The Apollo Global Management breach: Social Security numbers, and no count
Someone talked their way into Apollo’s cloud systems in July. Letters started going out on 21 August, and the data listed in them includes Social Security numbers. Here is what the notice actually says, what it leaves out, and what is worth doing this week.
Attackers reached Apollo Global Management’s cloud systems between 6 and 10 July 2026 by tricking employees into handing over their sign-in codes. Apollo established on 12 August that personal data was involved and began notifying people on 21 August. The exposed fields are names, dates of birth, contact details, home addresses and Social Security numbers; the company says investment and financial account data was not involved, and that it has seen no evidence of misuse so far. No total has been published. Because a Social Security number cannot be reissued, the step that matters most is freezing your credit file at all three bureaus, on top of the 24 months of monitoring the letter offers.
What the notice says, point by point
Everything below comes from Apollo’s notification, its filing with the California attorney general, and the reporting that followed between 21 and 24 August 2026. Where the company has not said something, the row says so rather than filling the gap.
| Question | What Apollo states | What that means |
|---|---|---|
| When the intruders were inside | 6 to 10 July 2026 | Apollo’s own notice gives that window. The company says the way in was social engineering rather than a software flaw: staff were talked into entering their passwords and one-time codes on pages built to look like the real sign-in. |
| What they reached | “Certain cloud platforms” | Apollo has not named the systems. It does say the incident did not touch investment or financial account data, which is the question most people ask first when an asset manager is the one writing. |
| What was in the files | Names, dates of birth, contact details, home addresses, Social Security numbers | This list comes from the notification letter itself. A Social Security number alongside a date of birth is the combination that matters here: neither can be reissued the way a password can. |
| How many people | Not disclosed | Apollo has not published a figure. The filing with the California attorney general tells you only that at least 500 California residents are involved, because that is the number at which the filing becomes mandatory. The nationwide total is unknown. |
| Whose records | Not specified | The notice does not say whether the people written to are employees, former staff, job applicants, investors or personnel at portfolio companies. Reporters who asked did not get an answer either. |
| What Apollo is offering | 24 months of credit monitoring and identity protection | Provided through Cyberscout, a TransUnion company, per the notification. Monitoring reports credit activity after it happens; it does not block anything on its own. |
| Misuse so far | None found | As of the letters going out on 21 August, Apollo said it had no evidence the data had been published or used for fraud. That is a statement about what has been observed, not a guarantee about what happens next. |
Sources: Apollo’s notification letter and its California attorney-general filing, plus reporting by CyberScoop, The Register, SecurityWeek, Cybernews and PYMNTS, 21–24 August 2026.
1. What happened, in order
Between 6 and 10 July 2026, someone got into cloud systems belonging to Apollo Global Management, one of the largest alternative asset managers in the world. The way in was not a software flaw. According to the company’s own account, employees were talked into entering their credentials and one-time codes on convincing fake sign-in pages, the same phone-and-webpage routine that has been working against large companies all year. Apollo says its investigation established on 12 August that personal data had actually been involved, and notification letters went out from Friday 21 August. The filing with the California attorney general, and the reporting that followed on 21 to 24 August, are where everything public about this comes from. Apollo has published no separate statement of its own beyond the notice.
2. Why a letter arrives from a company you never signed up with
Apollo is not a consumer service. Nobody has an Apollo account the way they have a bank or a shopping account, which is what makes this letter confusing to receive. The records a firm like this holds on individuals come from being an employer, a former employer, a recruiter, and an owner of other businesses: tax and payroll paperwork, onboarding and background files, and administrative records for people at the companies in its portfolio. Apollo has not said which of those groups the notifications went to, and reporters who asked did not get an answer. So the letter tells you your details were in a file that was taken, and not much about why they were there. That question is worth putting to the company in writing.
3. What was taken, and why this list is worse than a password leak
The notification lists names, dates of birth, contact information, home addresses and Social Security numbers. Apollo states that investment and financial account information was not involved. That is genuinely the better outcome for anyone with money there, but it does not make the rest harmless, because the fields that did come out are the permanent ones. You can change a password in a minute and a card number in a week. A Social Security number is issued once, a date of birth never moves, and together with a current address they are most of what a lender uses to satisfy itself that an application is really you. That is the exposure here, and it does not decay on its own.
4. What is worth doing this week
Freeze your credit file at all three bureaus first: Equifax, Experian and TransUnion, each separately, online, for free. A freeze blocks a new account being opened in your name, which is the thing this particular data set enables. Then take the 24 months of monitoring in the letter, because it is paid for and catches what a freeze does not, but treat it as the second layer rather than the answer. Two more are worth the time if a Social Security number of yours is in circulation: request an Identity Protection PIN from the IRS, which stops someone filing a tax return in your name, and check your Social Security earnings record for employment you did not do. Keep the letter and the date it arrived. If anything comes of this later, that paperwork is what makes a claim or a complaint easy.
