Jessica Entwistle
August 24 2026
Private equity firm Apollo has confirmed a data breach following a five-day intrusion in early July, during which attackers gained access to some of the company's cloud platforms and compromised sensitive personal data. TechCrunch reports that the breach is part of a broader wave of attacks targeting financial services firms, which Google researchers highlighted in recent weeks. Apollo disclosed that the attackers used social engineering techniques to gain initial access, then moved laterally within the cloud environment. The company has notified affected individuals and is working with law enforcement and cybersecurity specialists to investigate the incident. The disclosure comes amid heightened concern about coordinated campaigns targeting the financial sector, suggesting that attackers are systematically exploiting common weaknesses across multiple organisations.
This incident is operationally significant because it demonstrates how attackers are successfully targeting cloud environments within highly regulated and well-resourced organisations. The use of social engineering as an initial access vector underscores the continued effectiveness of human-focused attacks, even in organisations with mature technical controls. For UK businesses in financial services or adjacent sectors, this is a reminder that cloud security, identity and access management, and user awareness remain critical defensive layers. The fact that this breach is part of a broader pattern of attacks suggests that financial services firms are being systematically targeted, likely due to the value of the data they hold and the potential for financial gain or espionage. The five-day window during which attackers maintained access highlights the importance of rapid detection and response capabilities, as well as the need for continuous monitoring of cloud environments. For many organisations, cloud platforms represent a significant portion of their attack surface, yet visibility and control in these environments often lag behind on-premises infrastructure.
UK businesses, particularly those in financial services, should review cloud access controls, ensure multi-factor authentication is enforced across all privileged accounts, and verify that security monitoring covers cloud platforms as comprehensively as on-premises infrastructure. Consider whether your organisation has tested its ability to detect and respond to lateral movement within cloud environments, including the ability to identify unusual access patterns, privilege escalation attempts or data exfiltration. Review whether your organisation has implemented conditional access policies, just-in-time access controls or privileged access management solutions that limit the scope and duration of access to sensitive cloud resources. Ensure that security awareness training includes social engineering scenarios relevant to cloud environments, such as phishing for cloud credentials or impersonation of cloud service providers. Consider whether your organisation has visibility into third-party access to cloud platforms, including managed service providers, contractors or business partners. Finally, review whether your incident response plan includes specific procedures for cloud-based breaches, including how to isolate compromised accounts, preserve forensic evidence and coordinate with cloud service providers.
Source: TechCrunch