{"id":36895,"date":"2026-08-28T10:38:29","date_gmt":"2026-08-28T15:38:29","guid":{"rendered":"https:\/\/itdconsulting.com\/?p=36895"},"modified":"2026-08-28T10:38:29","modified_gmt":"2026-08-28T15:38:29","slug":"apollo-global-ciberamenaza","status":"publish","type":"post","link":"https:\/\/itdconsulting.com\/en\/noticias\/apollo-global-ciberamenaza\/","title":{"rendered":"Apollo Global and the New Threat to the Financial Sector"},"content":{"rendered":"<p class=\"wp-block-paragraph\">Apollo Global Management, one of the world\u2019s largest alternative asset management firms, confirmed in August 2026 that it had suffered a security breach after unauthorized individuals managed to gain access to certain cloud platforms of the company. The incident occurred between July 6 and 10 and, according to the investigation subsequently conducted, may have exposed personal information such as names, dates of birth, contact information, home addresses, and U.S. Social Security numbers. The company notified the authorities about the incident and hired external cybersecurity and forensic analysis specialists to determine how the intrusion occurred and what its scope was. The case is particularly relevant because it occurred amid a broader campaign of attacks targeting U.S. financial companies through social engineering techniques.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The situation demonstrates that threats against large companies no longer necessarily depend on sophisticated malware or unknown vulnerabilities in their systems. In many cases, criminals attempt to exploit something much more difficult to control: human behavior. A phone call, a convincing email, or an apparently routine request may be enough to get an employee to hand over information that allows access to protected systems. The Apollo incident thus serves as an example of an important transformation in corporate cybersecurity, where employees\u2019 digital identities have become one of the main targets for attackers.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Attack Against Apollo Global Management<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Apollo discovered that unauthorized individuals had gained access to certain cloud platforms of the company for several days in July. After detecting the incident, Apollo launched an investigation to reconstruct the activities carried out by the intruders and determine what information may have been accessed or extracted. Apollo\u2019s investigation identified potentially compromised personal data, including names, dates of birth, contact information, home addresses, and Social Security numbers. In addition, Apollo reported the incident to the authorities and turned to external specialists to conduct technical and forensic analyses that would help clarify what had happened.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apollo has not made all the details of the intrusion public, nor has it definitively attributed the attack to a specific group. Nor has a definitive number of people affected by the exposure of information been publicly established. Apollo stated that, as of the time of its communication, it had found no evidence that the data had been published or used to commit fraud or identity theft. As a preventive measure, Apollo provided affected individuals with free identity protection and credit monitoring services.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"765\" src=\"https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-1-1024x765.webp\" alt=\"ITD Consulting y Apollo Global: la nueva amenaza para el sector financiero actual\" class=\"wp-image-36896\" srcset=\"https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-1-1024x765.webp 1024w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-1-300x224.webp 300w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-1-768x573.webp 768w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-1-16x12.webp 16w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-1.webp 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The fact that no immediate fraudulent use of the data has been detected is relevant, but it does not mean that the risk disappears for Apollo or for the affected individuals. A personal information breach can have consequences for years because certain data cannot be easily changed. A compromised password can be changed quickly, while a name, date of birth, or Social Security number remains linked to the same person, regardless of whether the incident occurred at Apollo. Therefore, a security breach such as the one suffered by Apollo can create risks long after the attackers have lost access to the original systems.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>A Campaign Against Financial Companies<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Apollo incident occurred as part of a broader campaign targeting financial companies and large U.S. companies. Cybersecurity researchers detected numerous malicious websites designed to deceive employees of major organizations and obtain their credentials, a threat that also focused on Apollo and other major firms in the sector. The attackers focused their efforts particularly on investment companies, private equity, and other sectors related to finance, where companies such as Apollo handle large amounts of sensitive information. This strategy demonstrates that criminals are systematically seeking organizations such as Apollo that can provide valuable information or have the financial capacity to become extortion targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The financial sector is especially attractive because of the amount and sensitivity of the information it holds. Investment and asset management firms, such as Apollo, may store data on clients, employees, investors, suppliers, and business partners, in addition to corporate and financial documents. An intrusion against a company of this type may allow attackers to obtain information useful for committing fraud or preparing subsequent attacks against other organizations, making a company such as Apollo an especially valuable target. At the same time, an interruption of the services of a financial company can have significant economic consequences, which increases the attractiveness of companies such as Apollo as potential extortion targets.