Apollo Global Management confirms data breach exposing Social Security numbers and home addresses

Apollo Global Management, the private equity firm that manages nearly a trillion dollars in assets, has confirmed that hackers broke into its cloud systems and walked away with some of the most sensitive personal data imaginable. Names, birth dates, home addresses, and Social Security numbers. And that’s before we even get to the part where Apollo won’t say whose data was taken.

According to TechCrunch, Apollo confirmed the breach in a letter filed with California’s attorney general. The company’s HR chief, Matthew Breitfelder, said hackers used a social engineering attack to access Apollo’s cloud environment between July 6 and July 10. Social engineering, in plain terms, means they tricked people. No zero-day exploit. No sophisticated malware. Just phone calls and fake IT helpdesks.

This matters because it exposes a painful truth about corporate security: the weakest link is almost always human. The hackers behind this campaign, tracked by Google under names including Falcon, Helix, Pink, and Redact, reportedly call employees while posing as IT support staff. They convince those employees to type their passwords and multi-factor authentication codes into fake login pages. Once they’re in, they steal data and then demand a ransom, threatening to publish everything if the company refuses to pay. Some ransoms in this campaign reached $750,000, according to Google.

Apollo’s breach doesn’t sit in isolation. Security researchers at Google warned weeks earlier about a coordinated extortion campaign hitting private equity firms and financial institutions. Reuters named Apollo alongside Blackstone, Bridgewater, and Bain Capital as targets. At the time, it wasn’t clear which companies had been successfully hit. Now we know Apollo was. And it raises an obvious question: who else?

The opacity here is striking. Apollo has around 5,000 employees as of early 2026, but the breach notice doesn’t clarify whether the stolen records belong to employees, people at portfolio companies, or someone else entirely. Apollo spokesperson Giovanna Falbo declined to comment or answer questions, including whether the company paid a ransom. That silence tells you something.

For people whose data may be in that breach, the lack of clarity is genuinely harmful. Social Security numbers combined with home addresses and birth dates is everything an identity thief needs. If Apollo has 5,000 employees and an unknown number of affiliated individuals in its systems, the exposure could be significant. And yet the company is filing paperwork with state attorneys general while saying nothing publicly.

There’s also a strange footnote worth mentioning: until 2025, TechCrunch was a subsidiary of Yahoo, which is owned by Apollo. The firm now being scrutinized for how it protects people’s data once owned a major tech media outlet. That context won’t change the outcome for anyone whose Social Security number is now floating around a hacker’s leak site, but it adds a certain irony to the story.