The Identity Theft Resource Center recorded 1,803 data compromises in the first half of 2026, generating an estimated 471 million victim notices — more than the 297.5 million issued in the whole of 2025.
That comparison has carried most of the coverage, and it is accurate. It is also almost entirely the work of one incident.
Where the notices actually came from
Three breaches dominate the half.
| Incident | Victim notices | Share of H1 total |
|---|---|---|
| Instructure Holdings (Canvas) | 275.0M | 58.4% |
| Under Armour | 72.7M | 15.4% |
| SoundCloud | 29.8M | 6.3% |
| Those three combined | 377.5M | 80.1% |
| The remaining 1,800 compromises | 93.7M | 19.9% |
Notice counts as reported from the ITRC H1 2026 report. Percentages and the two summary rows are RECATOOLS arithmetic against the 471.2M half-year total. Three events out of 1,803 account for four fifths of everyone notified.
What happens when you take the biggest one out
The comparison driving the headlines is H1 2026 against all of 2025. It is worth running that comparison twice.
| Measure | Victim notices | Against all of 2025 |
|---|---|---|
| H1 2026, as reported | 471.2M | 1.58× |
| H1 2026, excluding Canvas | 196.2M | 0.66× — below |
| H1 2026, excluding the top three | 93.7M | 0.31× |
| All of 2025, for reference | 297.5M | — |
RECATOOLS arithmetic. Removing the single largest incident takes the half-year total below the whole of 2025. This is not an argument that the mega-breach does not count — 275 million people were notified — but the "already worse than last year" framing rests on one event rather than on a broad deterioration.
A huge number of people were exposed this half, but the typical organisation's experience did not change nearly as much as the total suggests.
Incidents up slightly, exposure up sharply
The count of compromises is rising, but modestly. At 1,803 for the half, the year is tracking toward roughly 3,600 against 3,321 in 2025 — an increase of about nine per cent.
Victim notices are a different story, because the average breach now reaches far more people — and how much further depends entirely on whether the outlier is included.
| Period | Notices per compromise | Against 2025 |
|---|---|---|
| 2025, full year | ~89,600 | — |
| H1 2026, as reported | ~261,300 | 2.92× |
| H1 2026, excluding Canvas | ~108,900 | 1.22× |
RECATOOLS arithmetic dividing reported victim notices by reported compromise counts. Including the largest incident, the average breach appears to reach nearly three times as many people as last year. Excluding it, the increase is closer to a fifth.
The frequency of incidents has barely moved; their scale has.
Two per cent of incidents, sixty per cent of notices
The mechanism behind that is visible in the supply-chain figures. The ITRC counted 38 supply-chain incidents in the half, which produced 280.6 million notices.
Those 38 events are 2.1 per cent of all compromises and 59.6 per cent of all victim notices. A single supply-chain compromise reaches everyone downstream, so a handful of these events can easily outweigh eighteen hundred ordinary ones.
The second quarter did the work
The half was not evenly distributed either. The ITRC counted 1,029 compromises in the second quarter, which it describes as the second-highest single-quarter total in its tracking history. That leaves 774 for the first quarter, a rise of about a third between them.
Even without the mega-breaches, the acceleration in the second quarter would still matter: it reflects a rise in the number of events, not just the number of people caught in them.
Attacks reach ten times further than mistakes
The report splits causes two ways — how often something happens, and how many people it reaches. The two do not line up.
| Cause | Share of breaches | Share of victim notices | Reach per incident |
|---|---|---|---|
| Cyberattacks | 69.7% | 92.3% | 1.32 |
| System and human error | 6.9% | 0.9% | 0.13 |
Shares as reported. The reach index is RECATOOLS arithmetic — each cause's share of notices divided by its share of breaches, where 1.0 would mean a cause reaches exactly its proportional number of people. On that basis a breach caused by a cyberattack reaches roughly ten times as many people as one caused by error.
Mistakes are frequent but contained. Attacks are rarer but do far more damage. The distinction matters for budgeting: training can reduce errors, but it does little to stop the attacks generating almost all the exposure.
A compromise is not always a confirmed breach
It is worth remembering what "compromise" means in this context. Of the 1,803 compromises, 1,394 — about 77 per cent — were confirmed data breaches. The remainder are events where exposure occurred or was suspected without meeting that bar.
It is a reasonable way to count, and it means the headline number is deliberately broader than "breaches". Anyone comparing this figure against another organisation's tally should check that both are counting the same thing first.
The transparency number is the one to worry about
Seventy-six per cent of breach notices — 1,378 of them — gave no information about how the attack happened. Only 24 per cent named an attack vector, the lowest share the ITRC has recorded. In 2021 the figure was 93 per cent.
That collapse of 69 percentage points in five years has a practical cost for defenders. Breach notices are one of the few places where defenders learn what actually worked against someone else. A notice that says an incident occurred, without saying how, satisfies a legal duty and teaches nobody anything.
What is actually rising
Underneath the mega-breach distortion, two categories moved in ways that a single large incident cannot explain.
| Category | H1 2026 | All of 2025 | Reading |
|---|---|---|---|
| Malicious insider incidents | 21 | 3 | Seven times the full prior year, in half the time |
| Zero-day attacks | 14 | 17 | On pace for about 28, up around 65% |
| Ransomware | 76 | — | Up 4.1% year on year |
| Phishing, smishing and BEC | 157 | — | The single leading cause of compromises |
Counts as reported. The zero-day annualisation and its percentage are RECATOOLS arithmetic on the half-year figure and assume the second half resembles the first, which it may not. Ransomware and phishing comparatives were reported as rates rather than prior-year counts.
The insider figure, in particular, should not be smoothed over. Twenty-one incidents against three in the whole of the previous year is a small base, so the multiple overstates the trend — but the direction is unambiguous, and insider cases are not addressed by the perimeter controls most of this reporting assumes.
Where the compromises landed
By count rather than by scale, financial services led with 387 compromises and healthcare followed with 281, reversing a slight decline the previous year.
Healthcare shows why incident counts and victim notices tell different stories. It ranks second by number of incidents, yet contributed no breach to the top ten by size, against three in the top five a year earlier, and only seven healthcare breaches exceeded a million notices. A sector can be attacked constantly and still not appear in a list ranked by how many people each attack reached.
The caveats
- Victim notices are not victims. One person breached three times receives three notices, so the total counts notifications rather than people.
- The counts differ by source. ITRC put healthcare patients affected at 11.7 million; federal OCR data as of 23 July gave 28.8 million. Different collection rules produce different totals for the same sector.
- This is US-focused reporting. The ITRC tracks compromises reported in the United States; it is not a global census.
- Annualising a half-year assumes the second half matches the first. Our projections are arithmetic, not forecasts.
- Small bases exaggerate multiples. Three insider incidents rising to twenty-one is a sevenfold increase and also a movement of eighteen cases.
Key takeaways
- 1,803 compromises and about 471 million victim notices in the first half of 2026.
- Three breaches account for 80.1 per cent of those notices; the other 1,800 share the remaining fifth.
- Excluding the largest incident, the half-year total falls below all of 2025.
- 38 supply-chain incidents produced 59.6 per cent of all notices.
- 76 per cent of notices named no attack vector, against 93 per cent disclosure in 2021.