← Back to Home

Ameriprise Data Breach

Verified Breach
Mar 1, 2026 Breach Date
502,597 Accounts Affected
7 Data Types Exposed
May 26, 2026 Added to HIBP
About This Breach
In March 2026, the financial services firm Ameriprise Financial was named by the ShinyHunters group in a "pay or leak" extortion campaign. The group claimed possession of more than 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure, and subsequently published the data after negotiations allegedly failed. The published data contained 500k unique email addresses as well as names, phone numbers, physical addresses and employer information. In their disclosure to state attorneys general, Ameriprise reported 47,876 affected people; the larger email address population represents contacts from Ameriprise's broader operational systems, including internal staff. Ameriprise further advised that they have "implemented heightened monitoring of your account(s) to include enhanced identity verification procedures".
Compromised Data Types
Email addresses Employers Financial transactions Job titles Names Phone numbers Physical addresses
Check If You Were Affected

Were you part of the Ameriprise breach?

Has your email been exposed in a breach?