---
title: "Ameriprise Financial stored-data incident"
description: "Evidence-backed account of Ameriprise Financial stored-data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/ameriprise-financial-stored-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/ameriprise-financial-stored-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/ameriprise-financial-stored-data-incident-2026/stix.json"
---

# Ameriprise Financial stored-data incident

An unauthorized individual accessed certain Ameriprise stored data and files between March 2 and March 18, 2026. Regulator records identify affected people and sensitive data categories; HIBP separately characterizes a broader unique-email corpus.

Last modified Aug 9, 2026 · 5 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

An unauthorized individual accessed certain [Ameriprise](https://www.ameriprise.com/) stored data and files between March 2 and March 18, 2026. [2](#source-2) [3](#source-3) [4](#source-4)

## Impact

Regulator records identify affected people and sensitive data categories; HIBP separately characterizes a broader unique-email corpus. [3](#source-3) [4](#source-4)

Documented data types include:

- Names — Names reported in the Texas regulator record and listed for the broader HIBP corpus. [3](#source-3) [4](#source-4)
- Dates of birth — Dates of birth reported by the Texas Attorney General; HIBP does not list this class for its broader corpus. [3](#source-3) [4](#source-4)
- Contact information — Email addresses, phone numbers, and physical addresses listed for the HIBP incident corpus. [3](#source-3) [4](#source-4)
- Financial transaction information — Financial transactions listed for the HIBP incident corpus; distinct from regulator-reported account identifiers. [3](#source-3) [4](#source-4)
- Social Security numbers — Social Security number information reported by the Texas Attorney General; HIBP does not list this class for its broader corpus. [3](#source-3) [4](#source-4)
- Employment information — Employers and job titles listed for the HIBP incident corpus. [3](#source-3) [4](#source-4)
- Financial account information — Financial information, including account or payment-card numbers, reported by the Texas Attorney General; exact elements varied by person. [3](#source-3) [4](#source-4)

A cited record reports 502,597 records (Unique email addresses represented in the HIBP incident corpus; a corpus-record count, not an affected-customer or affected-person count; as of 2026-05-26). [3](#source-3) [4](#source-4)

A cited record reports 47,876 individuals (Total individuals affected according to the Texas Attorney General record; as of 2026-04-22). [3](#source-3) [4](#source-4)

A cited record reports 2,390 individuals (Texas residents affected according to Texas Attorney General record BR-0004987; as of 2026-04-22). [3](#source-3) [4](#source-4)

An unauthorized individual gained access to certain Ameriprise stored data and files that may have included personal information. [5](#source-5)

## Timeline

### March 2, 2026 — Activity began

Start of the Texas regulator's reported incident range, California's incident date, and the HIBP BreachDate. [2](#source-2) [3](#source-3) [4](#source-4)

### March 18, 2026 — Documented activity ended

Ameriprise said it blocked the unauthorized access upon discovery; Texas reports the same date as the end of the range. [3](#source-3) [5](#source-5)

### March 18, 2026 — Discovery

Date Ameriprise says it discovered and blocked the access. [3](#source-3) [5](#source-5)

### April 17, 2026 — Public disclosure

Consumer-notification date in California's filtered incident directory; individual delivery dates may vary. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Ameriprise offered 12 months of Equifax Complete Premier credit and identity monitoring at no cost. Ameriprise immediately launched an investigation with external cybersecurity experts. Ameriprise implemented heightened account monitoring and enhanced identity-verification procedures. Ameriprise said no unauthorized transactions or movement of funds occurred as part of the incident. Ameriprise advised recipients to activate monitoring, consider a fraud alert or security freeze, review account statements and credit reports, and report unauthorized transactions. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [5](#source-5)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/ameriprise-financial-stored-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Search Data Security Breaches — Ameriprise Financial filter

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list?field_sb24_org_name_value=Ameriprise>

<a id="source-2"></a>

### Submitted Breach Notification Sample — Ameriprise Financial, Inc.

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-621953>

<a id="source-3"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-4"></a>

### Ameriprise breach record

advisory · Have I Been Pwned · May 26, 2026

<https://haveibeenpwned.com/api/v3/breach/Ameriprise>

<a id="source-5"></a>

### Notice of Data Incident

official · Ameriprise Financial, Inc. · Apr 17, 2026

<https://www.mass.gov/doc/2026-604-ameriprise-financial-inc/download>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Disclosed At · 100% confidence · current**  
   April 2026 Ameriprise individual notification: 2026-04-17
2. **Exposed Record Count · 100% confidence · current**  
   Ameriprise personal-information exposure: 502,597 record
3. **Exposed Data Category · 100% confidence · current**  
   Ameriprise personal-information exposure: Names
4. **Exposed Data Category · 100% confidence · current**  
   Ameriprise personal-information exposure: Dates of birth
5. **Resulted In · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: An unauthorized individual gained access to certain Ameriprise stored data and files that may have included personal information.
6. **Resulted In · 100% confidence · current**  
   April 2026 Ameriprise individual notification: Ameriprise offered 12 months of Equifax Complete Premier credit and identity monitoring at no cost.
7. **Resulted In · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: Ameriprise personal-information exposure
8. **Resulted In · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: Ameriprise immediately launched an investigation with external cybersecurity experts.
9. **Exposed Data Category · 90% confidence · current**  
   Ameriprise personal-information exposure: Contact information
10. **Resulted In · 100% confidence · current**  
   April 2026 Ameriprise individual notification: Ameriprise implemented heightened account monitoring and enhanced identity-verification procedures.
11. **Ended At · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: 2026-03-18
12. **Affected Individual Count · 100% confidence · current**  
   Ameriprise personal-information exposure: 47,876 individual
13. **Began At · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: 2026-03-02
14. **Affected Individual Count · 100% confidence · current**  
   Ameriprise personal-information exposure: 2,390 individual
15. **Exposed Data Category · 90% confidence · current**  
   Ameriprise personal-information exposure: Financial transaction information
16. **Discovered At · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: 2026-03-18
17. **Exposed Data Category · 100% confidence · current**  
   Ameriprise personal-information exposure: Social Security numbers
18. **Exposed Data Category · 90% confidence · current**  
   Ameriprise personal-information exposure: Employment information
19. **Resulted In · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: Ameriprise said no unauthorized transactions or movement of funds occurred as part of the incident.
20. **Exposed Data Category · 100% confidence · current**  
   Ameriprise personal-information exposure: Financial account information
21. **Resulted In · 100% confidence · current**  
   April 2026 Ameriprise individual notification: Ameriprise advised recipients to activate monitoring, consider a fraud alert or security freeze, review account statements and credit reports, and report unauthorized transactions.
22. **Affected Organization · 100% confidence · current**  
   March 2026 Ameriprise stored-data incident: Ameriprise Financial, Inc.

</details>