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attacks observed during this campaign also show that criminals do not necessarily need to directly overcome the technological defenses of a company such as Apollo. Instead of attacking a server or exploiting a software vulnerability, they may first attempt to obtain the credentials of an Apollo employee and subsequently use them to access protected systems. If they manage to get that person to reveal their password, approve an access request, or enter their information on a fake page, they can enter using an apparently legitimate identity. This technique can be particularly difficult to detect because security tools are designed to recognize suspicious access, while an authentic Apollo account may appear normal even when it is being used by an attacker.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Social Engineering as a Weapon<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Social engineering consists of manipulating a person into performing an action that benefits the attacker. The method can take different forms, from fake emails to text messages, fraudulent websites, or phone calls, and these techniques represent a particularly relevant threat to companies such as Apollo. In campaigns targeting financial companies, criminals have especially resorted to impersonating employees from technology or support departments. The intention is to create a situation that is sufficiently credible for the victim to consider it normal to provide certain information or follow instructions apparently related to Apollo\u2019s systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A phone call can be particularly effective because it creates a direct interaction. The supposed technician may claim that there is a problem with the Apollo employee\u2019s account, that suspicious activity has been detected, or that a security check needs to be carried out. The sense of urgency may reduce the amount of time the victim spends verifying the identity of the person calling. If the attacker also previously knows some information about Apollo, its employees, or its systems, the conversation may seem much more authentic and increase the chances that the employee will trust the request.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The fundamental problem is that security systems can interpret as legitimate an action that the user themselves has authorized under deception. A correct password remains correct even if it was obtained through a fraudulent call targeting an Apollo employee. Similarly, an authentication code may be valid even though the person using it is not actually who they claim to be. Social engineering precisely attempts to exploit that trust in order to turn the tools designed to protect Apollo into instruments that facilitate the attacker\u2019s access.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Personal Data and Its Consequences<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The information potentially exposed in the Apollo case is particularly important because of its personal nature. A name and an email address can facilitate phishing campaigns, but the combination of several pieces of data allows much more complete profiles of victims associated with Apollo to be built. The inclusion of dates of birth, home addresses, and Social Security numbers increases the potential usefulness of the data for certain forms of identity impersonation, especially when that information comes from a large financial organization. The risk is greater when the data comes from a business source such as Apollo that criminals may consider reliable and that concentrates information on numerous employees and other people connected to the company.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One of the difficulties of these breaches is that personal information cannot be recovered in the same way as a physical object. Apollo can delete a compromised account, change a password, or block a device, but it cannot absolutely erase data that may already have been copied by an attacker. The information obtained during an intrusion against Apollo could remain stored and be used at another time or combined with data obtained from other breaches. Therefore, Apollo\u2019s response to a breach must consider not only the immediate recovery of its systems, but also the protection of the people whose data may have been exposed.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2-1024x576.webp\" alt=\"Apollo e ITD Consulting: riesgo para el sector financiero ante la nueva amenaza global\" class=\"wp-image-36897\" srcset=\"https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2-1024x576.webp 1024w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2-300x169.webp 300w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2-768x432.webp 768w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2-1536x864.webp 1536w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2-18x10.webp 18w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-2.webp 1600w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The credit monitoring and identity protection services offered by Apollo can help detect certain signs of fraud. However, these tools do not eliminate all risks and require victims to remain constantly vigilant after the Apollo incident. Those affected should pay particular attention to unexpected communications, requests for personal information, and financial transactions they do not recognize, even if they apparently come from legitimate companies. The objective is to reduce the chances that a breach related to Apollo will later turn into a case of fraud or identity theft.