Skip to Content
Opening Bell

Close-UpFriday, August 2112 Min Read

Apollo's Breach Exposed Social Security Numbers; the Stock Rose

The first open confirmation in a voice-phishing campaign aimed at Wall Street's largest asset managers came from Apollo: Social Security numbers were among the data taken. The shares closed higher the same day — and the reason for that non-reaction is the story.

Breaking into the cloud systems of one of Wall Street's largest asset managers did not require a new software vulnerability. A phone call was enough.

On Friday, August 21, Apollo Global Management confirmed, in a notice filed with the California attorney general, that it had suffered a "social engineering incident" in early July. Attackers reached the firm's cloud environment; the exposed data includes names, dates of birth, addresses and Social Security numbers. Apollo did not disclose how many people were affected, and said it is offering 24 months of complimentary credit monitoring.

That same day, Apollo shares closed at $132.69, up 2.08% from the prior session.

Put those two facts side by side and one question follows: why does a firm's stock not fall on the day it confirms that employee and investor Social Security numbers were taken? The answer lies not in the size of the incident but in what the equity market is able to measure.

By the Numbers

200+

Organizations trapped in five weeks

72

Spoofed login sites registered

$10M

Ransom payments traced, January–May

$750K

Average settlement in resolved cases

Google's Target List and the Names on It

The story began two weeks before Apollo's notice. On August 6, Google's threat intelligence unit disclosed a voice phishing campaign aimed at the largest U.S. financial institutions. Reuters, reviewing Google's data alongside internet infrastructure records, reported that digital traps had been built for more than 200 organizations in five weeks.

Named targets include Blackstone, Bridgewater Associates, Apollo, Bain Capital, KKR, TPG, CME Group, Clearlake Capital and Moody's. Hedge funds Point72, Two Sigma and Citadel appear on the list as well, along with non-financial names such as Uber, Zillow and Levi Strauss.

A distinction matters here: being targeted is not the same as being breached. Google did not say at which organizations the attacks succeeded. Most of the named firms declined to comment; several did not respond. Apollo's August 21 notice is the first open confirmation from anyone on the list.

Austin Larsen, the Google researcher who worked on the campaign, put it briefly to Reuters:

"Sophisticated is not the right word. It is just really effective."

From a Phone Call to Cloud Data

There is nothing new in the technical mechanics. What is new is the choice of targets and the way the chain is assembled.

The Attack Chain

  1. 01Phone callPersonal mobile, help desk impersonation
  2. 02Spoofed portalpasskeyhelpdesk · setupsso · idokta
  3. 03Identity providerOkta · Microsoft Entra ID
  4. 04SaaS applicationsMicrosoft 365 and connected services
  5. 05ExfiltrationAutomated Python and PowerShell scripts

The critical link is the spoofed portal in the middle. These are not ordinary phishing pages; they use an adversary-in-the-middle setup, with the attacker sitting between the victim and the real login page. The victim enters a password and the one-time code sent to their phone, and the page relays both to the real system in real time. The code expires in thirty seconds; the attacker uses those thirty seconds. Two-factor authentication is switched on and is defeated anyway.

The first move after getting in is persistence: the attacker registers their own device as a second authentication factor and removes the victim's real one. From that point, changing the password no longer closes the door.

This is also where the damage compounds. Identity providers such as Okta and Microsoft Entra ID work on single sign-on: an employee who authenticates once reaches dozens of connected applications without entering another password. What is convenience for the employee is a single door for the attacker. When one identity falls, what falls with it is not one account but the entire cloud application estate behind it. The data then leaves not by hand but through prepared scripts.

The Arithmetic of the Ransom

Understanding why this campaign keeps running requires arithmetic, not moralizing.

What Happened at Apollo

According to the notice, the unauthorized access took place between July 6 and July 10 and was detected on July 10. The firm said that as of the notification date it had found no evidence the data had been published anywhere or misused.

Apollo managed $1.05 trillion in assets as of June 30. It reported second-quarter results on August 4 with $1.3 billion in quarterly profit. Its market capitalization stood near $78 billion at the August 21 close.

Timeline

  1. July 6–10Unauthorized access to Apollo's cloud environment.
  2. July 10The firm detects the intrusion.
  3. August 4Apollo reports Q2 results; assets under management reach $1.05 trillion.
  4. August 6Google's report lands; Reuters publishes the target list.
  5. August 21The California notice confirms the breach; shares close up 2.08%.

Two Thresholds, Two Different Questions

Beneath the sentence "the company disclosed a breach" sit two separate reporting regimes that operate independently of each other. The distinction explains why this incident was announced by letter and not to the market.

