Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    What It Does to Your SOC

    September 12, 2026

    Is A Free VPN Worth Using? Here’s Why It Could Be Risky

    September 12, 2026

    Researchers link another hacking campaign to OpenAI agents

    September 12, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms
    Cybersecurity

    Apollo Confirms Data Breach Amid Cyberattacks Targeting Financial Firms

    InfoForTechBy InfoForTechSeptember 3, 2026No Comments4 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Apollo Global Management has confirmed a data breach in which attackers obtained sensitive personal information, including names, home addresses, dates of birth, and Social Security numbers.

    The investment firm said unauthorized access occurred across certain cloud platforms between July 6 and July 10, following a social engineering attack. Apollo has not disclosed how many people were affected or whose information was exposed.

    The incident comes amid a broader wave of social-engineering attacks targeting large companies and financial organizations, raising fresh concerns about attackers using stolen credentials and impersonation to gain access to corporate cloud environments.

    How the Apollo attack unfolded

    Apollo says the intrusion took place between July 6 and July 10.

    In a breach notification letter attached to its California breach report, the company, through its Global Head of Human Capital, Matthew Breitfelder, characterized the incident as a social engineering attack.

    The timing and social-engineering tactics overlap with a broader campaign targeting major corporations and financial firms, although Apollo has not publicly attributed its breach to a specific group.

    Reporting on the wider campaign found attackers impersonating IT support personnel and using phishing pages to trick employees into handing over credentials and authentication information, which could then be used to access corporate cloud environments.

    Apollo said it began investigating the incident after detecting the unauthorized activity and brought in outside cybersecurity and forensic specialists. It also notified law enforcement of the incident.

    Breitfelder also said there is currently no evidence that the information has been publicly posted or used for identity theft or fraud.

    Who was behind the Apollo breach?

    Apollo has not publicly identified the attackers.

    Google, which first sounded the alarm about targeted attacks, has linked the attacks to a single threat group with several aliases.

    TechCrunch reports that the listed names include Redact, Pink, Falcon, and Helix. CyberScoop noted that the tactics resemble different subsets of the broader The Com cybercrime ecosystem. However, those connections should not be treated as proof that any one of those groups breached Apollo.

    The hacker’s identity is far from the only thing Apollo has left unanswered. The company has not publicly said whose personal information was stolen, how many people were affected, exactly which cloud platforms were accessed, or whether the attackers accessed anything beyond the disclosed personal information.

    Apollo has also not provided information on whether they demanded or received a ransom.

    CyberScoop says hackers often demand up to $3 million, but negotiations bring the amount down to less than $1 million. TechCrunch also asked Apollo for more information about the breach, but the company has not provided answers beyond its public disclosure.

    What the Apollo breach means for everyone else

    Apollo’s breach shows where the consequences of this campaign ultimately land: with the people whose information was exposed. But the bigger issue extends well beyond the people directly affected by Apollo’s breach to other large enterprises, their employees, and users.

    Reuters found that attackers had created personalized phishing domains for more than 200 companies, showing how easily this approach can be replicated at scale.

    That means organizations across the financial ecosystem now have to assume that their own help desks, authentication systems and cloud accounts could be tested in the same way.

    For companies, that raises the bar beyond simply having MFA, endpoint protection or cloud security in place. They need to verify the person behind an authentication request, make help-desk processes resistant to impersonation, limit what compromised accounts can reach and watch for unusual activity after legitimate credentials are used.

    And for individuals, Apollo’s offer of monitoring and identity protection is a reminder that the effects of a breach do not necessarily end when the attacker leaves the network.

    The immediate investigation may find no evidence of fraud today, but exposed identity data can remain useful to criminals long after the original incident has disappeared from the headlines.

    More Security News: Microsoft has delayed Exchange Server Subscription Edition CU1 as engineers work through AI-assisted security findings and ongoing patch requirements, leaving administrators without a firm release date. 

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    What It Does to Your SOC

    September 12, 2026

    AI Agents Help Hackers Compromise 440 PaperCut Servers

    September 12, 2026

    Best Practices for Deception Technology Implementation

    September 12, 2026

    Weekly Update 521: Breach Perception v. Reality

    September 11, 2026

    Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    September 11, 2026

    180 Android Security Flaws Patched: What to Do

    September 11, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views

    How is Luckin Coffee expanding rapidly in S’pore while keeping its coffee so cheap?

    April 23, 202621 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    A Billionaire-Backed Startup Wants to Grow ‘Organ Sacks’ to Replace Animal Testing

    March 23, 2026337 Views

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202640 Views

    Mayiduo spent S$1M to produce his movie. It broke even & that’s a win in S’pore.

    March 31, 202628 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.