More than 471 million million victim notices were associated with data compromises in the first half of 2026, according to a new report from the Identity Theft Resource Center, a nonprofit that assists identity-theft victims and tracks publicly reported data breaches. A cyber incident that occurred at education tool Canvas accounted for more than half of those notices, at 275 million.
The half-year tally compares with 297.5 million notices issued in all of 2025, the ITRC report shows. The number of incidents reached 1,803 in the first half of the year, up from 1,732 during the same period in 2025. If the second half of the year is as active, the final tally for 2026 will eclipse the 3,321 security incidents reported for all of last year.
AI involved in more breaches
The increase in data breaches comes as artificial intelligence‘s ever-improving capabilities make it easier to exploit vulnerabilities in company systems. Between March 2025 and February 2026, one in four breaches was AI-enabled, up 56% from a year earlier, according to a new study from IBM.
Cybersecurity ranks among the top three priorities for 93% of audit committees at public companies, according to a 2025 survey released by Deloitte’s Center for Board Effectiveness and the Center for Audit Quality, a nonprofit focused on the integrity of financial reporting. Half of the survey’s 237 respondents ranked cybersecurity as the leading priority.
Most polled companies around the globe — 78% — indicated they would boost their cybersecurity budgets over the next 12 months, according to a survey of 3,887 business and technology executives from 72 countries and territories released by accounting firm PwC last October.
More incidents involving malicious insiders
Meanwhile, the ITRC report said 21 events in the first half of this year involved “malicious insiders,” up from three events for all of 2025. A malicious insider is a person within an organization who uses their access or authority to steal data.
“The raw number doesn’t look very big, but when you look at the historical trend line, insiders haven’t been big sources of data breaches,” Lee said. “We’ve never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months.”
Part of the increase is due to disgruntled laid-off employees who “were stealing information on their way out the door,” Lee said.
Additionally, the ITRC report notes that some organizations have been targeted by a scam the FBI has flagged in which North Korea places remote information technology workers in U.S. businesses using stolen identities, deepfake videos during interviews and AI-generated resumes. “This is arguably the most significant structural driver of malicious insider attacks,” the report reads.
Where you live determines if you find out [about a breach], and if you do find out, what you’re told.
James Lee
President of the Identity Theft Resource Center
Lee said that malicious insider attacks probably occur more frequently than reported because only 24% of notices sent to affected consumers in the first half of 2026 included details of the data breach. In 2021, 93% of notices sent out included specifics of the incident.
However, Lee said court cases may have led companies to reduce what they include in their notices to only what is required, which varies from state to state.
“We don’t have any uniformity,” Lee said. “Where you live determines if you find out [about a breach], and if you do find out, what you’re told.”
Consumers should consider the ‘Fort Knox’ of protection
For consumers, the best way to protect your personal information from being used is to protect your credit, experts say.
You can review your credit reports from the credit-reporting firms — Equifax, Experian and TransUnion — at AnnualCreditReport.com for free as often as once weekly, said John Ulzheimer, a credit expert and president of The Ulzheimer Group in Atlanta. Doing so does not affect your credit score.
You also can sign up for free credit-monitoring services that alert you when something changes on your report that could be indicative of fraud, Ulzheimer said.

Alternatively, you can put a fraud alert on your credit report, which “would compel lenders to contact you if they receive an app in your name to confirm it’s authentic,” he said.
The most secure way to guard against someone getting a loan in your name is to freeze your credit at each of the credit firms, which means your credit report cannot be checked. This free precaution generally will prevent a bank from approving a new account or loan in your name.
However, if you need to legitimately apply for a loan or credit account, you have to first lift your credit freeze temporarily.
This can be an annoyance to do, Ulzheimer said.
“But it’s kind of the Fort Knox of credit protection. If you’re meaningfully concerned about your information being out there, I always suggest a credit freeze,” he said. “Then just remember to thaw it when you want to apply for credit.”