California noticeSEC Form 8-K, Item 1.05
What it measuresNumber of people affectedFinancial significance to the company
ThresholdMore than 500 state residentsManagement's materiality determination
Deadline30 calendar days from discoveryFour business days from the determination
ResultSample letter to the attorney generalAnnouncement to the market
InstrumentCalifornia Civil Code 1798.82, SB 446SEC rule, December 2023

The first column counts. Under SB 446, effective January 1, 2026, California tied notification to 30 calendar days from discovery; where more than 500 state residents are affected, a sample of the consumer letter also goes to the attorney general and becomes public. In Apollo's case that is the only concrete measure of scale available: the letter's presence at the attorney general's office means at least 500 Californians were affected. The date a notice reaches the attorney general need not be the date affected individuals were notified.

The second column does not ask how many. It asks whether it matters. Under the SEC rule that took effect in December 2023, the four-business-day clock starts not from the incident but from the moment management determines the incident is material. The distinction looks small on paper and governs the entire rule in practice: if no materiality determination has been made, the clock has never started.

The consequence shows up in the counts. Debevoise & Plimpton's tracker records 79 filings from 74 issuers between December 18, 2023, when the rule took effect, and May 21, 2026. Of those, 29 were filed under Item 1.05, the material-incident item; 50 were filed under Item 8.01, the voluntary-disclosure item. In two and a half years, across every U.S. exchange, a company judged a cyber incident financially material 29 times.

So the instrument behind "U.S. companies have to disclose cyberattacks" ties disclosure not to the size of the incident but to the company's own assessment. A breach that clears California's headcount threshold can comfortably fail to clear the SEC's materiality threshold. Reporting on the Apollo incident describes the state notice; no Form 8-K filing is mentioned.

Why the Market Did Not Move

First, an honest word about causation. August 21 was a broadly higher day; SPY, which tracks the S&P 500, rose 0.41%. There is no basis for attributing Apollo's 2.08% gain to the breach news. The finding here is not the movement but the absence of one: a firm that had just confirmed the theft of Social Security numbers saw no distinguishable selling.

For the backdrop of the day:

SPYSPDR S&P 500 ETF Trust
The S&P 500 tracking fund — past month

Nor is this specific to Apollo. Comparitech's study of 118 publicly traded companies that suffered breaches between 2007 and 2023 produces this average picture: the stock bottoms 41 trading days after disclosure, with an average loss at that point of 1.4%, and returns to its pre-disclosure level by day 53. Over a six-month window, the shortfall against the Nasdaq is 3.2%.

Six-Month Performance vs. Nasdaq After a Breach

Healthcare-10.6%
Finance-6.4%
Manufacturing-4.0%
Overall average-3.2%

The study's most instructive finding runs against intuition. Where highly sensitive data such as Social Security numbers leaked, the stock beat the Nasdaq by 1.0% over six months; where only low-sensitivity data such as email addresses leaked, it trailed by 7.93%.

That looks senseless at first and settles into place once you work through the mechanism. The market is not pricing how private the data is. It is pricing how much revenue is interrupted. Email lists tend to sit at consumer-facing companies, where a breach usually means the site goes down, payments stop, customers go elsewhere — a visible hole in that quarter's revenue. Social Security numbers tend to sit in employee, applicant and investor files; leaking them is expensive, but the expense is notification costs, credit monitoring subscriptions and litigation spread over years. None of it shows up in next quarter's revenue.

In Apollo's case the gap runs to the extreme. Revenue comes from management fees charged on the $1.05 trillion it oversees. A large share of that money is committed capital in closed-end funds: an institutional investor cannot withdraw a commitment because of a data breach, because the agreement does not permit it. A retailer's customer can shop elsewhere the next day; a pension fund's ten-year commitment does not work that way. If the revenue line is fixed by contract, the incident has no channel through which to reach the share price.

For the ground the stock was standing on before and after:

APOApollo Global Management Inc
Apollo — the past three months

The chart is not proof of an argument; it is a picture of the terrain the news landed on. On valuation logic, a share price is the present value of future cash flows, and for a breach to enter that price it has to change those cash flows measurably.

What Is Still Open

Three questions remain unanswered.

The first is the count. Apollo did not say how many people were affected, only that its investigation continues. All the California threshold tells us is that the number exceeds 500. Whether those affected are employees, applicants or investors was not specified either.

The second is the list. Google counted the organizations targeted, not the ones breached. Apollo's is the first open confirmation on that list; the silence of the others does not mean "not breached," it means "not disclosed."

The third is time. No evidence of misuse is not the same as no copying. A Social Security number is a permanent identifier; unlike a password, it cannot be reset. Data of that kind holds its resale value for years, and so does the risk attached to it.

This piece draws on Reuters' August 6 exclusive, the findings of Google's threat intelligence report as relayed in the press, the contents of Apollo's notice to the California attorney general as reported by TechCrunch and Bloomberg, Apollo's second-quarter results of August 4, Debevoise & Plimpton's Form 8-K cyber incident tracker, and Comparitech's 118-company share performance study. Ransom figures and infrastructure counts are drawn from press accounts of the Google report and have not been independently verified. The number of individuals affected has not been disclosed by the company.