Apollo Global Management, one of the world's largest private equity firms, has confirmed a breach that exposed personal data including Social Security numbers.
Attackers used a social engineering attack, likely phishing, to trick an Apollo employee into handing over access to the company's cloud environment. The intrusion ran from July 6 to July 10, 2026, before Apollo caught it and brought in police and outside forensic investigators. On August 12, the company determined the exposed data included names, dates of birth, contact information, home addresses, and Social Security numbers. No credit card or bank account details were taken, and Apollo has notified California's Attorney General while offering affected people two years of free identity monitoring through Cyberscout.
The bigger story is who Apollo is. Private equity firms sit on enormous stockpiles of sensitive data on portfolio company employees, limited partners, and executives, which makes them lucrative targets even without touching a bank account number. A name, birth date, address, and Social Security number is a complete identity theft starter kit, useful for opening credit lines or convincing a bank someone is who they say they are.
Two years of credit monitoring is the industry's standard apology gift, not a fix. And "no evidence of dark web leaks yet" is doing a lot of work in that sentence; six weeks after a breach is still early.