TL;DR: ShinyHunters (the same group behind the Vercel breach, the Kemper breach, and dozens of other corporate hacks) breached Ameriprise Financial on March 2, 2026. The company didn't notice until March 18. By then, attackers had grabbed 200GB of data including Social Security numbers, account balances, net worth figures, and medical records for 47,876 clients. ShinyHunters posted a ransom threat on March 22, giving Ameriprise until March 25 to pay up. Ameriprise filed breach notices with state regulators on April 18, nearly seven weeks after the initial compromise. Two class action lawsuits have already been filed and dismissed without prejudice. And this is Ameriprise's second breach in six months.
What Happened
On March 2, 2026, an unauthorized party accessed Ameriprise Financial's systems and began exfiltrating data. The company didn't detect the intrusion until March 18: sixteen days of unmonitored access to one of America's largest wealth management firms [1].
The stolen data reads like a financial identity thief's wish list:
- Full names, addresses, dates of birth
- Social Security numbers
- Account numbers and policy numbers
- Account values and net worth estimates
- Payment card information
- Protected health information and medical records
- Email addresses and phone numbers
This isn't just names and emails. This is the full financial profile of people who trust Ameriprise with their retirement savings. The firm manages over $1.6 trillion in assets [2].
ShinyHunters Strikes Again
On March 22, ShinyHunters posted the breach on their dark web leak site. They claimed to hold over 200GB of compressed data stolen from Ameriprise's Salesforce instance and SharePoint servers [3].
The ransom deadline: March 25, 2026. Three days to pay up or the data goes public.
No sample data was published with the listing, unusual for ShinyHunters, who typically post proof files. No ransom amount was publicly disclosed. No images, no downloadable files [3].
That's either restraint or negotiation leverage. When you're holding net worth figures and SSNs for 48,000 wealthy Americans, the threat alone carries weight.
If you've been following our ShinyHunters coverage, this attack fits the playbook. The group has been on a tear since late 2025, hitting 400+ companies through Salesforce, Okta SSO, and social engineering campaigns. They stole a petabyte from Telus Digital. They hit Infinite Campus, exposing 11 million student records. They breached Carnival Corporation for 8.7 million records.
Ameriprise is just the latest in a campaign that's become the most prolific corporate breach spree in recent memory.
The Second Breach in Six Months
Here's the part Ameriprise would rather you didn't notice: this isn't their first breach in the past year.
In November 2025, a phishing attack targeted an advisor's office staff member, giving attackers "temporary access to client information." That breach exposed names, SSNs, addresses, driver's license numbers, financial details, and even protected health information for hundreds of clients across multiple states [4].
Ameriprise's response to the November breach: "enhanced verification procedures for account requests."
Three months later, ShinyHunters walked in and took 200GB of data from Salesforce and SharePoint.
Whatever "enhanced verification procedures" means, it apparently doesn't include detecting a 16-day data exfiltration from your core business platforms.
Ameriprise's Response
According to filings with state attorneys general, Ameriprise took these steps [1][2]:
- Blocked unauthorized access upon discovery (March 18)
- Engaged external cybersecurity experts
- Notified affected individuals
- Offered 12 months of free credit monitoring through Equifax
- Stated "no unauthorized transactions or movement of funds occurred"
- Reported "no disruption to business operations"
Twelve months of credit monitoring. For a breach that exposed your SSN, net worth, account balances, and medical records. That data will be useful to identity thieves for decades. A year of Equifax monitoring (from a credit bureau that suffered its own catastrophic breach) is the corporate equivalent of thoughts and prayers.
The Legal Fallout
Two class action lawsuits were filed in the U.S. District Court for the District of Minnesota almost immediately. The lead case, Lackey v. Ameriprise Financial Inc. (Case No. 0:26-cv-02128), alleges that Ameriprise failed to implement adequate security measures to protect client data from the ShinyHunters attack [5].
Both suits were voluntarily dismissed without prejudice the week of April 14, which typically means the parties are negotiating or the plaintiffs plan to refile with a stronger complaint [5].
Multiple law firms, including Edelson Lechtzin LLP, Migliaccio & Rathod LLP, and Schubert Jonckheer & Kolbe, have opened investigations and are recruiting plaintiffs [2][6].
Ameriprise's filings with state regulators list 47,876 affected individuals, including 335 in Maine. The actual number could be higher once additional state filings are analyzed.
What Ameriprise Clients Should Do
- Freeze your credit. Don't just monitor it, freeze it. Contact Equifax, Experian, and TransUnion directly. A freeze prevents anyone from opening new accounts in your name. It's free and reversible.
- Check your Ameriprise accounts. Look for any unauthorized transactions, address changes, or beneficiary modifications. The company says no unauthorized transactions occurred, but verify that for yourself.
- Watch for targeted phishing. Attackers now have your financial profile. Expect sophisticated phishing emails that reference your actual account details, advisor name, or recent transactions. Ameriprise will never ask for your password by email.
- File an IRS Identity Protection PIN. With your SSN exposed, file for an IP PIN from the IRS to prevent tax fraud.
- Don't rely on the free monitoring. Equifax's complimentary 12-month monitoring is better than nothing, but consider a longer-term identity protection service or set up your own monitoring with fraud alerts.
- Document everything. If you're affected, keep copies of the breach notification letter and any communications from Ameriprise. You may need them if a class action moves forward.
The Pattern No One's Breaking
ShinyHunters keeps hitting financial services firms through the same vectors: Salesforce environments, SSO platforms, social engineering. They've published a playbook through sheer repetition, and companies managing trillions in assets keep falling for it.
Ameriprise manages $1.6 trillion. They got phished in November. They got breached through Salesforce in March. Two breaches in six months, and the response both times was "enhanced procedures" and credit monitoring.
At some point, "enhanced procedures" has to mean something more than a press release.
Sources
- ThinkAdvisor: "Ameriprise Data Breach Affected Nearly 48,000" (April 20, 2026)
- GlobeNewsWire: "Data Breach Alert: Edelson Lechtzin LLP Investigates Reported Ameriprise Financial, Inc. Incident" (April 21, 2026)
- Prism News: "ShinyHunters Claims 200GB Ameriprise Data Breach, Sets March Deadline" (March 2026)
- ClaimDepot: "Ameriprise Financial Data Breach 2026" (April 2026)
- Top Class Actions: "Ameriprise Sued After Breach Allegedly Put Customer Financial Data at Risk" (April 2026)
- Migliaccio & Rathod LLP: "Ameriprise Data Breach Investigation" (April 20, 2026)
Published: April 27, 2026