AMERIPRISE FINANCIAL, INC.
bd_e60f06771abd1293 · schema v1 · pii pii-v1
Full breach record for AMERIPRISE FINANCIAL, INC. →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Shinyhunters on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Salesforce records containing PII and over 200GB compressed Sharepoint internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_5f2a053599f5f3c9Maine State AGfiled 2026-04-17(25d gap)Verified
- bd_87d680adebf94539Iowa State AGfiled 2026-04-17(25d gap)Verified
- bd_8dfab8a7a73e8fe0Indiana State AGfiled 2026-04-17(25d gap)Verified
- bd_eb12126d0012e885California State AGfiled 2026-04-17(25d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 45d gap
- bd_f8b3dd7680ac0ff5Oregon State AGfiled 2026-04-17(25d gap)Verified
- bd_fa7df8283d489ea1Washington State AGfiled 2026-04-17(25d gap)Verified
- bd_7bd8e49d9e00029bSouth Carolina State AGfiled 2026-04-20(28d gap)Verified
- bd_0f2775856e7200e1Texas State AGfiled 2026-04-22(30d gap)Verified
- bd_795bde141ec61020Maine State AGfiled 2026-02-06(45d gap)Verified
Source provenance
- Source URL
- https://www.ransomware.live/
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 22, 2026
- Raw hash
- 567cb6ee2f65aceffc9e72fbff3f8204568bbe4f6c74dd671ddf79f013a96f5a
Reporting entity
- Name
- shinyhunters
Victim entity
- Name
- AMERIPRISE FINANCIAL, INC.norm: ameriprise financial
- Domain
- ameriprise.com
- Industry
- Financial Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· shinyhunters
- Threat actor
- ShinyhuntersExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.