AMERIPRISE FINANCIAL, INC.
bd_e60f06771abd1293 · schema v1 · pii pii-v1
Full breach record for AMERIPRISE FINANCIAL, INC. →75 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Shinyhunters on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Salesforce records containing PII and over 200GB compressed Sharepoint internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Mar 22, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Regulatory filings (10) · sorted by filing gap
- Vermont State AGbd_31751275b2b0456f2026-04-17 · +25dVerified
- Massachusetts State AGbd_4ca343f72bba0d382026-04-17 · +25dVerified
- New Hampshire State AGbd_5d8be0c5042fbeeb2026-04-17 · +25dVerified
- Maine State AGbd_5f2a053599f5f3c92026-04-17 · +25dVerified
Show 6 more filings ↓Show fewer ↑up to 128d gap
- Iowa State AGbd_87d680adebf945392026-04-17 · +25dVerified
- Indiana State AGbd_8dfab8a7a73e8fe02026-04-17 · +25dVerified
- Rhode Island State AGbd_ad81226da095b63e2026-04-17 · +25dVerified
- South Carolina State AGbd_7bd8e49d9e00029b2026-04-20 · +28dVerified
- Texas State AGbd_0f2775856e7200e12026-04-22 · +30dVerified
- New Hampshire State AGbd_ecfe28f07939f2972026-07-29 · +128dVerified
Showing first 10 of 15 linked disclosures.
Filing propagation · 11 filings · 9 states
View merged incident ↗Pattern: first filing Mar 22, last Jul 29 (NH) — a 128-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Cascade drawn from the first 10 linked disclosures of 15 — the full spread may be wider.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
shinyhunters
According to ransomware.live, ShinyHunters is a financially motivated data-theft and extortion group active since 2020, responsible for high-profile breaches including Ticketmaster (via Snowflake) and PowerSchool; by 2025 they launched a RaaS offering called "shinysp1d3r," and in August 2025 French authorities arrested four members.