Apollo Global Management confirmed on August 21, 2026 that attackers gained unauthorized access to its cloud platforms between July 6 and July 10, 2026, a four-day window. The exposed personal data includes names, dates of birth, home addresses, contact information, and Social Security numbers, though no financial account details or proprietary business information was compromised. The attack was carried out through a sophisticated phishing campaign combining website spoofing and phone-based deception to extract employee credentials. The firm is offering 24 months of complimentary credit monitoring and identity protection to affected individuals, and initial findings indicate that the stolen data has not been publicly released or used for fraud. Other major private equity firms, including Blackstone, KKR, and Bain Capital, were also targeted by the same coordinated campaign.
Source: Read the original article

