Last updated 1 month ago
In March 2026, Ameriprise Financial, a financial services firm, was targeted by the ShinyHunters group in a 'pay or leak' extortion campaign. The group claimed possession of over 200GB of compressed data exfiltrated from Ameriprise's Salesforce environment and internal SharePoint infrastructure. After negotiations allegedly failed, the data was published, exposing 502,597 unique email addresses along with names, phone numbers, physical addresses, and employer information. Ameriprise disclosed 47,876 affected individuals to state attorneys general, with the larger email population representing contacts from broader operational systems, including internal staff.
The attack vector involved unauthorized access to Ameriprise's Salesforce environment and internal SharePoint infrastructure, likely through compromised credentials or a vulnerability. The ShinyHunters group, known for extortion-driven data breaches, exfiltrated over 200GB of compressed data. The exposed data types included email addresses, names, phone numbers, physical addresses, and employer information, but no financial account numbers or Social Security numbers were reported.
Ameriprise reported the incident to state attorneys general, confirming 47,876 affected individuals. The company implemented heightened monitoring of affected accounts, including enhanced identity verification procedures. No ransom payment was disclosed, and no litigation or regulatory fines have been reported as of the disclosure date.
Data exfiltrated from Salesforce environment and internal SharePoint infrastructure via extortion campaign
Ameriprise's breach underscores the critical need for robust access controls and monitoring of third-party cloud environments like Salesforce and internal SharePoint. The exfiltration of over 200GB of data suggests inadequate data loss prevention (DLP) measures and insufficient segmentation between operational and sensitive systems. Financial firms must enforce strict least-privilege access, implement continuous monitoring for anomalous data transfers, and conduct regular security assessments of integrated SaaS platforms to prevent large-scale data theft.
Sign in to join the discussion.
Company
Industry
Location
Discovered
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor