Apollo Global Management confirmed that attackers used social engineering to get into its cloud environment between July 6 and July 10, and its Aug. 12 disclosure says the exposed data included names, birth dates, contact details, home addresses, and Social Security numbers. CyberScoop says Apollo is the first victim to formally confirm personal data exposure in the wider July campaign against financial and private-equity firms.
The intrusion did not require breaking a cloud provider. The attackers persuaded employees into giving up the login and multi-factor authentication path, then used that access to reach cloud systems as if they were staff, which is why the stolen data sits in the identity and HR layer rather than in a mailbox or endpoint.
For firms that keep employee or portfolio-company data behind cloud identity and help-desk workflows, the lasting risk is identity theft and downstream fraud against real people. Google has tied the broader wave to BlackFile, but Apollo’s filing is the clearest sign yet that the campaign is producing operationally significant breaches, not just intrusion attempts.