Data breach
Ameriprise Financial, Inc.
- Records
- 851,166
- Breach date
- 22 March 2026Estimated
- Added
- 9 April 2026
What was exposed
8 types of data · 3 put you at serious risk
- Email addresses851,166
- Names797,887
- Phone numbers204,376
- Street addresses76,439
- Social security numbers68,771
- Dates of birth7,068
- Bank account numbers4,025
- Driving licence numbers3,484
About this breach
An unauthorized individual gained access to stored data and files held by Ameriprise Financial, Inc. beginning March 2, 2026, and the Minneapolis-based financial services firm blocked the access after discovering it on March 18, according to notices the company filed with state regulators. In filings with the Maine and Iowa attorneys general, Ameriprise reported that 47,876 people were affected, including 335 Maine residents and 583 Iowa residents. The company began mailing written notices to affected individuals on April 17, 2026.
The investigation team, which added this listing on April 9, 2026, indexes 851,166 rows of data connected to the incident, with an estimated attack date of March 22, 2026. The row count in our index is substantially higher than the notified-person tally in the regulatory filings, and the difference has not been reconciled in public sources reviewed for this article. The company's own filings put the number of affected individuals at roughly 48,000.
March 2, 2026: An unauthorized third party began accessing certain Ameriprise stored data and files, according to the company's notice filed with the California Attorney General and state regulator filings.
March 18, 2026: Ameriprise discovered and blocked the unauthorized access and launched an investigation with outside cybersecurity experts, per its Iowa Attorney General notice.
April 17, 2026: The company began providing written notification to affected individuals, according to its Maine Attorney General filing.
April 21, 2026: A proposed class action was filed against Ameriprise in Minnesota federal court, alleging the company failed to safeguard customer data, according to Law360.
What Information Was Compromised?
Our analysis found the following data types in this breach: Social Security numbers (68,771 records), dates of birth (7,068), email addresses (851,166), phone numbers (204,376), driver's license numbers (3,484), names (797,887), street addresses (76,439), and bank account numbers (4,025).
The company's notification letters say the affected information varied from person to person but may have included an individual's name, address, account number, date of birth, and Social Security number. Account numbers appear in the company notice but are not confirmed for every record in our index.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Social Security numbers, dates of birth, and driver's license numbers are the most sensitive items in this set. Combined with names, addresses, and account details, they can support identity theft, fraudulent loan or credit applications, and tax-related fraud. Phishing is a further risk: attackers who hold a victim's name, address, and account number can craft convincing messages that appear to come from a real financial firm. Ameriprise stated that no unauthorized transactions or movement of funds occurred, but the exposure of identity documents creates risk that persists well beyond the breach itself.
What Is Ameriprise Financial, Inc. Doing in Response?
According to its Iowa Attorney General notice, Ameriprise blocked the unauthorized access upon discovery on March 18, launched an investigation with external cybersecurity experts, and implemented heightened account monitoring with enhanced identity verification for affected clients. The company is offering affected individuals credit and identity monitoring through Equifax Complete Premier for 12 months at no cost, and stated that no unauthorized transactions or disruption to business operations occurred.
Two lawsuits filed in connection with the case allege that the group known as ShinyHunters claimed responsibility and threatened to release more than 200 gigabytes of internal data, according to Fox News. The company's notice describes this as a separate incident from a December 2025 data breach that arose from a phishing scam, as reported by PR Newswire.
What Should You Do If You Were Affected?
Accept the free 12-month Equifax Complete Premier credit and identity monitoring if you received a notice, and watch for activation instructions.
Place a free security freeze on your credit files with Equifax, Experian, and TransUnion to block new accounts opened in your name.
Review financial account statements and credit reports for unfamiliar activity, and report suspected identity theft to the Federal Trade Commission at IdentityTheft.gov and your state attorney general.
Be cautious with unsolicited emails, calls, or texts referencing your finances, since attackers may use breached details to impersonate legitimate institutions.
In the news
- Maine Attorney General, Data Breach Notices: Ameriprise Financial, Inc.maine.gov (opens in a new tab)
- Iowa Attorney General, Ameriprise Financial notice, April 17, 2026iowaattorneygeneral.gov (opens in a new tab)
- InvestmentNews, "LPL, Ameriprise once again report attacks on client data to Maine"investmentnews.com (opens in a new tab)
- Law360, "Ameriprise Didn't Disclose Records Breach, Suit Says"law360.com (opens in a new tab)
