Ameriprise: a data breach
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general , Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".
The record
- Organisation
- Ameriprise →
- Identity
- Ameripriseidentified by its domain in a verified breach record
- Records affected
- 502,597 records
- Data exposed
- Email addresses, Employers, Financial transactions, Job titles, Names, Phone numbers, Physical addresses
- Sector
- Not recorded
- Occurred
- 2026-03-02
- Disclosed
- 2026-05-26
- First recorded here
- 2026-09-09
Sources (1)
One source so far.
- Have I Been Pwned ↗First reported
2026-05-26