Apollo Global Management has disclosed a breach tied to social engineering, saying attackers gained unauthorized access to “certain cloud platforms” and may have obtained personal information including Social Security numbers, according to The Register. The disclosure came in a notification filed with California’s attorney general, The Register reports. Apollo described the incident as social engineering and said the unauthorized access lasted from July 6 through July 10. The company has not said which cloud platforms were accessed, how the attackers got in, or how many people were affected. According to The Register’s account of the filing, Apollo’s investigation determined on August 12 that the potentially compromised data included names, dates of birth, contact information, home addresses, and Social Security numbers. Apollo said it has not found evidence so far that the information has been publicly posted or used for identity theft or fraud. The company is offering affected individuals 24 months of credit monitoring and identity protection services. In the notification, Matthew Breitfelder, Apollo’s global head of human capital, said the company notified law enforcement, brought in outside cybersecurity and forensic experts, strengthened security protocols, and began an investigation after detecting the incident, according to The Register. The incident lands against a broader set of reported attacks on financial-sector targets. The Register notes that Google recently warned about UNC6671, an extortion-focused group also known as BlackFile, targeting private equity firms and other financial-services companies. Reuters had reported that Apollo was among the companies targeted, along with Blackstone, Bridgewater and Bain Capital, though it was not clear then whether any of those attacks had succeeded. Apollo’s disclosure confirms that someone did gain access in its case, but it does not attribute the breach to UNC6671. The company’s notification said the incident was similar to those affecting other financial-services firms, according to The Register, but that is not the same as naming an actor. Google’s description of UNC6671’s method is consistent with the broader social-engineering pattern: calling employees on personal phones while impersonating colleagues or IT support, then directing them to fake login pages designed to capture credentials and multi-factor authentication codes. Google said the group steals corporate data and threatens publication unless victims pay, with some payments reaching $750,000, The Register reports. For Apollo, the material unknowns remain large: the number of affected people, whose Social Security numbers were exposed, the specific cloud services involved, and the precise path the attackers used. Until those details emerge, the disclosure establishes the breach window and categories of exposed data, but not the full operational or financial impact. Who benefits: No commercial beneficiary is established by the provided reporting. The immediate relief described is for affected individuals, who are being offered 24 months of credit monitoring and identity protection services. Who's exposed: People whose information was in the affected systems may be exposed, particularly because Social Security numbers were among the potentially compromised data. Apollo and other financial-services firms also remain exposed to similar employee-targeted social-engineering campaigns, according to the context cited by The Register.