What happened: Apollo Global Management confirmed in a notice filed with the California Attorney General that attackers accessed portions of its cloud environment between July 6 and July 10, 2026, using a social engineering attack, and that it discovered the exposure on August 12 before disclosing publicly on August 21. The exposed data includes names, dates of birth, contact information, home addresses, and Social Security numbers. Apollo said it has found no evidence the data was posted online or used for fraud, and is offering affected individuals credit monitoring.

Why it matters: Apollo is not an isolated case. Google has attributed a broader campaign targeting financial institutions, private equity firms, law firms, and rating agencies to a group operating under the names Falcon, Helix, Pink, and Redact, which relies on social engineering calls to IT help desks rather than software exploits. Apollo becoming the first firm in this wave to formally disclose puts a name and a regulatory filing behind a pattern researchers had only described in general terms until now.

The original insight: the entry point here was a phone call, not a vulnerability. CyberTech has tracked a steady run of cloud platform breaches and smaller scale customer data exposures this month, and the common thread across most of them is not a novel technical flaw but a help desk process that trusted the wrong caller. Security budgets that lean entirely on patch management and endpoint tooling will keep missing this category. It needs the same rigor applied to identity: verified callback procedures, hardware bound MFA that cannot be socially engineered away, and help desk staff trained specifically on impersonation scripts, not just generic phishing awareness.

Source: California Department of Justice