On March 22, 2026, the Shinyhunters ransomware group claimed to have compromised Ameriprise Financial, Inc., alleging access to Salesforce records with personally identifiable information (PII) and over 200GB of compressed Sharepoint internal corporate data. The group issued a "final warning" for contact by March 25, 2026, before threatening to leak the data. As of March 23, 2026, no official confirmation of this incident has been released by Ameriprise Financial, Inc.
Specific data types confirmed to be compromised include PII from Salesforce records and internal corporate data from Sharepoint. The number of affected individuals remains unknown, and no official company breach notifications or state Attorney General filings related to this incident have been found. It is not publicly confirmed whether this incident involved SSN, medical, or financial data. This reported breach primarily targets Ameriprise directly, without indications of it being a vendor or third-party breach.
Details about this incident are still emerging, and official notices may be delayed.