Apollo Global Management, one of the world's largest alternative asset managers, has confirmed that intruders accessed personal data held in its cloud environment after a social engineering attack. The disclosure came in a notification letter dated August 21, 2026, signed by Apollo's chief human resources officer Matthew Breitfelder and posted to the California attorney general's breach portal, as reported by both Bloomberg and TechCrunch. Apollo says the unauthorized access occurred between July 6 and July 10, 2026, and that the exposed data included names, dates of birth, contact information, home addresses, and Social Security numbers. No source publishes a victim count. The breach lands roughly six weeks into a documented extortion campaign against U.S. private equity firms, hedge funds, and financial infrastructure operators that Google Threat Intelligence Group tracks as UNC6671.
What Happened
The confirmed facts are narrow and consistent across sources. Apollo experienced what it describes as a social engineering incident, which led to unauthorized access to "certain cloud platforms" over a five-day window from July 6 to July 10, 2026. Bloomberg reports Apollo said hackers used social engineering to reach data stored in Apollo's cloud. TechCrunch, working from the same California filing, adds that the letter does not identify whose data was taken, leaving open whether the affected individuals are Apollo employees, personnel at portfolio companies, or some mix. Apollo listed roughly 5,000 employees in public regulatory filings as of February 2026, and TechCrunch puts assets under management at $938 billion. TechBooky, a lower-confidence outlet, describes the AUM figure only as "hundreds of billions."
Two details appear in single OTHER-tier sources and should be treated as unconfirmed. TechBooky reports that Apollo discovered the activity on July 10, secured its systems, and began notifying affected people. That discovery date is plausible given the stated end of the access window, but no primary or established-press source states it. TechBooky also notes that California requires a sample notice to be filed with the attorney general when more than 500 state residents are affected, which would set a floor of 500 California residents but says nothing about the total population. ClassAction.org, also OTHER-tier, reports that Apollo's sample notice letter says the investigation remains ongoing and that the company may issue further updates. Plaintiffs' attorneys are already soliciting affected individuals for a possible class action.
Apollo has not publicly attributed the intrusion to any named group. Apollo spokesperson Giovanna Falbo did not respond to TechCrunch's questions, including whether the firm paid a ransom. The link between Apollo and the UNC6671 campaign is an inference drawn by the press from timing and technique, not something Apollo has confirmed.
What Was Taken
Every source that describes the data set agrees on its composition: names, dates of birth, contact information including home addresses, and Social Security numbers. That combination is the full identity-theft kit. Social Security numbers alongside dates of birth and verified home addresses support synthetic identity fraud, credit application fraud, and account takeover at institutions that still use knowledge-based authentication.
What nobody has published is a number. There is no record count in any of the eight sources, and no breakdown of whether the affected population is employees, retirees, dependents, portfolio company staff, or investors. Given the California filing threshold, the affected California resident count exceeds 500, but the national total is unknown. Apollo's roughly 5,000-employee headcount is the only quantitative anchor available and should not be mistaken for a breach scope figure, since the letter explicitly does not limit the affected population to employees.
Also unstated: whether investment data, deal documents, or portfolio company information was accessed. The notification covers personal information only, which is what California law compels. Absence of a claim about corporate data is not evidence that none was touched.
Why It Matters
The UNC6671 campaign has been aimed squarely at firms that sit on concentrated, high-value non-public information. Reuters reported on August 6 that the operators built 72 malicious websites targeting employees at firms including Blackstone, Apollo, and KKR, and that Google observed a shift toward private equity, law firms, and financial ratings agencies. Reuters was explicit at the time that it could not establish whether any of the attempted intrusions succeeded. Apollo's filing is the first public confirmation from a named target in that cohort that an attempt landed.
The broader victim list assembled by the press is substantial. TechCrunch, citing Reuters, names Apollo, Bain Capital, Blackstone, Bridgewater Associates, CME Group, KKR, Moody's, and TPG among those targeted. BleepingComputer, citing Reuters and Bloomberg, adds Point72 Asset Management, Millennium Management, Two Sigma Investments, and Citadel. Several of those firms have pushed back on the idea they were compromised. Point72 reportedly told investors it was attacked but found no evidence client data was stolen, and Two Sigma said it blocked an attempted intrusion with no indication that systems or data were affected. Millennium and Citadel declined to comment to BleepingComputer. Targeted is not the same as breached, and the public record currently supports "targeted" for most of the list and "breached" only for Apollo.
For defenders, the strategic read is that identity is the perimeter. As TechBooky frames it, a single successful identity compromise in a cloud environment can reach data that older, more segmented architectures kept isolated. The attackers here did not need a zero-day. They needed one employee to answer a phone call.
