On 21 August 2026, Apollo Global Management (Apollo), one of the world's largest private equity firms with $938 billion in assets under management, confirmed that hackers had stolen employee data in a breach that began more than six weeks earlier. In a notice filed with California's attorney general, Apollo's global head of human capital, Matthew Breitfelder, said intruders gained unauthorised access to the firm's cloud environment between 6 and 10 July 2026 through a social engineering attack. It took until 12 August, more than a month after the intrusion, for the company to determine exactly what had been taken.
The method was vishing. According to Google's Threat Intelligence Group, the actors behind the campaign, tracked under aliases including Falcon, Helix, Pink and Redact, called Apollo employees directly on their personal mobile phones, posing as the firm's internal IT help desk. In some calls, the attackers spoofed the company's genuine help desk number, so the caller ID matched what an employee would expect to see from a legitimate internal call. Staff who engaged were walked through to lookalike login pages built to harvest passwords and one-time multi-factor authentication codes, credentials that gave the attackers a working route into Apollo's systems without needing to breach a firewall.
The data taken included full names, dates of birth, home addresses and Social Security numbers. Apollo has not disclosed how many people are affected, nor whether the exposed records belong to its own employees, staff at the companies it owns, or another group entirely. The company is offering 24 months of credit monitoring and identity protection to those affected and says it has found no evidence so far that the stolen data has been sold or published, though it has not said whether a ransom was paid.
Apollo is not an isolated target. Google warned weeks earlier that the same actors had been running a coordinated campaign against private equity and financial firms including Blackstone, Bridgewater, Bain Capital and CME Group, using identical help desk impersonation tactics. Some of those attempts, including one against Steve Cohen's Point72 in early August, were reportedly detected and stopped before data left the building. Apollo's disclosure is one of the first confirmations that this summer's campaign against Wall Street and private equity firms did not just probe, it succeeded. Google says ransom demands in the wider campaign have reached as high as $750,000 per victim.
The defences that failed here were not weak by conventional standards. Apollo runs multi-factor authentication across its systems, employs external forensic and cybersecurity specialists, and notified law enforcement as soon as the intrusion was found. None of that mattered at the moment that counted, because the attack was never aimed at a technical vulnerability. It was aimed at a person on the other end of a phone call who had no reliable way to confirm that the voice claiming to be IT support actually was.
This is precisely the scenario GoFirm is built to stop. A password reset or a multi-factor authentication approval triggered by an inbound phone call is an execution event, not a routine IT interaction. Before that reset or approval completes, a confirmation request goes out over a separate channel, never the phone line the caller is already controlling, to the named authority responsible for that account or system, requiring a biometric confirmation on their own registered device.
No confirmation, no execution. It does not matter how convincing the caller sounds, how much internal jargon they use, or whether the caller ID matches the real help desk number precisely, as it reportedly did in Apollo's case. A spoofed caller ID, however convincing, cannot produce that confirmation. The execution boundary holds regardless of how credible the impersonation appears.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Whittaker, Z. 2026. Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants. TechCrunch, 21 August 2026.
2. Insurance Business. 2026. Alternative asset manager confirms hackers stole personal data in social engineering attack. Insurance Business, 21 August 2026.
3. Google Cloud Threat Intelligence Group. 2026. UNC6671 Targets Financial Services and Enterprise Cloud Environments. Google Cloud Blog, August 2026.