5. Telling the real notice from the wave of fakes
Every breach that reaches the news is followed within days by messages pretending to be the notification. This one has the ingredients that make them work: a household name, Social Security numbers in the headline, and a lot of people who cannot immediately tell whether they are affected. Apollo notified by post from 21 August. A genuine notice explains what happened and how to enrol in the monitoring it offers; it does not ask you to confirm your Social Security number, and it has no reason to need your bank details. Judge any message by how it reached you rather than by how it reads, because the wording and the logo are the easy part to copy. If you want to verify something, look the company up yourself instead of using a number or a link the message supplied. Our guide to breach notification letters goes through what a real one contains, line by line.
6. The lawyer emails, and what they actually mean
Within three days of the disclosure, law firms were publishing investigations into the breach and sites were collecting names of affected people. It is worth knowing what that stage is. A firm announcing an investigation is looking for clients; it is not a filed case, not a certified class, and certainly not money waiting to be claimed. If a case is filed and eventually settles, the notice comes from a court-appointed administrator, arrives by post, and claiming costs nothing. That is a process measured in years. Until then, treat any request for a fee or for your Social Security number in exchange for “registering your claim” as the scam it is. If you want to see what a real payout stage looks like, our list of settlements currently taking claims is checked against the official administrator sites.
7. The part that outlives this incident
A breach notice closes a file at the company and changes nothing about what is already published about you. The address and phone number that made the stolen record useful are sold openly by people-search and data-broker sites, and that is where the next set of target lists gets built no matter who is breached next. Getting those listings removed is the one step here whose effect lasts past the news cycle, and it needs repeating rather than doing once, because brokers rebuild profiles from public records within weeks. For the general version of the response, our post-breach guide covers it in seven steps.
The address in that file is also for sale
A stolen Social Security number becomes usable when it sits next to a current address and phone number, and those are published by 499 broker and people-search sites whether or not anyone breaches anything. PersProtect finds where you are listed, files the removals and keeps checking that they stay down. The scan is free.
Check my exposure — free →The Apollo breach, answered
Why would Apollo Global Management have my Social Security number?
Because you do not need to be a customer to be in a company’s files. An asset manager holds tax and payroll paperwork for current and former staff, background and onboarding records for people it hired or considered hiring, and administrative details for individuals connected to the businesses it owns. Apollo has not said which of those groups the letters went to, so the honest answer is that a letter arriving does not tell you much about why your record was there. If one arrives and you genuinely cannot place the connection, ask them in writing what category of record yours came from.
Was my investment account or my money touched?
Apollo says no. Its notice states that investment and financial account information was not involved, and nothing in the reporting on 21 to 24 August contradicts that. What did come out is the identity paperwork: name, date of birth, home address, contact details and Social Security number. That combination is not used to move money out of an existing account. It is used to open new credit somewhere else in your name, which is why the response below is about your credit file rather than about your Apollo relationship.
How many people were affected?
Nobody outside the company knows. Apollo has not published a number, and the California attorney-general filing only proves the count passed 500 residents in that one state, since that is the threshold that forces a public filing. For a firm of Apollo’s size the real figure could be far higher, and it may go up: the notice describes an investigation that reached its conclusion about the data on 12 August, which is the point at which counting usually begins rather than ends.
I got an email saying I was in the Apollo breach. Is it real?
Treat it as suspicious. Apollo notified people by letter starting 21 August, and news coverage of a breach with Social Security numbers in it is exactly what a phishing wave feeds on. The tell is never the wording or the logo, both of which are easy. It is the route: a genuine notice does not need you to click anything to “verify whether you are affected”, and no legitimate notification asks for your Social Security number back. If you want to check something in an email, do not use its links or its phone number — go to the company’s own site yourself.
What is the single most useful thing to do?
Freeze your credit file at Equifax, Experian and TransUnion. It is free, it takes about ten minutes per bureau online, and unlike monitoring it stops a new account being opened rather than telling you afterwards that one was. Take the 24 months of monitoring Apollo is offering as well, because it costs you nothing and catches what slips through, but do not let it stand in for the freeze. A freeze can be lifted temporarily whenever you apply for credit yourself.
Should I join a class action?
There is nothing to join yet. Several law firms announced investigations in the days after the disclosure, and an investigation is a firm looking for people to represent, not a case a court has certified and not a settlement paying anything out. If a case is filed and eventually settles, notice reaches you through the court-appointed administrator, usually by post, and claiming is free. Anything arriving now that asks for a fee, your bank details or your Social Security number to “register your claim” is a scam built on the news.
Is this connected to the other financial-sector attacks in the news?
Press reporting places it in the same campaign. Security researchers cited by CyberScoop and The Register have tied a run of intrusions at financial firms to one extortion crew and its affiliates, and named Blackstone, Bridgewater and Bain Capital as having been targeted with the same infrastructure — targeted being the operative word, since it is not established that any of them were compromised. Apollo is described as the first in that wave to formally disclose that personal data was taken. Expect more disclosures rather than fewer over the next few weeks.
My data was already leaked in something else. Does one more matter?
For passwords, no, one more copy of an old leak changes little. For this combination it does. A Social Security number and a date of birth do not expire and cannot be rotated, so each new file that pairs them with a current address and phone number makes it easier for someone to answer the identity questions a bank or a lender asks. The exposure accumulates, and the only part of it you can still act on is what is published about you now.
You cannot reissue a Social Security number
You can take down the address, phone number and relatives that make it usable. See which sites publish yours right now — free, in about a minute.
Run my free exposure scan →