The Identity Theft Resource Center recorded 1,803 data compromises in the first half of 2026, generating an estimated 471 million victim notices — more than the 297.5 million issued in the whole of 2025.

That comparison has carried most of the coverage, and it is accurate. It is also almost entirely the work of one incident.

80.1%of all H1 victim notices produced by just three breaches
3 of 1,803compromises behind four fifths of every victim notice in the half
76%of breach notices that named no attack vector — the worst rate on record
increase in malicious insider incidents against the whole of 2025

Where the notices actually came from

Three breaches dominate the half.

Computed by RECATOOLS1 August 2026
IncidentVictim noticesShare of H1 total
Instructure Holdings (Canvas)275.0M58.4%
Under Armour72.7M15.4%
SoundCloud29.8M6.3%
Those three combined377.5M80.1%
The remaining 1,800 compromises93.7M19.9%

Notice counts as reported from the ITRC H1 2026 report. Percentages and the two summary rows are RECATOOLS arithmetic against the 471.2M half-year total. Three events out of 1,803 account for four fifths of everyone notified.

What happens when you take the biggest one out

The comparison driving the headlines is H1 2026 against all of 2025. It is worth running that comparison twice.

Computed by RECATOOLS1 August 2026
MeasureVictim noticesAgainst all of 2025
H1 2026, as reported471.2M1.58×
H1 2026, excluding Canvas196.2M0.66× — below
H1 2026, excluding the top three93.7M0.31×
All of 2025, for reference297.5M

RECATOOLS arithmetic. Removing the single largest incident takes the half-year total below the whole of 2025. This is not an argument that the mega-breach does not count — 275 million people were notified — but the "already worse than last year" framing rests on one event rather than on a broad deterioration.

A huge number of people were exposed this half, but the typical organisation's experience did not change nearly as much as the total suggests.

Incidents up slightly, exposure up sharply

The count of compromises is rising, but modestly. At 1,803 for the half, the year is tracking toward roughly 3,600 against 3,321 in 2025 — an increase of about nine per cent.

Victim notices are a different story, because the average breach now reaches far more people — and how much further depends entirely on whether the outlier is included.

Computed by RECATOOLS1 August 2026
PeriodNotices per compromiseAgainst 2025
2025, full year~89,600
H1 2026, as reported~261,3002.92×
H1 2026, excluding Canvas~108,9001.22×

RECATOOLS arithmetic dividing reported victim notices by reported compromise counts. Including the largest incident, the average breach appears to reach nearly three times as many people as last year. Excluding it, the increase is closer to a fifth.

The frequency of incidents has barely moved; their scale has.

Two per cent of incidents, sixty per cent of notices

The mechanism behind that is visible in the supply-chain figures. The ITRC counted 38 supply-chain incidents in the half, which produced 280.6 million notices.

Those 38 events are 2.1 per cent of all compromises and 59.6 per cent of all victim notices. A single supply-chain compromise reaches everyone downstream, so a handful of these events can easily outweigh eighteen hundred ordinary ones.

The second quarter did the work

The half was not evenly distributed either. The ITRC counted 1,029 compromises in the second quarter, which it describes as the second-highest single-quarter total in its tracking history. That leaves 774 for the first quarter, a rise of about a third between them.

Even without the mega-breaches, the acceleration in the second quarter would still matter: it reflects a rise in the number of events, not just the number of people caught in them.

Attacks reach ten times further than mistakes

The report splits causes two ways — how often something happens, and how many people it reaches. The two do not line up.

Computed by RECATOOLS1 August 2026
CauseShare of breachesShare of victim noticesReach per incident
Cyberattacks69.7%92.3%1.32
System and human error6.9%0.9%0.13

Shares as reported. The reach index is RECATOOLS arithmetic — each cause's share of notices divided by its share of breaches, where 1.0 would mean a cause reaches exactly its proportional number of people. On that basis a breach caused by a cyberattack reaches roughly ten times as many people as one caused by error.

Mistakes are frequent but contained. Attacks are rarer but do far more damage. The distinction matters for budgeting: training can reduce errors, but it does little to stop the attacks generating almost all the exposure.

A compromise is not always a confirmed breach

It is worth remembering what "compromise" means in this context. Of the 1,803 compromises, 1,394 — about 77 per cent — were confirmed data breaches. The remainder are events where exposure occurred or was suspected without meeting that bar.

It is a reasonable way to count, and it means the headline number is deliberately broader than "breaches". Anyone comparing this figure against another organisation's tally should check that both are counting the same thing first.

The transparency number is the one to worry about

Seventy-six per cent of breach notices — 1,378 of them — gave no information about how the attack happened. Only 24 per cent named an attack vector, the lowest share the ITRC has recorded. In 2021 the figure was 93 per cent.

That collapse of 69 percentage points in five years has a practical cost for defenders. Breach notices are one of the few places where defenders learn what actually worked against someone else. A notice that says an incident occurred, without saying how, satisfies a legal duty and teaches nobody anything.

What is actually rising

Underneath the mega-breach distortion, two categories moved in ways that a single large incident cannot explain.

Computed by RECATOOLS1 August 2026
CategoryH1 2026All of 2025Reading
Malicious insider incidents213Seven times the full prior year, in half the time
Zero-day attacks1417On pace for about 28, up around 65%
Ransomware76Up 4.1% year on year
Phishing, smishing and BEC157The single leading cause of compromises

Counts as reported. The zero-day annualisation and its percentage are RECATOOLS arithmetic on the half-year figure and assume the second half resembles the first, which it may not. Ransomware and phishing comparatives were reported as rates rather than prior-year counts.

The insider figure, in particular, should not be smoothed over. Twenty-one incidents against three in the whole of the previous year is a small base, so the multiple overstates the trend — but the direction is unambiguous, and insider cases are not addressed by the perimeter controls most of this reporting assumes.

Where the compromises landed

By count rather than by scale, financial services led with 387 compromises and healthcare followed with 281, reversing a slight decline the previous year.

Healthcare shows why incident counts and victim notices tell different stories. It ranks second by number of incidents, yet contributed no breach to the top ten by size, against three in the top five a year earlier, and only seven healthcare breaches exceeded a million notices. A sector can be attacked constantly and still not appear in a list ranked by how many people each attack reached.

The caveats

  • Victim notices are not victims. One person breached three times receives three notices, so the total counts notifications rather than people.
  • The counts differ by source. ITRC put healthcare patients affected at 11.7 million; federal OCR data as of 23 July gave 28.8 million. Different collection rules produce different totals for the same sector.
  • This is US-focused reporting. The ITRC tracks compromises reported in the United States; it is not a global census.
  • Annualising a half-year assumes the second half matches the first. Our projections are arithmetic, not forecasts.
  • Small bases exaggerate multiples. Three insider incidents rising to twenty-one is a sevenfold increase and also a movement of eighteen cases.

Key takeaways

  • 1,803 compromises and about 471 million victim notices in the first half of 2026.
  • Three breaches account for 80.1 per cent of those notices; the other 1,800 share the remaining fifth.
  • Excluding the largest incident, the half-year total falls below all of 2025.
  • 38 supply-chain incidents produced 59.6 per cent of all notices.
  • 76 per cent of notices named no attack vector, against 93 per cent disclosure in 2021.