Original briefings. Zero spin.
Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.
Apollo Global Management Confirms Hackers Stole Social Security Numbers in July Breach

Apollo Global Management confirmed hackers broke into some of its cloud systems last month and made off with personal data that includes Social Security numbers. Apollo manages more than $1 trillion in assets.
According to Reuters, the unauthorized access happened between July 6 and July 10, 2026. Apollo says it discovered the potential compromise earlier this month, notified law enforcement, and brought in outside cybersecurity and forensic experts. The firm began sending notification letters to affected individuals on August 20, 2026, according to Cole & Van Note, a California law firm now investigating potential data breach class action claims.
The stolen data potentially includes names, dates of birth, contact information, home addresses, and Social Security numbers, per Apollo's own notification letter as reported by Reuters. Apollo has not said how many people were affected, and Reuters did not specify whether those impacted are employees, clients, investors, or some combination.
A Bigger Hacking Campaign, Not a One-Off
Apollo wasn't picked at random. Reuters reported the firm was among dozens of prominent U.S. financial institutions and other businesses recently targeted by ransom-seeking hackers who use phone calls to compromise victims. Bloomberg reported the breach stemmed from a "social engineering incident," a term security researchers use for attacks that manipulate employees into handing over credentials rather than exploiting a software flaw.
Ground News aggregation shows the same story getting picked up across outlets including Bloomberg, and notes that hedge funds Point72, Citadel and Millennium had faced attempted or successful attacks earlier this same month. Google researchers reportedly flagged hackers targeting financial companies broadly, according to reporting cited by Ground News, before Apollo's breach came to light.
This is one firm inside a coordinated wave of attacks against the financial sector, using a method that doesn't require breaking through a firewall. It requires convincing one employee to type a password into the wrong place.
How the Attack Worked, As Far As Anyone Knows
Apollo has not publicly detailed exactly how the attackers got in. But futureproof.app, citing Reuters reporting, notes the broader campaign against financial firms involved phone calls and fake websites designed to steal employee passwords, a technique often called vishing (voice phishing) paired with credential-harvesting sites that mimic legitimate company logins.
Reuters has not confirmed that this specific method is what let attackers into Apollo's systems. The precise entry point remains undisclosed. Firms in this position often stay vague about the mechanism, either because forensic investigations are still running or because disclosing tactics can help future attackers. Apollo's investigation is described as ongoing.
What Apollo Says It Found, and Didn't Find
Apollo says it found no evidence that the stolen information was publicly posted or used for identity theft or fraud, according to futureproof.app's reporting on Apollo's disclosure. Affected individuals are being offered free third-party identity protection and credit monitoring, a standard response in breaches involving Social Security numbers.
This is Apollo's position as of now. It is not proof the data hasn't been or won't be misused. Stolen identity data frequently surfaces on criminal marketplaces months or years after a breach, long after companies stop watching closely.
Legal Exposure Is Already Building
Cole & Van Note, a California firm specializing in data breach class actions, is actively soliciting affected individuals for a potential lawsuit against Apollo Management Holdings, L.P. The firm points to a California Attorney General data breach notice as the basis for its investigation and says it will be pursuing legal action on behalf of those affected. This is standard practice after any large breach involving Social Security numbers.
The Uncomfortable Pattern
The Wealth Advisor's coverage notes that Apollo has poured enormous resources into securing its cloud infrastructure while depending on individual employees to authenticate access to that same infrastructure. A sufficiently convincing phone call bypasses a lot of expensive security architecture. The pattern repeats across the whole wave of attacks hitting Citadel, Point72, Millennium and others this year.
Whether Congress, the SEC, or state regulators respond with new disclosure requirements for social engineering attacks against financial firms remains an open question. Apollo's investigation is ongoing, and the firm has not publicly disclosed how many people were affected or identified the attackers.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.