LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Ameriprise Data Breach (2026)

MEDIUM severityConfirmedHow we verify

Ameriprise Data Breach (2026): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·March 2, 2026

SourceBreach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Ameriprise Data Breach (2026)

Reported March 2, 2026. Approximately 503K people affected.

MEDIUM
Severity
503K
People affected
7
Data types exposed
March 2, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Ameriprise disclosed a data breach affecting 503,000 people on 2 March 2026. The exposed records include names, email addresses, employers, job titles, and financial transactions; anyone who may have been impacted should check the company’s notice and take protective steps.

Severity & verification
MEDIUM severityConfirmed
Contact / identity PII exposed.
Corroborated by an official disclosure or a verified breach feed.
Was your email in the Ameriprise Data Breach (2026) breach?
503K accounts were exposed here. See if yours is one — and every other breach it’s in. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In March 2026, reports emerged that Ameriprise Financial had been named in connection with a claimed data exposure. The incident involved assertions that more than 200 GB of data had been taken from the company’s Salesforce environment and internal SharePoint infrastructure, with subsequent publication of records containing roughly 500,000 unique email addresses along with associated personal and employment details. Ameriprise’s filing with state attorneys general listed 47,876 affected individuals, creating a discrepancy with the larger figure referenced in public claims.

Inside the incident

The reported events began with a March 2, 2026 disclosure that placed Ameriprise in an extortion campaign described as “pay or leak.” The claiming party stated it had obtained compressed data from cloud and collaboration platforms and released portions after negotiations did not produce payment. Published material was said to include email addresses, names, phone numbers, physical addresses, employers, job titles, and financial transactions. No official timeline for initial access or exfiltration has been released by the company, and the precise volume of records ultimately made public remains unconfirmed beyond the stated email count.

How a breach like this happens

Incidents involving cloud-hosted customer-relationship platforms and document repositories often begin with compromised credentials or misconfigured access controls. Once inside, an actor can enumerate permissions, locate sensitive folders or objects, and copy large volumes of data to external locations. In extortion-driven cases, the material is then used to pressure the victim organization before selective publication occurs if demands are not met. Such operations exploit the centralized nature of modern business applications, where a single set of credentials can reach both structured customer records and unstructured internal files.

Who is Ameriprise?

Ameriprise operates as a financial-services company offering investment advice, insurance products, and retirement planning to individual and institutional clients. Organizations in this sector routinely maintain records that include client identities, contact information, account activity, and employment data supplied during onboarding or ongoing service. A confirmed exposure at such a firm is consequential because the data types involved are directly useful for account takeover attempts, social-engineering campaigns, and targeted fraud.

What was likely exposed

The named data categories in the published claims are email addresses, names, phone numbers, physical addresses, employers, job titles, and financial transactions. Ameriprise’s regulatory filing does not enumerate every field, so the exact overlap between the claimed dataset and the 47,876 individuals reported to attorneys general is not publicly detailed. Typical records held by financial-services firms also include account numbers, tax identifiers, and investment holdings; whether those fields were present in the released material has not been independently verified.

Why it matters

Exposure of names, addresses, and financial-transaction details can enable identity-verification fraud and unauthorized access to linked accounts. When employer and job-title information is also available, the records become more useful for crafting convincing phishing messages or business-email compromise attempts. For the organization, the incident adds regulatory reporting obligations, potential legal exposure, and the operational cost of notifying affected clients and strengthening access controls.

What to do if you're exposed

Individuals who believe their information may be involved should review recent account statements for unrecognized activity, enable multi-factor authentication on all financial portals, and place fraud alerts with major credit bureaus. Monitoring credit reports at no cost through AnnualCreditReport.com provides an ongoing check for new accounts opened in one’s name. Readers may also run a free exposure scan of their email address against known breach datasets to determine whether their information appears in publicly referenced collections.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Method

CompanyAmeriprise security record
68/100
DoxxScan™ · Moderate doxx risk
B- 76Above-average record

1 reported incident on record.

See Ameriprise’s full breach history →

More recent breaches

Moody Bible Institute Data Breach (2026)June 15, 2026Sysco Data Breach (2026)June 15, 2026JCPenney Data Breach (2026)June 12, 2026American Tower Data Breach (2026)June 12, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Ameriprise Data Breach (2026) →

Verified breach. Breach data provided in part by Have I Been Pwned, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram