Apollo has confirmed unauthorised access to personal data after a cyber attack hit its cloud platforms in July 2026.
According to Financial Times, Apollo stated that it had notified law enforcement of the incident and was continuing to assess its scope.
In a letter posted to the California attorney general's website, Apollo said the exposed information included names, dates of birth, home addresses, and social security numbers. The company attributed the breach to a social engineering incident, a method in which attackers manipulate individuals into granting access to secure systems, typically through phishing emails or fraudulent phone calls. Apollo did not disclose further details of how the attack was carried out.
The letter, dated Friday and addressed to an individual affected by the breach, stated that there was no evidence the exposed personal information had been publicly posted or used for identity theft or fraud at the time of writing. Apollo did not respond to a request for comment on the incident.
Part of a wider pattern of attacks on financial firms
The disclosure follows attacks on several hedge funds, including Point72, Citadel, and Millennium Management, which were reported earlier in the same month. The recurrence of such incidents across large financial institutions reflects the sector's exposure to cyber threats, given the scale of personal, financial, and operational data these firms hold.
It remains unclear whether artificial intelligence played a role in the attack on Apollo. However, the incident comes amid broader concern among governments and financial institutions about the potential for AI tools to lower the barrier for cyber criminals and state-linked groups seeking to target sensitive systems.
Regulatory and industry context
In April 2026, US Treasury Secretary Scott Bessent met with leaders of several large US banks to discuss cyber risks associated with an advanced AI model developed by Anthropic, which reportedly demonstrated an ability to detect cybersecurity vulnerabilities. The following month, the Trump administration introduced export controls on some of Anthropic's advanced models after identifying a method for bypassing safety measures; the restrictions were lifted by the end of June 2026.
The International Monetary Fund (IMF) also raised concerns in May 2026, noting that the capacity of advanced AI models to expose weaknesses in lenders' cyber defences could elevate cyber risk to a potential macro-financial shock, particularly where discovery and exploitation of vulnerabilities can scale rapidly.
The Apollo breach adds to a growing list of cybersecurity incidents affecting major financial institutions in 2026, reinforcing calls from regulators and international bodies for stronger oversight of cyber risk as AI capabilities continue to evolve.