Apollo Global Management Confirms Data Breach in Wall Street Vishing Wave
Breach Summary
Apollo Global Management disclosed on August 21 that unauthorized actors accessed cloud platforms between July 6 and July 10, 2026, exfiltrating names, dates of birth, home addresses, contact details, and Social Security numbers. Google Threat Intelligence Group has linked the intrusion to a broader vishing campaign targeting Blackstone, Bridgewater, Bain Capital, and other Wall Street institutions.
Apollo manages roughly $700 billion in assets. It lost control of its identity fabric in five days. Nobody at Apollo noticed for a month.
What Happened
Between July 6 and July 10, 2026, unauthorized actors accessed unspecified Apollo cloud platforms and exfiltrated personal information belonging to an undisclosed number of individuals connected to the firm. Apollo's forensic investigation determined on August 12 that the stolen records include full names, dates of birth, contact information, home addresses, and Social Security numbers. The firm disclosed the incident publicly on August 21.
The notice was signed by Matthew Breitfelder, Apollo's Global Head of Human Capital. Apollo's language characterizes the event as "unauthorized access to certain cloud platforms" — accurate but structurally undersized for what actually happened. This was not an incidental system-level intrusion. This was the successful theft of authenticated sessions from privileged users at a firm managing roughly $700 billion in assets.
Key facts:
- Access dates: July 6 to July 10, 2026
- Discovery / forensic determination: August 12, 2026 (33 days after last access)
- Public disclosure: August 21, 2026 (9 days after forensic determination)
- Data compromised: names, dates of birth, home addresses, contact information, Social Security numbers
- Signatory: Matthew Breitfelder, Global Head of Human Capital
Attack Vector Detail
Apollo has confirmed the intrusion was executed through "advanced social engineering rather than software vulnerability exploits." The specific technique: vishing — voice phishing calls placed to Apollo employees by attackers posing as internal IT helpdesk staff.
The callers walked victims through what appeared to be routine access support and captured credentials and multi-factor authentication codes via lookalike sign-in portals. The stolen sessions were then used to reach the cloud platforms directly, from the attacker's browser.
Why vishing works against MFA: Multi-factor authentication is designed to defeat credential theft, not to defeat authenticated sessions. When an employee enters a password and completes an MFA challenge on a lookalike portal, the attacker's proxy relays both to the real identity provider in real time, receives the authenticated session token in return, and uses that token to access cloud resources as the user. The MFA challenge was successfully completed. From the identity provider's perspective, the login is normal. There is nothing to detect at the authentication layer.
Threat actor(s): ShinyHunters-adjacent — per Google GTIG tracking, the operators go by Falcon, Helix, Pink, Redact, and Silent Ransom. The same crew has been publicly credited with the 2026 Canvas / Instructure breach, the RingCentral 1.6M record leak, the Aura consumer identity-protection breach, and the broader wave targeting Wall Street financial institutions.
For the full technical anatomy of the attack chain and the hardening playbook that closes the exposure, see the companion technical analysis: How a Phone Call Beats MFA: Anatomy of the Wall Street Vishing Wave.
Breach Pattern Timeline
The August 2026 vishing wave hitting Wall Street is the latest evolution of a threat actor ecosystem that has been targeting corporate cloud environments for years. Selected milestones:
- 2024 — Snowflake customer wave: Attackers exploit unrotated Snowflake credentials to exfiltrate data from hundreds of customer tenants.
- March 2026 — Aura breach: ~900K records exfiltrated via vishing against an identity-protection company employee. Widely covered for the irony.
- April–May 2026 — Canvas / Instructure: ShinyHunters compromises Canvas LMS. 275M user records held for ransom. Cloudskope's coverage was cited by Brian Krebs.
- July 2026 — RingCentral: Sophisticated social engineering campaign; 1.6M customer records eventually leaked after ransom demand rejected.
- July 6–10, 2026 — Apollo Global Management: Vishing successfully captures cloud platform access. Discovered mid-August, disclosed August 21.
- August 2026 (ongoing) — Wall Street wave: Blackstone, Bridgewater, Bain Capital identified by Google GTIG as targeted; specific outcomes not publicly disclosed at this time.
The through-line is not a single crew. It is a pattern of tradecraft — voice phishing, helpdesk impersonation, session token capture — that has been demonstrated repeatedly across sectors and refined against successively higher-value targets. Wall Street is the current apex.
Executive Lessons
Six questions every senior leader should answer about their own environment this week:
- Have we had verification calls to our own IT helpdesk that we cannot definitively attribute to a real employee?
- When was the last time an Azure AD / Entra ID review confirmed no anomalous device registrations, no unfamiliar OAuth grants, and no unexpected mailbox rules across executive accounts?
- Do our helpdesk agents have any procedure for verifying caller identity that is meaningfully harder to defeat than knowing a name, a start date, and a department?
- What data resides in the cloud platforms our employees log into daily — and what is our reset radius when a single session token is stolen?
- What does our attestation to insurers, auditors, and counterparties say about identity controls — and would we defend that language in a deposition six months from now?
- Where would we accept a bounded, fixed-fee engagement to find and remediate what we don't want to hear about, before someone else finds it and publishes it?
Private Equity Implications
Wall Street is the target now. The historic pattern was that PE-backed portfolio companies were the exposed layer — the general partners themselves were assumed to be relatively hardened. That assumption is no longer defensible.
Apollo confirmed. Blackstone, Bridgewater, and Bain Capital were actively targeted per Google GTIG. Insight Partners was breached earlier this year (12,600+ affected, including limited partners, portfolio company data, and banking records). The trend line is that the crews following the money have decided the wealth layer is worth targeting directly.
Compounding the exposure: Bain Capital — one of the firms Google identified in the vishing campaign — is also a named defendant in the March 2026 California federal ruling allowing data breach claims against a PE firm to proceed directly for a portfolio company's cyber failure (PowerSchool). Bain is now defending on two fronts: extortion crews at the front door, plaintiffs' bar at the back door.
Cloudskope's full synthesis of the two-front war on PE cyber: Apollo. Blackstone. Bridgewater. Bain. The Same Crew Is Vishing Them All — And Bain Is Already a Defendant.
Every PE deal team's operating partner and general counsel should be running:
- A same-quarter compromise assessment of the firm's own M365 / Entra ID posture
- A review of helpdesk verification procedures against the current attacker tradecraft
- A read of LP disclosures and insurance attestations against what a Bain-style operational-control theory could argue
- A refresh of cyber diligence posture across the active portfolio, with particular focus on identity fabric hygiene
How Cloudskope Can Help
Cloudskope built SARTUS™ specifically to answer the question "are we already compromised" in a bounded window. Part 1 assessment reviews M365 and Azure AD identity posture, credential exposure, cloud configuration drift, and active-compromise indicators over three days. Part 2 remediates what can be closed within the assessment window. Findings that cannot be closed inside six days land in the consolidated risk register with a documented path and, where requested, a separate quote. Fixed fee, defined scope, executive readout on the following week.
Book a strategy session to talk through the fit for your environment.
.png)