Data Breaches Negative 7

Apollo's 5-Day Cloud Intrusion Exposes SSNs, Names, DOBs

Apollo Global's breach disclosure shows a five-day cloud intrusion that exposed Social Security numbers, dates of birth, and contact data. The attack is tied to a wider campaign using vishing and fake login pages against financial firms.

· 4 min read · Verified by 2 sources ·

Beat this week

Last 7 days · Data Breaches

2 stories
6 avg impact
0% positive
50% negative
vs prior 7 days 0 Unchanged vs prior 7 days

Impact 6.0/10, unchanged. Counts are stories in our record, not a market forecast.

Open the change report

Coverage balance Negative coverage leads. Negative coverage exceeds positive coverage by 50 percentage points.

  • 50% neutral
  • 50% negative

This story sits in Data Breaches — the counts compare this beat's last 7 days with the previous 7 in our verified record, not a market forecast.

Figures are computed live from our source-verified story record (as of ) The volume change compares this window with the prior 7 days in the same record. — see our methodology for how impact and sentiment are derived.

Cybersecurity briefing

Key takeaways

7 impact
Negativesentiment
2sources
4min read
  1. Apollo Global's breach disclosure shows a five-day cloud intrusion that exposed Social Security numbers, dates of birth, and contact data.
  2. The attack is tied to a wider campaign using vishing and fake login pages against financial firms.
Drawn from
  • thestar.com.my
  • finance.yahoo.com

In this briefing

Mentioned

Key Intelligence

Key Facts

  1. 1Unauthorized access to certain Apollo cloud platforms occurred between July 6 and July 10, 2026.
  2. 2Potentially impacted personal data includes names, dates of birth, contact information, home addresses, and Social Security numbers.
  3. 3Apollo notified law enforcement and engaged outside cybersecurity and forensic experts to investigate the breach.
  4. 4Affected individuals are being offered complimentary third-party identity protection and credit monitoring, according to Global Head of Human Capital Matthew Breitfelder.
  5. 5Reuters reported that dozens of prominent U.S. financial institutions and other businesses were targeted by ransom-seeking hackers using phone calls.
  6. 6As of Aug. 21, Apollo said it had no evidence that the stolen information had been publicly posted or used for identity theft or fraud.

Who's Affected

Apollo Global Management
companyNegative
Financial sector employees
groupNegative
Uber Freight
companyNegative
Levi Strauss & Co.
companyNegative

Analysis

Security teams should read Apollo's breach as a modern financially motivated intrusion playbook: attackers relied on phone-based social engineering and credential-harvesting websites targeting private equity employees, not zero-day exploits. The July 6–10 cloud access window demonstrates how stolen credentials can translate into multi-day dwell time before containment. With Social Security numbers in the exposed dataset, this is a high-severity PII incident that demands lessons for identity and access management.

Apollo Global Management confirmed on Friday, Aug. 21, 2026, that hackers stole personal information during a five-day intrusion into certain cloud platforms between July 6 and July 10. The New York-based alternative asset manager disclosed in a letter from Global Head of Human Capital Matthew Breitfelder that the potentially impacted data included names, dates of birth, contact information, home addresses, and Social Security numbers. The firm has notified law enforcement and engaged outside cybersecurity and forensic experts to investigate. As of the disclosure, Apollo said it had not found evidence that the stolen information had been publicly posted or used for identity theft or fraud.

Apollo Global Management confirmed on Friday, Aug.

The breach at Apollo is one node in a broader campaign against financial institutions and other high-profile companies. Reuters reported earlier in August that dozens of prominent U.S. financial institutions and businesses were targeted by ransom-seeking hackers who use phone calls to compromise victims. Internet intelligence reviewed by Reuters showed that the attackers built websites designed to steal passwords from employees of private equity firms and financial companies. Uber Freight and Levi Strauss said earlier this month they were investigating cybersecurity incidents involving unauthorized access to their systems, underscoring the breadth of the campaign.

What stands out from a security standpoint is the relatively low-tech nature of the initial compromise. Even as firms invest in sophisticated security programs and grapple with AI-driven threats, phone-based social engineering remains among the most effective intrusion methods, according to experts. Attackers can use vishing calls to persuade employees to reveal credentials or approve multi-factor authentication requests, then pivot into cloud platforms where sensitive data resides. Apollo's five-day access window from July 6 through July 10 suggests meaningful dwell time before the unauthorized access was contained, though the company has not specified exactly when the intrusion was detected.

The data involved makes this a high-severity personal information incident rather than a routine exposure. Social Security numbers, combined with names, birth dates, contact details, and home addresses, provide everything needed for identity theft and targeted fraud. Apollo is offering affected individuals complimentary third-party identity protection and credit monitoring, which is standard practice for breaches involving this class of data. The costs of forensic investigation, notification, legal review, and identity protection services can run into the millions even before any regulatory fines or litigation.

What to Watch

For investors, the direct financial impact on Apollo's asset management business may be limited, but the reputational and compliance dimensions are significant. Institutional investors and allocators expect asset managers to maintain strict controls over investor and employee data. A confirmed breach involving Social Security numbers can erode trust and trigger due diligence questions from limited partners. Public companies also face SEC cybersecurity disclosure requirements that require material incidents to be reported within four business days of a materiality determination, adding legal and compliance pressure to the technical response.

Looking forward, Apollo's disclosure may be followed by additional notices from other financial firms caught in the same campaign. The use of credential-harvesting websites aimed at private equity and financial company employees signals a targeted effort to access deal information, investor data, and internal communications. Organizations should expect continued emphasis on call-back verification, anti-phishing training, cloud access monitoring, and strict authentication policies. As the investigation advances, any evidence that the stolen data has been used for fraud would escalate both the financial and reputational consequences for Apollo.

Timeline

Timeline

  1. Unauthorized cloud access begins

  2. Unauthorized cloud access ends

  3. Apollo learns full scope of compromised data

  4. Apollo discloses breach in letter

Source cluster

Primary reporting

2articles

Cite This Page

"Apollo's 5-Day Cloud Intrusion Exposes SSNs, Names, DOBs." Cyber Intelligence Brief, August 21, 2026. https://getcyberbrief.com/story/apollo-5-day-cloud-intrusion-cyber

How we covered this story

Every story in our cybersecurity coverage is assembled from multiple primary sources, cross-referenced for factual consistency, and scored along three independent dimensions: sentiment, operational impact, and source-cluster confidence. Single-source rumors and unverifiable claims do not pass our editorial gate. When a story shows "Verified by N sources" with N≥2, the development is independently corroborated; when N=1, we mark it explicitly so readers can weigh the signal accordingly.

Impact scoring uses a 1-10 scale weighted toward regulatory, financial, and operational consequence rather than coverage volume. A topic that runs in every outlet but moves no real decisions ranks lower than a niche regulatory filing that reshapes how operators in the cybersecurity space have to behave. Read our full methodology for the scoring rubric, our glossary for term definitions, and our trends index for the longitudinal view across the beat.

Sources are only linked to a story once they clear our classification pipeline at a minimum 35 percent relevance threshold. According to that methodology, reviewed July 2026, this follows multi-source corroboration standards recommended by journalism research bodies such as the Reuters Institute for the Study of Journalism.

See something wrong in this story — a wrong fact, a broken source link, a misattributed entity? Report a data issue.