Ransomware victim disclosure
← All victimsAmeriprise Financial, Inc.
Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Mar 22, 2026
- Data size
- 200 GB
About the victim
AI dossier — public-source company profileAmeriprise Financial, Inc. is a large U.S.-based financial services corporation headquartered in Minneapolis, Minnesota, offering financial planning, wealth management, asset management, and insurance products. It serves millions of individual and institutional clients through a network of financial advisors across the United States and internationally. The company manages hundreds of billions in client assets and operates as a publicly traded entity on the NYSE.
- Industry
- Financial Planning & Wealth Management
- Address
- 707 2nd Ave S, Minneapolis, MN 55402, United States
- Employees
- 10000+
- Founded
- 1894
Attack summary
Severity: critical — Ameriprise is a major regulated financial services firm; the claimed exfiltration includes PII at scale from Salesforce CRM records and 200+ GB of internal SharePoint data, representing a large-volume breach of regulated financial-sector data subject to SEC, FINRA, and state privacy regulations.ShinyHunters claims to have exfiltrated Salesforce records containing PII and over 200 GB of compressed SharePoint internal corporate data, and is issuing a final warning demanding contact by 25 March 2026 before publishing the data and causing additional unspecified 'digital problems.'
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally identifiable information (PII)
- SharePoint internal corporate documents
- Internal business data
What the group claims
Salesforce records containing PII and over 200GB compressed Sharepoint internal corporate data have been compromised. This is a final warning to reach out by 25 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 23 Mar 2026 | Warning: FINAL WARNING
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

