HackingCustomer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
AMERIPRISE FINANCIAL, INC.
bd_eb12126d0012e885 · schema v1 · pii pii-v1
Full breach record for AMERIPRISE FINANCIAL, INC. →Ameriprise Financial, Inc. reported that an unauthorized individual gained access to certain stored data and files on March 2, 2026. The company blocked the access upon discovery on March 18, 2026, and launched an investigation with external cybersecurity experts. Affected data may include personal information such as names, addresses, and financial account details. Ameriprise is offering 12 months of credit and identity monitoring to affected individuals.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Ransomware claims (1)
- bd_e60f06771abd1293Leak Siteshinyhuntersfiled 2026-03-22(25d gap)Verified
Regulatory filings (8) · sorted by filing gap
- bd_5f2a053599f5f3c9Maine State AGfiled 2026-04-17Verified
- bd_87d680adebf94539Iowa State AGfiled 2026-04-17Verified
- bd_8dfab8a7a73e8fe0Indiana State AGfiled 2026-04-17Verified
- bd_f8b3dd7680ac0ff5Oregon State AGfiled 2026-04-17Verified
Show 4 more filings ↓Show fewer ↑up to 70d gap
- bd_fa7df8283d489ea1Washington State AGfiled 2026-04-17Verified
- bd_7bd8e49d9e00029bSouth Carolina State AGfiled 2026-04-20(3d gap)Verified
- bd_0f2775856e7200e1Texas State AGfiled 2026-04-22(5d gap)Verified
- bd_795bde141ec61020Maine State AGfiled 2026-02-06(70d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-621953
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 17, 2026
- Raw hash
- 2e1f00e48cdf9dd157e42ccc2814f16168bb207583c5df1302e5c92b6bff8661
Reporting entity
- Name
- AMERIPRISE FINANCIAL, INC.norm: ameriprise financial
- Domain
- ameriprise.com
Victim entity
- Name
- AMERIPRISE FINANCIAL, INC.norm: ameriprise financial
- Domain
- ameriprise.com
Incident
- Discovered
- Mar 18, 2026
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
Compliance
- Time to disclose
- 4 weeks(30 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.