was every firm on the Reuters target list breached? Unknown. (3) Did Apollo pay? Unanswered. Boards that collapse those into one slide will make worse decisions about MFA hardware rollouts and voice-reset bans.
For readers arriving from “was I affected by the Apollo hack”: only Apollo’s notice — or a portfolio company’s own letter naming this incident — answers that. LinkedIn posts and Telegram “check your SSN” bots are not authoritative. If mail has not arrived and you have no relationship to Apollo or its portfolio, you are probably outside this event; still keep the help-desk call defenses, because the same crews are still dialing other firms.