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Cloud and the New Corporate Perimeter<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The fact that the unauthorized access related to Apollo affected cloud platforms is also significant. Modern companies, including Apollo, increasingly depend on cloud services to store documents, run applications, and allow their employees to work from different locations. This transformation offers important productivity and flexibility advantages, but it also changes the way Apollo and other organizations must approach their security. A company\u2019s perimeter is no longer limited to its offices and internal servers, but includes user accounts, devices, applications, and connected services.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A legitimate Apollo account that has been compromised can represent a considerable risk if it has broad permissions. The attacker may attempt to use that identity to access information, move toward other resources, or maintain access for as long as possible without arousing suspicion. For this reason, Apollo and other companies need to carefully control what each user can do and detect behaviors that do not match their usual activities. Cloud security depends both on the provider\u2019s technology and on the way Apollo manages its identities, permissions, and internal procedures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The principle of least privilege is fundamental in this context. Apollo employees should have only the access necessary to perform their functions, so that the compromise of an account has limited consequences. It is also necessary to record relevant activities and establish additional controls for particularly sensitive operations within Apollo\u2019s systems. In this way, even if an attacker manages to overcome a first barrier, they would still have to face other measures before being able to access critical information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Limits of Multifactor Authentication<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Multifactor authentication has become one of the most important tools for protecting corporate accounts such as those used by Apollo. Its objective is to prevent a stolen password from being sufficient to access a system by requiring a second proof of identity. However, social engineering campaigns demonstrate that this protection should not be considered infallible either, even in an organization with Apollo\u2019s resources. The attacker may attempt to manipulate the user themselves into providing or approving the second factor and thus overcome one of the main security barriers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This does not mean that multifactor authentication is useless, but rather that it must be part of a broader strategy. Apollo needs to combine this tool with access controls, verification procedures, session monitoring, and detection of anomalous behavior. It must also establish clear rules so that employees know what information they should never provide, even when the request appears to come from Apollo\u2019s IT department. The more independent layers there are, the more difficult it will be for a single deceptive action to cause a major intrusion.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Apollo case precisely demonstrates the need to adopt a perspective based on multiple barriers. Apollo\u2019s security should not be built on the assumption that all its employees will always recognize an attempted fraud, because attackers are developing increasingly convincing methods to manipulate them. Companies must assume that someone may be deceived and design their systems to limit the consequences of that error, a strategy that is particularly important for an organization handling highly valuable financial and personal information. This philosophy makes it possible to reduce the impact of a compromised account and increase the chances that Apollo will detect the attack before it reaches particularly sensitive information.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>The Impact on Wall Street<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For a financial company such as Apollo, a data breach can have consequences that go beyond technical costs. Investment institutions depend on the trust of clients, investors, and partners, so any security incident affecting Apollo can also become a reputational problem. The company must deal with investigations, assistance to affected individuals, potential legal costs, and new investments in security, in addition to the effort required to clarify what happened. At the same time, Apollo has to demonstrate that it has learned from the incident and that it is adopting measures to reduce the chances of a similar situation occurring again.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The risk may also extend to other companies related to Apollo. Data obtained in an intrusion can provide information about employees, suppliers, departments, and internal processes that can subsequently be used to prepare new attacks. A criminal who manages to learn about Apollo\u2019s structure can create a much more convincing story when attempting to deceive another employee of the company. In this way, an individual breach such as the one suffered by Apollo can become a tool for facilitating future operations against the same company or against other organizations connected to it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How Can Companies Protect Themselves?<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Employee training should become a permanent part of the cybersecurity strategy of Apollo and any financial company. Workers must learn to recognize suspicious calls, unexpected messages, and urgent requests related to their accounts or the company\u2019s systems. They also need to know how to verify the identity of the person requesting information and whom they should contact when they have doubts about a request that apparently comes from Apollo. An effective security culture should allow an employee to stop a suspicious operation without fear of being penalized for delaying work.