Morning Overview

Data-breach notices have already blown past last year’s record, and AI is fueling one in four attacks

Halfway through 2026, the number of Americans warned that their personal information had been exposed already surpassed the total for all of the previous year, a milestone that points toward a record-breaking twelve months for identity crime. Analysts tracking the trend say the surge is being driven both by the return of enormous single-event breaches and by attackers who increasingly lean on artificial intelligence to find and exploit weaknesses. The practical consequence is a landscape in which most consumers should now assume that at least some of their data is already circulating.

A first half that eclipsed all of 2025

The Identity Theft Resource Center, a nonprofit that catalogs publicly reported data compromises, tracked 1,803 data compromises between January and June 2026. The second quarter alone accounted for 1,029 of them, the second-highest single-quarter figure in the organization’s history. If that pace holds, the year could close with roughly 3,600 compromises, extending a four-year streak above 3,000 and topping the previous annual record of 3,321 set in 2025.

The count of individual notices sent to breach victims tells an even starker story. An estimated 471.2 million notices went out in the first half of the year, already dwarfing the 297.5 million issued across all of 2025. With more warnings mailed than there are people living in the United States, the center concluded that consumers can no longer treat exposure as a remote possibility.

The Canvas breach and the return of the mega-breach

A single incident dominated the tally. A compromise involving Instructure Holdings’ Canvas education platform generated an estimated 275 million victim notices, or about 58 percent of the entire first-half total. Such outsized events had grown less common in recent years, and their return is a large part of why the notice count climbed so sharply.

Concentration was the theme elsewhere as well. Supply-chain attacks produced 280.6 million notices from just 38 initial breach events that rippled out to 206 organizations, a stark illustration of how one vendor failure can cascade across its customers. Publicly traded companies, meanwhile, accounted for only about 10 percent of all compromises but generated more than 83 percent of the victim notices, a sign that the largest institutions hold the largest troves of records.

The concentration reached industries not usually associated with mass data loss. Manufacturing, for instance, produced roughly 74 million victim notices in the first half of 2026, compared with fewer than 2 million in all of 2025, a leap the center tied to the sector’s expanding reliance on connected systems. The broader pattern held throughout the data: a handful of enormous events, rather than a wide rise in small ones, drove most of the record notice count.

Why roughly one in four attacks now involves AI

Artificial intelligence is reshaping how those breaches happen. Roughly one in four malicious breaches studied between March 2025 and February 2026 were AI-enabled, a 56 percent increase over the prior year, according to research cited in coverage of the trend. Attackers are using the technology to write more convincing phishing lures, automate reconnaissance and probe systems at machine speed.

The effect is visible in the resurgence of zero-day exploitation, in which criminals take advantage of software flaws before a fix exists. The center logged 14 such events in the first half of 2026, nearly matching the 17 recorded in all of 2025, and attributed part of that acceleration to AI tools that surface vulnerabilities faster than human researchers can.

Beyond speed, artificial intelligence is lowering the skill required to mount an attack. Systems that draft flawless, personalized phishing messages let less-capable criminals impersonate colleagues and institutions convincingly, while automation can test stolen credentials against thousands of sites at once. Analysts caution that the same efficiencies helping defenders spot threats are also compressing the time an intruder needs to move from a first foothold to a full breach.

Insider wrongdoing and a widening transparency gap

Not every threat came from outside. Insider-wrongdoing events jumped to 21 in the first six months of the year, a sevenfold increase over the three logged in all of 2025, a rise the center linked to technology-sector layoffs and to recruitment schemes run by hostile nation-states. Those cases are difficult to detect because the offender already holds legitimate access.

Compounding the problem, transparency is eroding. Only 24 percent of the breach notices issued in the first half of 2026 described how the incident actually happened, the lowest share the center has ever recorded. That opacity leaves consumers and businesses guessing about the true nature of their exposure even as the raw numbers climb.

What the record pace means for households

By sector, financial services logged the most frequent compromises at 387, while healthcare rose to 281, reversing a modest decline from the prior year. Because breached records often resurface months later in fraud attempts, the center urged individuals to treat their information as already compromised rather than wait for a specific notice.

Its recommended defenses are straightforward and mostly free. Consumers can freeze their credit files at the major bureaus to block new accounts opened in their name, replace passwords with passkeys where available to blunt credential theft, and switch on multifactor authentication using an app or hardware key rather than text messages. None of those steps stops a breach at its source, but together they narrow the window in which stolen data can be turned into money.

This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.


More from Morning Overview