Apollo Global Management has confirmed that hackers made off with personal data during a breach last month, making it the first firm caught up in this summer's wave of social-engineering attacks on private equity and financial companies to say outright that data was actually stolen rather than just probed.
In a notice filed with the California attorney general's data breach registry on Friday, Apollo said an investigation found intruders had unauthorized access to some of its cloud-based systems between July 6 and July 10. The firm said it wasn't until August 12 that it pinned down exactly which categories of information were taken: full names, dates of birth, contact details, home addresses, and Social Security numbers. Apollo hasn't said how many people are affected, or whether the exposed records belong to employees, portfolio company staff, or some other group.
Matthew Breitfelder, Apollo's global head of human capital, signed the notification letter. The firm said it moved quickly once the intrusion was found, notifying law enforcement and bringing in outside cybersecurity and forensic experts. Apollo said it has no evidence so far that the stolen data has been posted online or used for fraud, and it's offering affected individuals complimentary credit monitoring and identity protection services.
Apollo didn't say exactly how the intruders got in, describing the incident only as a case of social engineering. The breach fits inside a broader extortion campaign that security researchers flagged weeks earlier as targeting private equity firms and other financial institutions. The group behind it has reportedly been posing as internal IT help desks over the phone, talking employees into handing over passwords and one-time login codes through convincing fake sign-in pages, with some resulting extortion demands said to run into the hundreds of thousands of dollars.
That approach, commonly known as vishing, or voice phishing, was also behind the wave of attempted hacks that hit Wall Street firms including Point72 last month, when Steve Cohen's hedge fund said it had been targeted, though it initially indicated no client information had been taken. Several other large financial institutions have also been named as targets of the same campaign in recent weeks, alongside Apollo, though it's not yet clear which of them, if any, had data taken rather than simply fending off an attempt.
For carriers and brokers writing management liability and cyber lines into the private equity space, Apollo's disclosure is a reminder that vishing has become a preferred way in for attackers going after firms that sit on enormous troves of sensitive personal and financial data but, in many cases, run leaner security teams than banks of a similar size. Insurance Business has previously reported on how cyberattacks have become a "material transaction risk" for private equity firms, with one industry survey finding an average financial hit of $2.1 million per incident and a meaningful chance that losses on any single attack could top $5 million. That kind of exposure is part of why carriers such as QBE have started publishing guidance aimed specifically at helping PE firms shore up the cyber resilience of their portfolio companies, not just their own back office.
The case also touches a question underwriters have been wrestling with for a while: how to price and structure coverage for breaches that start with a phone call rather than a technical exploit. Many cyber policies still cap payouts for social-engineering fraud well below the limits available for a network intrusion, an approach that looks increasingly out of step with how these attacks actually play out. A stolen login obtained by tricking a help desk employee can lead to the same kind of data loss as a more sophisticated hack, which is pushing some carriers to rethink where that line belongs.
There's also a bigger-picture regulatory angle. US Treasury Secretary Scott Bessent has convened bank leaders this year to talk through how increasingly capable AI tools could make attacks like these easier to run at scale, and the International Monetary Fund has separately warned that AI-assisted attacks exposing weaknesses in lenders' defenses could pose a risk to financial stability more broadly, not just to the firms directly hit. Whether AI played any role in the Apollo intrusion specifically hasn't been established, and Apollo hasn't said.
Apollo did not respond to requests for comment on the incident, and it's not known whether the firm paid the attackers a ransom.
For more on how the cyber insurance market is responding to this kind of exposure, see Insurance Business's cyber insurance coverage hub.