BREACH2026-08-26T08:02:31.822854+00:005 min read

Your SSN Was Inside a $1 Trillion Firm. Hackers Got It With a Phone Call.

Apollo Global Management — a $1 trillion Wall Street giant — exposed Social Security numbers and home addresses after hackers tricked employees over the phone.

Your SSN Was Inside a $1 Trillion Firm. Hackers Got It With a Phone Call.

You Never Had to Sign Up for This to Happen to You

Apollo Global Management manages over $1 trillion in assets. You have probably never done business with them directly. That does not matter. If you worked for a company they invested in, managed funds alongside them, or simply appeared in a document that crossed their systems, your data was there. Your name, your date of birth, your home address, your Social Security number.

Between July 6 and July 10, 2026, hackers got into Apollo's cloud platforms. They did not use malware. They did not exploit a software vulnerability. They picked up a phone.

How Does a Phone Call Beat a Trillion-Dollar Company?

Social engineering is the art of tricking a person rather than a machine. In Apollo's case, attackers called employees and impersonated trusted parties. Colleagues, vendors, IT support, service providers. They said the right things. They had enough context to sound legitimate. And somewhere along the way, an employee handed over access.

This is not a failure of technology. It is a failure of trust. Human beings are wired to help, to defer to authority, and to avoid conflict. Attackers exploit all three. No firewall blocks a convincing voice. No antivirus catches a plausible story.

The technique is called vishing, voice phishing. It works at every level of the corporate ladder, from the help desk to the C-suite. Attackers do research first. LinkedIn profiles, press releases, old breach data. They know your colleague's name. They know the org chart. They know just enough to make you believe them.

The access they gained exposed names, dates of birth, home addresses, contact information, and Social Security numbers. Financial account and investment data was not compromised, according to Apollo.

The Numbers: What We Know

Apollo began notifying affected individuals on August 21, 2026. The total number of people impacted has not been publicly disclosed.

That silence is telling. When companies withhold the headcount, the number is usually large enough to be embarrassing. What we know is that the combination of data exposed, SSNs, birthdates, home addresses, is precisely what identity thieves need. They use it to open credit cards, file fraudulent tax returns, and take out loans in your name.

Apollo is offering 24 months of free credit monitoring and identity protection through Cyberscout, a TransUnion company, to affected individuals. If you received a notification, take them up on it. Do not assume the monitoring is enough on its own.

What to Do Right Now

Whether or not you received a notification from Apollo, this breach is a reminder that your personal data lives in more places than you can track. Take these steps today.

  1. Freeze your credit. Contact all three bureaus, Equifax, Experian, and TransUnion, and request a freeze. It is free. It blocks new credit lines from opening in your name without your explicit approval. A credit freeze is the single highest-impact action you can take after an SSN exposure.

  2. Enroll in the free monitoring if you were notified. Apollo is offering 24 months through Cyberscout. Accept it. Then set a reminder to find your own monitoring when those 24 months end.

  3. Pull your credit reports. You can get free reports from all three bureaus at annualcreditreport.com. Look for accounts you did not open, addresses you do not recognize, or inquiries you did not authorize.

  4. Turn on two-factor authentication everywhere that matters. Email, banking, investment accounts, retirement accounts. Use an authenticator app rather than SMS, because SIM-swapping is a real follow-on attack when SSNs are in the wild.

  5. Consider a data removal service. Data brokers sell your personal information, and their databases fuel the research attackers do before making a vishing call. Services like DeleteMe or Kanary can systematically opt you out. They reduce your attack surface over time.

  6. Watch for follow-on scams targeting you personally. Once your data is in criminal hands, you may become a target. Callers claiming to be your bank, the IRS, or a fraud department. Emails with urgent account warnings. Anything that demands you act fast deserves immediate skepticism.

What If You Were Not Notified?

Act as if you were. Notification lists capture only the people a company knows were affected at the time of disclosure. Breach investigations expand. Scope changes. Companies frequently undercount.

If you have any connection to Apollo, through employment, investment, or a business partnership, assume your data was exposed. If you have no connection at all, a credit freeze still costs nothing and permanently blocks a category of fraud.

The Uncomfortable Truth About Where Your Data Lives

Your most sensitive personal data sits inside institutions you have never heard of and did not choose. Private equity firms hold data on thousands of companies and their employees. Insurance carriers aggregate policyholder records across industries. Data brokers collect everything they can from public records and purchase histories.

You cannot opt out of all of it. What you can control is how hard you make it for someone to weaponize that data against you. A credit freeze makes a stolen SSN nearly useless for opening new accounts. Strong authentication makes a stolen password nearly useless for account takeover.

The hackers did not need a single line of code. They needed a phone and a convincing story. An employee at a company you never interacted with received a call on a Tuesday afternoon that sounded just credible enough. That is the entire attack chain.

Your data was a bystander.


Do this now:

  • Freeze your credit at Equifax, Experian, and TransUnion, it is free
  • If Apollo notified you, enroll in the Cyberscout monitoring immediately
  • Pull your free credit reports at annualcreditreport.com and scan for anything unfamiliar
  • Enable 2FA via an authenticator app on your email, bank, and investment accounts
  • Look into a data removal service to shrink your broker footprint before the next breach

Sources

WHAT TO DO RIGHT NOW
  1. 01Go to haveibeenpwned.com and check your email address right now
  2. 02Change your password on the breached service — use a unique password you do not use anywhere else
  3. 03Enable two-factor authentication (2FA) on that account if available
  4. 04Monitor your bank statements and credit report for unusual activity over the next 90 days
RECOMMENDED PROTECTIONAFFILIATE

AuraAll-in-one identity theft and scam protection with real-time alerts

Get Aura
Check Have I Been Pwned →
// FAQ

Common Questions About Breach

What should I do immediately after a data breach?

Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.

How long do companies have to notify me after a data breach?

In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.

Should I freeze my credit after a data breach?

Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.

// RELATED

More in breach

153 Million Driver's Licenses Are Being Sold on the Dark Web Right Now
2026-09-08T08:03:13.929805+00:00 · 5 min read
Hasbro Kept Quiet for 5 Months While Hackers Had Workers' SSNs and Bank Info
2026-09-05T08:04:13.891376+00:00 · 5 min read
Your Hospital Records Could Go Public: Ransomware Gang Hit 27 US Facilities
2026-09-03T08:04:32.922878+00:00 · 5 min read

Stay invisible. Follow @hack_decoded