Every six months, a nonprofit that tracks identity crime totals up how many notices companies sent telling people their personal data had been exposed. The tally for the first half of 2026 landed in July, and it did not just add to a running total, it surpassed the number of notices sent during the entirety of the previous year in half the time. A handful of enormous breaches, rather than a steady stream of smaller ones, drove most of the increase, and the pattern researchers found inside the data points to specific industries carrying a disproportionate share of the risk.
One Breach Accounted for More Than Half the Total
The Identity Theft Resource Center tracked 1,803 data compromises between January and June of 2026, and found that those incidents generated an estimated 471.2 million victim notices, a figure that already eclipses the 297.5 million notices issued across all twelve months of 2025. A single compromise involving Instructure Holdings’ Canvas education platform accounted for roughly 275 million of those notices on its own, or about 58 percent of the half-year total, illustrating how a small number of mega-breaches can now outweigh thousands of smaller incidents combined. Supply-chain attacks more broadly generated 280.6 million victim notices from just 38 initial breach events, ultimately touching 206 separate companies that relied on the compromised vendors, a multiplier effect the report’s authors point to as evidence that a single vendor’s security failure can now cascade across an entire industry far faster than the vendor itself can notify every affected client.
Financial Services and Healthcare Lead in Frequency
Counted by number of incidents rather than notices, financial services recorded the highest frequency of any sector, with 387 separate compromises in the first half of the year. Healthcare compromises rose to 281, reversing a slight downward trend the sector had shown the year before. Manufacturing saw one of the sharpest swings of any industry: the sector generated 74 million victim notices in just six months, compared with only 1.97 million across all of 2025, a jump the ITRC attributes to a small number of large incidents rather than a broad rise in manufacturing-sector attacks. Publicly traded companies made up only about 10 percent of all compromises tracked but accounted for more than 83 percent of victim notices, underscoring how concentrated the exposure has become among large, high-profile targets. James E. Lee, the ITRC’s president, said in the organization’s release that being more than halfway to another record-breaking year is itself a warning sign for the identity scams and fraud attempts likely to follow, adding that a parallel “transparency crisis” leaves both consumers and businesses largely in the dark about their actual risk because the state laws meant to require disclosure often do not compel companies to explain how an intrusion happened.
Malicious Insiders and Vanishing Transparency
Two secondary trends stood out inside the same report. Insider wrongdoing, cases where an employee or contractor deliberately misuses access rather than an outside hacker breaking in, jumped to 21 documented events in the first half of 2026 alone, compared with just three for the entirety of 2025. The ITRC linked part of that rise to technology-sector layoffs and to nation-state recruitment schemes that place operatives inside companies as employees. At the same time, transparency around how breaches actually happen kept falling: only 24 percent of breach notices issued during the period disclosed any detail about the attack vector used, the lowest rate the organization has ever recorded, leaving both consumers and businesses with less information about their real exposure even as the number of incidents climbs. The ITRC’s practical advice for individuals is narrower than the scale of the numbers might suggest: freeze credit files with each of the major bureaus, switch from SMS codes to passkeys wherever a service offers them, and turn on multifactor authentication everywhere it is available, on the theory that a frozen credit file and a passkey-protected login blunt the damage of a breach regardless of which company loses the data next.
A Second Record Year in the Making
If compromises continue at the same pace through the back half of the year, the ITRC projects roughly 3,600 total events for 2026, which would extend a streak of more than 3,000 annual compromises to four consecutive years and surpass the 3,321 compromises recorded in 2025. Zero-day attacks, vulnerabilities exploited before a software vendor has issued a fix, reached 14 events in the first half of 2026, nearly matching the 17 recorded across the entirety of the previous year, a pace the organization partly credits to attackers using AI-assisted tools to locate exploitable flaws faster than defenders can patch them. With victim notices already outnumbering the entire population of the United States, the report’s authors argue that consumers are better served assuming their information has already been exposed somewhere and acting accordingly, rather than waiting for a notice that names them specifically. That framing matters because a single person can receive multiple notices tied to the same stolen information as it gets resold and reused across different incidents, meaning the 471.2 million figure measures notices sent rather than the number of unique individuals affected, even as it points to the same underlying scale of risk.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A granite sarcophagus surfaced in Egypt with its original lid still sealed
- The FBI tells phone owners to delete these toll-payment texts draining accounts nationwide
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- Long-term use of common heartburn pills is linked to kidney and dementia risk