Security1 distinct publisher2 min readUpdated
The firm says intruders reached its cloud platforms in July and took names, birth dates and Social Security numbers. Google attributes the campaign to BlackFile, a Com affiliate with four extortion brands.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
The number the filing does not contain is a detection date. Apollo puts the unauthorized access to its cloud platforms between July 6 and July 10 [2], and says it worked out on August 12 which categories of personal data had been taken [5]. That is 33 days from the last day of access to the determination [1], but Apollo did not say when or how it became aware of the intrusion, and it did not respond to a request for comment [3]. So the 33 days could be forensic reconstruction after a same-week catch, or most of a month of quiet before anyone looked.
Who signed the notice is also informative. It went out under the name of Matthew Breitfelder, Apollo's global head of human capital, and describes law enforcement notification, outside forensic experts, tightened protocols and an investigation [6]. Apollo has not said whose records these are, or how many people are involved [7]. A human capital byline on a notice listing dates of birth and Social Security numbers points toward people on a payroll rather than fund investors, though the company does not say that either.
Google's attribution supplies the name Apollo left out: BlackFile, affiliated with The Com, which recently split its extortion operations into four brands running on shared infrastructure, Redact, Pink, Helix and Falcon [8]. The method underneath the branding is a phone call. The group impersonates IT support in voice-phishing operations and moves from one sector to the next [11], having already worked through healthcare, technology, transportation, logistics, wholesale, and retail and hospitality this year [10]. That sequence is better read as a list of industries whose help desks will act on a convincing caller than as a ranking of whose data is worth having. Private equity, law firms, rating agencies and medical technology companies were the current stop [4].
Home addresses were in Apollo's compromised set [5], and Google has said some of this group's recent victims received threatening messages and faced escalation including swatting, a tactic used across several subsets of The Com [13]. That pairing is not what a credit monitoring enrolment is designed to answer, and it is the part of the filing that has a shelf life longer than the investigation.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Apollo Global Management confirmed Friday that it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month.
Attackers gained unauthorized access to some of Apollo's cloud platforms between July 6 and July 10, according to a data breach notification the company filed in California.
Apollo did not say when or how it became aware of the intrusion, and did not respond to a request for comment.
Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies.
Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised.
The disclosure notice was written by Matthew Breitfelder, Apollo's global head of human capital, who said the company promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced its security protocols and launched an investigation.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary filing, single outlet, key figures missing
The core facts rest on a document Apollo itself filed in California plus a named executive's disclosure statement, which is strong primary evidence for the intrusion window and the data categories taken. It is weakened by being reported by one publisher only, by Apollo declining to comment, and by the absence of a victim count, detection timeline, or any independent confirmation of the containment and 'no misuse' assertions. Attribution to BlackFile is second-hand from Google research rather than from Apollo or law enforcement.
Confirmed campaign across sectors, one formal victim disclosure
Real-world incidence is documented rather than speculative: one named victim has formally disclosed personal-data compromise, peer firms were reportedly targeted with the same infrastructure, and the group has hit organizations across at least six other industries this year. The score is held mid-range because the number of confirmed compromises remains one, affected-individual counts are undisclosed, and it is explicitly unclear whether Blackstone or Bain Capital were breached.
Slightly understated relative to exposure
The reporting is restrained and largely tracks the filing: no dollar loss is asserted against Apollo, and Apollo's own 'no evidence of misuse' line is carried without embellishment. If anything the story is understated - Social Security numbers from a $1.05 trillion manager are exposed with no disclosed victim count, no confirmation of whether extortion was attempted, and a group known to escalate to swatting, all of which imply more downside than the framing conveys.
Mandated disclosure framed by the victim; vendor attribution
The primary document is a legally compelled breach notice authored by Apollo's head of human capital, which has an obvious interest in emphasizing prompt law-enforcement contact, outside experts and enhanced protocols while omitting detection timing and victim counts. Threat-group naming and the four-brand taxonomy come from Google, a vendor with commercial incentive in attribution branding, and the outlet is extending its own prior reporting on the wave. None of these incentives are hidden, which keeps the score moderate rather than high.
Solid primary document, single-publisher cluster
Confidence is above midpoint because the load-bearing facts come from a regulatory filing with specific dates and data fields, and the tradecraft and attribution align with previously published research. It is capped by total reliance on one publisher, an unresponsive company, unquantified victim scope, and an investigation that is still described as ongoing.
invest
Nvidia's $500bn GPU pool makes the seller the guarantor of its own demand1 distinct publisher
leadership
Anthropic's services venture buys its way into the implementation layer1 distinct publisher
build
Anthropic's $1.5B Ode bets model value sits with embedded engineers, not API keys1 distinct publisher
invest
Nvidia's spotless balance sheet has about $30bn parked just outside it1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 21, 2026