---
title: "Apollo tells California regulators that hackers took Social Security numbers"
description: "The private equity firm disclosed a four-day intrusion in July through a breach letter filed with the state attorney general. Google's researchers say the campaign behind it works by phoning staff and pretending to be the IT helpdesk, and has hit several of the biggest names in finance."
category: "Business"
category_url: https://newsparlor.com/category/business
author: "Chloe Bennett"
published: 2026-08-22T09:46:29-04:00
updated: 2026-08-22T09:46:29-04:00
canonical: https://newsparlor.com/article/apollo-tells-california-regulators-that-hackers-took-employee-social-security-nu
tags: ["cybersecurity", "apollo", "private-equity", "data-breach", "social-engineering"]
---
# Apollo tells California regulators that hackers took Social Security numbers

The private equity firm disclosed a four-day intrusion in July through a breach letter filed with the state attorney general. Google's researchers say the campaign behind it works by phoning staff and pretending to be the IT helpdesk, and has hit several of the biggest names in finance.

Apollo Global Management has confirmed that hackers took names, dates of birth, contact details including home addresses, and Social Security numbers, in a breach it disclosed through a letter filed with California's attorney general, [TechCrunch reports](https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/).

The intruders had access between July 6 and July 10. The letter was signed by Matthew Breitfelder, Apollo's human resources chief.

## What Apollo has not said

The firm's letter does not say whether the people whose data was taken are Apollo employees or individuals at the companies Apollo owns. That is a meaningful gap, because those are very different populations of very different sizes, and it determines who should be watching their credit file.

Nor is a number of affected people given. Apollo's Giovanna Falbo did not provide comment when TechCrunch approached the firm.

The disclosure route is itself informative. California requires notice to the attorney general when a breach affects a threshold number of state residents, and those filings are public. A great deal of what the world learns about corporate intrusions arrives this way: not through an announcement a company chose to make, but through a form it was obliged to file.

## How the attackers got in

The intrusion was a social engineering attack on Apollo's cloud environment. Google's security researchers, who have been tracking the wider campaign, assess that the hackers "rely largely on social engineering attacks that involve calling employees and pretending to be IT helpdesks or support" in order to steal credentials and get onto the network.

This is worth dwelling on, because it defeats the mental model most organizations still have of a breach. There is no exploit here, no unpatched server, no clever piece of malware. Someone telephones an employee, sounds like the help desk, and asks for a code. Multi-factor authentication does not stop it, because the caller simply asks for the second factor too, and the employee, believing they are being helped, reads it out.

Google's researchers say the same actors operate under several names, including Falcon, Helix, Pink and Redact. That is an assessment by investigators rather than a claim of responsibility by the group itself, and the distinction matters: nobody has stood up and said they did this.

## The wider campaign

Apollo is not alone. TechCrunch, citing Reuters, names Blackstone, Bridgewater, Bain Capital and CME as targets in the same wave. Google has reported that some of the attacks in the campaign netted ransoms of as much as $750,000.

There is no indication in the report that Apollo paid anything, and none that it was asked to.

The choice of targets follows a logic. Alternative asset managers hold concentrated, high-value information about wealthy individuals, portfolio companies and transactions, on comparatively small staffs, and they run on cloud services that a single set of stolen credentials can unlock. A firm can spend heavily on security and still be undone by one person on a phone call believing they are talking to their own IT department.

That is the uncomfortable conclusion of this particular breach. What failed was not a system.

## Sources

- [Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants](https://techcrunch.com/2026/08/21/private-equity-firm-apollo-confirms-data-breach-amid-hacking-wave-targeting-financial-giants/)