The Attack Technique
Google's threat researchers published on August 6 describing groups that call employees on their personal mobile phones, impersonate co-workers or IT helpdesk staff, and walk targets into entering credentials and multi-factor codes on spoofed login portals. SecurityWeek reports that GTIG describes the pretext as a mandatory, urgent security migration, and that the operators focus on Microsoft 365 and Okta infrastructure, using adversary-in-the-middle techniques to relay credentials and MFA tokens in real time and gain access to cloud tenants. Data theft, followed by extortion under threat of publication, is the monetization model. One leak site quoted by TechCrunch reads: "We conduct every negotiation on professional terms. The publication of your data is never our preferred resolution; it is the consequence of refusal to engage."
Attribution is layered. Google Threat Intelligence Group principal threat analyst Austin Larsen told BleepingComputer that the activity is tracked as UNC6671, that the group previously operated under the public brand BlackFile, and that it has since diversified across the Redact, Pink, Helix, and Falcon brands. Larsen's assessment is that "a single core intrusion group is driving the helpdesk vishing and cloud data theft across these various public extortion brands." SecurityWeek reports the same brand cluster and adds that the Redact leak site launched in June with a claim that the BlackFile operation had been hijacked by an affiliate. GTIG hedges its own conclusion, noting that alternative explanations such as splintered affiliates cannot be ruled out.
Accounts differ on the group's origin date. BleepingComputer states that BlackFile first emerged in February 2025 with attacks on retail and hospitality organizations. SecurityWeek states the threat actor emerged in early 2026 under the BlackFile name, with a GTIG warning in May 2026 about dozens of targets across North America, Australia, and the UK. Both cite GTIG reporting. The discrepancy is unresolved in the public record, and readers should treat the group's start date as uncertain rather than settled. On the pivot to finance, BleepingComputer says Mandiant's report places the targeting shift in July 2026, which aligns with Apollo's July 6 to July 10 access window.
Apollo has confirmed only "social engineering." It has not said the intrusion involved vishing, spoofed portals, or an AiTM proxy, and it has not named UNC6671. The technique described above is what Google documented across the campaign, not what Apollo has attested to for its own incident.
What Organizations Should Do
-
Treat inbound IT helpdesk calls as an unauthenticated channel. Establish and publicize an out-of-band verification procedure so employees can confirm a caller's identity through a channel the caller does not control. The pretext here is an urgent, mandatory security migration, which is engineered to defeat exactly the hesitation you want employees to have.
-
Deploy phishing-resistant MFA on Microsoft 365, Okta, and every SSO-fronted cloud application. FIDO2 security keys and passkeys bound to the origin defeat AiTM proxies, which is the specific technique SecurityWeek reports GTIG observed. Push notifications, TOTP codes, and SMS do not.
-
Harden the helpdesk itself, not just the workforce. Require strong identity proofing before any MFA reset, device enrollment, or password change. This group's brand lineage runs through operations known for helpdesk-centric social engineering, and the reset workflow is as much a target as the employee.
-
Instrument for anomalous cloud data access, not just anomalous logins. The Apollo access window spanned five days. Alert on bulk exports, unusual SaaS API volume, new OAuth grants, impossible-travel sessions, and first-time-seen enrollment of authenticators on existing accounts.
-
Reduce standing access to personnel data. Names, dates of birth, home addresses, and SSNs should sit behind just-in-time access with approval workflow, not in a broadly readable HR platform. A single compromised identity should not be able to enumerate a workforce.
-
Rehearse the extortion decision before you face it. These operators run leak sites and negotiate. Decide in advance who authorizes contact, what your payment posture is, and how you meet state notification deadlines. Apollo's California filing arrived roughly six weeks after the access window closed, and that clock starts whether or not your investigation is complete.
-
Watch the portfolio, not just the parent. Apollo's letter does not say whose data was taken, which raises the question of downstream exposure at owned companies. Firms with portfolio or subsidiary structures should assume the parent's cloud tenant is an aggregation point and scope incident response accordingly.
Sources: Private equity firm Apollo confirms data breach amid ... | Google says hackers are calling financial firm employees to hack an... | Hedge fund cyberattacks tied to BlackFile-linked UNC6671 extortion... | Vishing Extortion Group UNC6671 Rebrands After Making Millions - Se... | Apollo Reports Data Breach From 'Social Engineering ... | Hackers targeted US private equity, other firms including ... | Apollo Global Management Data Breach Impacts SSNs | Apollo Data Breach Shows Wall Street's Cloud Security Problem