Ameriprise Financial stored-data incident

An unauthorized individual accessed certain Ameriprise stored data and files between March 2 and March 18, 2026. Regulator records identify affected people and sensitive data categories; HIBP separately characterizes a broader unique-email corpus.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

An unauthorized individual accessed certain Ameriprise stored data and files between March 2 and March 18, 2026. [2][3][4]

Impact

Regulator records identify affected people and sensitive data categories; HIBP separately characterizes a broader unique-email corpus. [3][4]

Documented data types include:

  • Names — Names reported in the Texas regulator record and listed for the broader HIBP corpus. [3][4]
  • Dates of birth — Dates of birth reported by the Texas Attorney General; HIBP does not list this class for its broader corpus. [3][4]
  • Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP incident corpus. [3][4]
  • Financial transaction information — Financial transactions listed for the HIBP incident corpus; distinct from regulator-reported account identifiers. [3][4]
  • Social Security numbers — Social Security number information reported by the Texas Attorney General; HIBP does not list this class for its broader corpus. [3][4]
  • Employment information — Employers and job titles listed for the HIBP incident corpus. [3][4]
  • Financial account information — Financial information, including account or payment-card numbers, reported by the Texas Attorney General; exact elements varied by person. [3][4]

A cited record reports 502,597 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not an affected-customer or affected-person count; as of 2026-05-26). [3][4]

A cited record reports 47,876 individuals (Total individuals affected according to the Texas Attorney General record; as of 2026-04-22). [3][4]

A cited record reports 2,390 individuals (Texas residents affected according to Texas Attorney General record BR-0004987; as of 2026-04-22). [3][4]

An unauthorized individual gained access to certain Ameriprise stored data and files that may have included personal information. [5]

Timeline

  1. Activity began

    Start of the Texas regulator’s reported incident range, California’s incident date, and the HIBP BreachDate.

    [2][3][4]
  2. Documented activity ended

    Ameriprise said it blocked the unauthorized access upon discovery; Texas reports the same date as the end of the range.

    [3][5]
  3. Discovery

    Date Ameriprise says it discovered and blocked the access.

    [3][5]
  4. Public disclosure

    Consumer-notification date in California’s filtered incident directory; individual delivery dates may vary.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Ameriprise offered 12 months of Equifax Complete Premier credit and identity monitoring at no cost. Ameriprise immediately launched an investigation with external cybersecurity experts. Ameriprise implemented heightened account monitoring and enhanced identity-verification procedures. Ameriprise said no unauthorized transactions or movement of funds occurred as part of the incident. Ameriprise advised recipients to activate monitoring, consider a fraud alert or security freeze, review account statements and credit reports, and report unauthorized transactions. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [5]