Apollo Global Management Confirms Data Breach in Broader Campaign Against Financial Firms

Apollo Global Management has confirmed a data breach in which hackers stole personal information from its cloud systems, according to a letter filed with California's attorney general on August 21, 2026. Apollo's human resources chief, Matthew Breitfelder, stated that hackers used a social engineering attack to gain access to the company's cloud environment between July 6 and July 10, 2026. Social engineering refers to manipulating people into giving up credentials or access rather than breaking through technical defenses. The stolen data included names, birth dates, contact information including home addresses, and Social Security numbers. Apollo spokesperson Giovanna Falbo did not provide comment when reached by TechCrunch about the incident.
Apollo is one of the world's largest private equity firms, with $938 billion in assets under management and roughly 5,000 employees as of February 2026. The breach did not occur in isolation. It is part of a broader extortion campaign tracked as UNC6671, in which hackers have targeted private equity companies and financial giants. Google researchers warned that the attackers rely largely on social engineering techniques, specifically tricking employees into entering passwords and multi-factor authentication (MFA) codes in spoofed login portals. A spoofed login portal is a fake website designed to look like a legitimate sign-in page. Reuters reported that Apollo was among companies targeted alongside Blackstone, Bridgewater, Bain Capital, and others.
Hackers built 72 malicious websites targeting employees at firms including Blackstone, Apollo, and KKR. Google's security researchers reported that hackers are calling employees of large U.S. financial firms directly to steal sensitive data and extort victims. Some of the attacks netted the attackers ransoms as much as $750,000, according to Google. Law firm Greenberg Traurig, also reportedly targeted, released a statement saying its security protocols successfully protected client data and prevented a data breach. Google's threat intelligence researchers attributed the activity to hackers known by names including Falcon, Helix, Pink, and Redact.
The Mandiant M-Trends 2026 report found the high-tech sector overtook finance as the top target of cyberattacks, accounting for 17% of all Mandiant investigations in 2025. The UNC6671 campaign, however, shows a continued, focused threat against financial services and enterprise cloud environments. The report covers cyber threats including ransomware recovery denial and extreme persistence. Until 2025, TechCrunch was a subsidiary of Yahoo, an advertising technology company owned by Apollo.
The broader context here is that the UNC6671 campaign's reliance on social engineering rather than novel exploit chains deserves attention from security teams. The attack vector that compromised Apollo's cloud environment, a social engineering attack resulting in stolen MFA codes, bypasses the credential protections that many enterprises treat as sufficient. The technique requires minimal investment in zero-day vulnerabilities, which are previously unknown software flaws that attackers exploit before developers can patch them. Spoofed login portals and direct phone calls to employees are effective because they exploit human trust at the access layer.
The successful exfiltration of Social Security numbers and home addresses from a firm of Apollo's scale creates a downstream risk profile that extends well beyond Apollo's internal operations. Employees whose data was stored in Apollo's cloud systems face potential identity theft, and the combination of Social Security numbers, birth dates, and home addresses provides a foundation for targeted phishing and fraud campaigns that could persist for months or years.
For technology professionals managing cloud security in regulated industries, the Apollo breach and the broader UNC6671 campaign reinforce the need for controls beyond MFA. Phishing-resistant authentication, continuous monitoring for anomalous cloud access, and employee training that accounts for direct voice contact are all measures that can reduce the attack surface. The ransom payments of up to $750,000 reported by Google indicate the campaign is economically viable for the attackers, which increases the likelihood of continued targeting.
The fact that a private equity firm with $938 billion in assets under management was compromised through social engineering techniques rather than a sophisticated technical exploit is a reminder that the weakest link in any security architecture remains the human element. A firm with Apollo's resources being vulnerable should give pause to smaller organizations with thinner security budgets. Google's research on UNC6671 and the broader pattern of attacks on financial firms provides a useful threat intelligence baseline, but the operational reality is that social engineering campaigns adapt quickly to defensive measures. The malicious websites built to target employees at Blackstone, Apollo, and KKR were likely designed to mimic legitimate authentication flows closely enough to deceive even technically sophisticated users. The successful breach at Apollo and the reported ransoms collected from other targets suggest the attackers behind UNC6671 have found a repeatable formula. Until financial services firms and private equity companies close the gap between MFA implementation and phishing-resistant authentication, campaigns like UNC6671 will continue to find victims.