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies should also review their account recovery and technical support processes, an issue that is especially important for Apollo after an incident based on social engineering techniques. A phone call should not be sufficient to modify important security controls if the identity of the requester cannot be independently verified. Sensitive operations should require additional verification and be recorded to facilitate subsequent investigations within Apollo and other organizations. The priority should be to prevent an attacker from turning an apparently normal conversation into direct access to corporate systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Finally, Apollo and the rest of the financial organizations need to prepare for the moment when an intrusion occurs. No company can guarantee that it will never suffer an attack, but Apollo can reduce its consequences through system segmentation, limited permissions, continuous monitoring, and well-defined response plans. A rapid response can prevent a compromised account from ultimately providing access to a much larger amount of information belonging to Apollo. The ability to detect, contain, and analyze an incident is therefore just as important as initial prevention and should form part of the company\u2019s ongoing security strategy.<\/p>\n\n\n\n<figure class=\"wp-block-image aligncenter size-large\"><img decoding=\"async\" width=\"1024\" height=\"683\" src=\"https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-3-1024x683.webp\" alt=\"ITD Consulting analiza Apollo Global y el riesgo de la nueva amenaza financiera global\" class=\"wp-image-36898\" srcset=\"https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-3-1024x683.webp 1024w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-3-300x200.webp 300w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-3-768x512.webp 768w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-3-18x12.webp 18w, https:\/\/itdconsulting.com\/wp-content\/uploads\/2026\/08\/itd-consulting-backup-acronis-vds-vps-ciberseguridad-microsoft-365-Apollo-ciberataque-3.webp 1536w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The case of Apollo Global Management demonstrates that the cybersecurity of large financial companies faces a threat that combines technology, information, and human behavior. The company suffered unauthorized access to certain cloud platforms during July 2026 and subsequently determined that highly sensitive personal data may have been exposed. Although it has not been publicly demonstrated that the information was used for fraud and the investigation is ongoing, the incident highlights the risks faced by organizations such as Apollo when they store large amounts of personal and financial information. Apollo\u2019s experience demonstrates that even companies with significant technological resources need to constantly review their protection and response mechanisms.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main lesson is that technological defenses, no matter how sophisticated they are, cannot operate in isolation. Multifactor authentication, cloud systems, automated detection, and artificial intelligence tools are fundamental elements, but they must be complemented by internal controls, supervision, and ongoing training. Attackers are learning that they do not always need to break through a digital barrier when they can convince a person to open it from the inside. Consequently, protecting employees\u2019 identities has become one of the central tasks of corporate security and a priority for companies that handle sensitive information.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Apollo is among the companies that have demonstrated that even organizations with enormous resources can become targets of social engineering campaigns. The incident should serve as a warning for the entire financial sector and for any company that handles sensitive personal information. In an increasingly connected environment, security is no longer solely about protecting servers, networks, and applications, but also about protecting the decisions of the people who use those systems. The best defense against this new generation of attacks will be one that combines technology, vigilance, strict procedures, and a corporate culture in which verifying a suspicious request is always more important than acting quickly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If your company is looking to strengthen its technological infrastructure and improve its protection against digital threats, ITD Consulting can help you with its IT and cybersecurity services. To learn more about its solutions and assess your organization\u2019s needs, you can write to<\/strong> <a href=\"mailto:info@itdconsulting.com\"><strong>info@itdconsulting.com<\/strong><\/a><strong>.<\/strong><\/p>","protected":false},"excerpt":{"rendered":"<p>Apollo Global y la nueva amenaza para el sector financiero. ITD Consulting analiza el caso y te brinda toda la informaci\u00f3n sobre esta ciberamenaza.<\/p>","protected":false},"author":5,"featured_media":36899,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[16],"tags":[459,563,69,71,68],"class_list":["post-36895","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias","tag-459","tag-apollo","tag-ciberataque","tag-ciberseguridad","tag-seguridad"],"_links":{"self":[{"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/posts\/36895","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/comments?post=36895"}],"version-history":[{"count":1,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/posts\/36895\/revisions"}],"predecessor-version":[{"id":36900,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/posts\/36895\/revisions\/36900"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/media\/36899"}],"wp:attachment":[{"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/media?parent=36895"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/categories?post=36895"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/itdconsulting.com\/en\/wp-json\/wp\/v2\/tags?post=36895"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}