Apollo Global Management has confirmed a data breach after hackers used a social engineering attack to access the private equity giant’s cloud environment between July 6 and July 10. According to a filing with California’s attorney general, the attackers stole names, dates of birth, contact information, home addresses, and Social Security numbers. Apollo, one of the world’s largest private equity firms with $938 billion in assets under management and roughly 5,000 employees, has not publicly confirmed who was affected or whether the hackers demanded or received a ransom.
The breach is especially concerning because it fits a broader campaign targeting financial services and private equity firms through cloud identity compromise. Groups tracked under names such as Falcon, Helix, Pink, and Redact have been calling employees while posing as IT help desks, tricking them into entering passwords and MFA codes into spoofed login portals. For firms like Apollo, that kind of access can expose not only employee data, but also sensitive deal workflows, portfolio company information, investor communications, financial models, legal documents, diligence materials, and cloud-hosted collaboration systems.
In an Apollo-style breach, the most urgent question is what the compromised identity actually touched during those four days. Unified visibility in a platform like NIKSUN lets investigators trace the attack from the social engineering event to cloud login, MFA abuse, SaaS access, file downloads, database queries, mailbox activity, API calls, and outbound network sessions. By correlating identity logs, cloud audit trails, endpoint telemetry, DNS, NetFlow/IPFIX, packet capture, DLP signals, and L2–L7 session analytics, security teams can determine in minutes which accounts were abused, what data was accessed, whether files were exfiltrated, and which systems require containment or credential rotation. That level of traceability is critical for private equity firms, where one cloud breach can create risk across employees, investors, portfolio companies, and confidential transactions.
Read more about this story on our LinkedIn page