ConfirmedData breach

Ameriprise: a data breach

In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign . The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general , Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".

The record

Organisation
Ameriprise
Identity
Ameripriseidentified by its domain in a verified breach record
Records affected
502,597 records
Data exposed
Email addresses, Employers, Financial transactions, Job titles, Names, Phone numbers, Physical addresses
Sector
Not recorded
Occurred
2026-03-02
Disclosed
2026-05-26
First recorded here
2026-09-09

Sources (1)

One source so far.

  1. Have I Been PwnedFirst reported

    2026-05-26