Daniel de la Hoz | Moments | Getty Images
Even as companies devote more resources to cybersecurity, the number of reported data breaches involving consumers’ personal data is increasing at a faster pace than last year’s record.
More than 471 million victim notifications were related to data breaches in the first half of 2026, according to a new report from the Identity Theft Resource Center, a nonprofit organization that helps victims of identity theft and tracks publicly reported data breaches. More than half of these notifications, or 275 million, were due to cyber incidents that occurred with the educational tool “Canvas.”
The six-month tally equates to 297.5 million notices issued in all of 2025, according to the ITRC report. The number of incidents reached 1,803 in the first half of this year, up from 1,732 in the same period in 2025. If the second half of this year is similarly active, the final tally for 2026 will exceed the 3,321 security incidents reported in all of last year.
“We continue to see an ever-increasing number of data breaches,” said ITRC Chairman James Lee. “It doesn’t seem to be slowing down.”
AI plays a role in further breaches
The rise in data breaches comes as artificial intelligence continues to improve, making it easier to exploit vulnerabilities in corporate systems. A new study from IBM shows that between March 2025 and February 2026, one in four breaches were caused by AI, an increase of 56% from the previous year.
Cybersecurity is in the top three priorities for 93% of public company audit committees, according to a 2025 study from Deloitte’s Center for Board Effectiveness and the nonprofit Center for Audit Quality, which focuses on financial reporting integrity. Half of the 237 survey respondents ranked cybersecurity as a top priority.
According to a survey of 3,887 business and technology executives from 72 countries and territories released last October by accounting firm PwC, most companies (78%) polled worldwide said they would increase their cybersecurity budgets over the next 12 months.
Incidents involving malicious insiders are on the rise
Meanwhile, the ITRC report said there were 21 events involving “malicious insiders” in the first half of this year, compared to three in all of 2025. A malicious insider is someone within an organization who uses their access and privileges to steal data.
“The raw numbers don’t seem that big, but if you look at historical trends, insiders aren’t a big source of data breaches,” Lee said. “We’ve never had more than three data breaches involving malicious insiders in a year. That’s 21 in six months.”

Part of the increase is because disgruntled employees who were fired were “stealing information on the go,” Lee said.
Additionally, the ITRC report notes that some organizations have been targeted by scams flagged by the FBI, which use North Korean stolen personal information, deepfake videos of interviews, and AI-generated resumes to place remote IT talent at U.S. companies. “This is perhaps the most important structural factor in malicious insider attacks,” the report states.
Where you live will determine whether you will be discovered and what will be said if you are discovered.
james lee
Director of the Identity Theft Resource Center
Lee said malicious insider attacks are probably occurring more frequently than reported, as only 24% of notifications sent to affected consumers in the first half of 2026 included details of a data breach. 93% of notifications sent in 2021 included incident details.
But Lee said the lawsuits may have led companies to reduce what they include in their notices to only what’s necessary, which varies by state.
“We don’t have uniformity,” Lee said. “Where you live will determine whether you will know (about the breach) and what you will be told if you do.”
Consumers should consider a “Fort Knox” of protection
For consumers, the best way to prevent their personal information from being used is to protect their trust, experts say.
You can check your credit report from a credit bureau. equifax, Experian and trans union “You can use AnnualCreditReport.com once a week for free,” said credit expert John Alzheimer, president of the Ulzheimer Group in Atlanta. Doing so will not affect your credit score.
You can also sign up for a free credit monitoring service that alerts you if anything changes in your report that could indicate fraud, Alzheimer said.

Alternatively, you could place a fraud alert on your credit report, he said, which would “force lenders to contact you if they receive an app in your name to verify it’s genuine.”
The safest way to prevent someone from taking out a loan in your name is to freeze your credit with each credit company. This means they won’t be able to check your credit report. This free precaution typically prevents banks from approving new accounts or loans in your name.
However, if you need to legally apply for a loan or credit account, you must first temporarily lift your credit freeze.
This can be troublesome, Ulzheimer says.
“But this is like the Fort Knox of credit protection. If you have serious concerns about your information being exposed, I always suggest a credit freeze,” he said. “Now, remember to unzip it when you apply for credit.”
