CSIDB logo
Incident

Ameriprise Financial, Inc.

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 05:18

Linked entities

Victim
Ameriprise Financial, Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Feb 2026
Resolved
Pending

Summary

Ameriprise Financial detected unauthorized access to certain stored data and files, leading to a breach that exposed personal information of approximately 48,000 customers across the United States. The company said no funds were taken and business operations continued without disruption after the access was blocked and outside experts were engaged. Notification letters indicated that the compromised data could include names, addresses, financial account details and, in some cases, Social Security numbers or other identifiers. Affected individuals were offered credit and identity monitoring services as part of the response.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 2, 2026, unauthorized access to certain stored data and files at Ameriprise Financial was initiated. The company detected the breach on March 18, 2026, approximately sixteen days after the initial intrusion, as noted in a filing with the Maine attorney general. Upon discovery, Ameriprise blocked the unauthorized access and engaged external cybersecurity experts to conduct an investigation. The incident was reported to state authorities and notification letters were prepared for affected individuals.

The notification letters indicated that the attacker accessed certain stored data and files that may have included personal information such as names, addresses, financial account details, and in some cases Social Security numbers or other identifiers. Ameriprise stated that no unauthorized transactions or movement of funds occurred and that business operations continued without disruption. The breach affected nearly forty‑eight thousand customers across the United States.

In response, Ameriprise notified the limited number of individuals whose personally identifiable information was impacted and offered them credit and identity monitoring services. The company also noted that it has reported multiple data security incidents over the past several years. No further details about the attacker’s identity or motives were disclosed in the available source.

Sources

Sources available to members: 1 source.

CSIDB