Skip to main content
Emerging ThreatsData Breaches

Apollo Breach Exposes Sensitive Data Via Social Engineering

Empty office cubicle with laptop and papers, set against blurred background of larger office space with cityscape outside.

“An unauthorized user had access to certain cloud platforms from July 6 to July 10, 2026,” Apollo Global Management said, a four-day window that defines the perimeter of the firm’s announced data breach.

Timeline: July 6–10, 2026

Apollo Global Management detected a social engineering attack and, following that detection, launched an investigation that established an unauthorized user had cloud access between July 6 and July 10, 2026. The company’s public disclosure links the period of exposure directly to that window; law enforcement and outside cybersecurity and forensics specialists were engaged to support the inquiry.

What was exposed: sensitive PII including Social Security numbers

Apollo said the incident affected sensitive, personally identifiable information (PII). The types of data identified in the company’s disclosure include names, birth dates, home addresses, contact information and Social Security Numbers (SSNs). The firm explicitly describes this list as sensitive PII, and it reported that, at this time, it has no evidence to suggest the information has been misused.

How the breach began: a social engineering scheme and cloud-platform access

According to Apollo’s statement, the root cause was a social engineering attack. That social engineering led to unauthorized access to “certain cloud platforms” for the four-day period in July. Beyond naming the attack vector and the affected hosting environment, Apollo’s public notice focuses on the facts that the incident was detected, that law enforcement was notified, and that external cybersecurity and forensics experts were retained to investigate.

Investigation: law enforcement and external forensics are involved

The company described the investigation as ongoing and said it had the support of law enforcement as well as external cybersecurity and forensics specialists. Apollo’s timeline and the participation of external teams are the elements the firm presented as the basis for its current understanding of what occurred. The disclosure reiterates that, to date, there is no evidence the exposed information has been misused, while the inquiry continues.

What this means for affected individuals, law enforcement, and technologists and security teams

  • Affected individuals: People whose names, birth dates, home addresses, contact information and Social Security Numbers were included in the exposure will be monitoring the investigation and any notifications from Apollo; the company has reported no evidence of misuse at this time but has confirmed the presence of their data in the breach.
  • Law enforcement and external cybersecurity and forensics experts: Those parties are actively supporting Apollo’s investigation into the social engineering incident and the cloud-platform access that occurred July 6–10, 2026; the firm identified them as part of its response effort.
  • Technologists and security teams: The firm’s account centers on social engineering and cloud-platform access, which are the technical and operational focal points of the inquiry Apollo disclosed. Those teams are the ones tasked with tracing the access, analyzing cloud logs, and validating the scope of exposed data as part of the ongoing forensics.

Apollo Global Management’s disclosure centers on three concrete facts: the breach resulted from a social engineering scheme, sensitive PII (including SSNs) was exposed, and an unauthorized user had cloud-platform access from July 6 to July 10, 2026. The company says it has engaged law enforcement and external forensics experts and that, so far, there is no evidence the information has been misused. The investigation remains active, and those are the details Apollo has put on the record.

Read the original announcement: https://www.securitymagazine.com/articles/102509-social-engineering-scheme-led-to-apollo-data-breach