1,803 data compromises were tracked by the Identity Theft Resource Center (ITRC) in the first half of 2026 — and at the current pace the year could finish with roughly 3,600 compromises, eclipsing 2025’s record of 3,321.
The scale so far: 1,803 compromises and 471.2 million victim notices
ITRC, a non-profit focused on minimizing the impact of identity theft, scams, and fraud, logged 1,803 data compromises through the first six months of 2026. In the second quarter alone, 1,029 incidents were recorded, the organization says, marking the second-highest quarter on record in its tracking history.
Those incidents produced an estimated 471.2 million breach victim notices in just six months — a total that has already surpassed 2025’s full-year total, driven in large part by a small number of very large events. If the current trend continues, the year could end near 3,600 reported compromises.
One breach dominated notices: the Instructure incident and supply chain totals
ITRC highlights the outsized effect of mega-breaches on aggregate counts. The breach of Instructure resulted in approximately 275 million victim notices, which the ITRC notes represents 58% of recorded notices so far in 2026. Supply chain compromises produced 280.6 million victim notices in total, illustrating how a handful of supply-chain events can account for the majority of exposed records.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleSector breakdown: Financial, Healthcare, Professional Services, Manufacturing, Technology
ITRC’s sector tally for the first half of 2026 identifies the most-compromised sectors by incident count:
- Financial: 387 compromises
- Healthcare: 281 compromises
- Professional Services: 269 compromises
- Manufacturing: 189 compromises
- Technology: 99 compromises
These raw counts do not directly map to victim-notice volumes; the report underscores that a relatively small share of events has produced the bulk of notices so far this year.
Attack patterns: insider wrongdoing, zero-days, and disclosure gaps
Several qualitative trends stand out in ITRC’s tracking. Insider wrongdoing breaches have increased sharply — the report states they rose sevenfold compared with 2025. The incidence of zero-day attacks is also reported as increasing, a rise ITRC associates in part with developments in artificial intelligence.
At the same time, the dataset shows a steep drop in transparency: details about breach attack vectors were included in only 24% of notices, the lowest rate ITRC has recorded. That lower rate of vector disclosure coincides with the other trends ITRC highlights, including the concentration of notices in a small number of events and the growing role of zero-day and insider-driven incidents.
Publicly traded organizations and concentration of victim notices
Publicly traded organizations accounted for 10.3% of events in the ITRC dataset but were responsible for 83.4% of victim notices. That disparity reflects how a minority of incidents involving large, publicly listed entities can create the majority of the consumer-facing impact measured by notice counts.
What this means for technologists, policymakers, and the public
- Technologists and security teams: The reported sevenfold rise in insider wrongdoing and an increase in zero-day attacks — which ITRC links in part to AI — are concrete operational pressures. Low disclosure of attack vectors (24% of notices) reduces the amount of publicly available forensic detail that defenders typically use to harden systems and update detections.
- Policymakers and regulators: The concentration of notices in publicly traded organizations (10.3% of events producing 83.4% of notices) and the outsized impact of supply chain events and a single mega-breach (Instructure’s ~275 million notices) sharpen the policy question about disclosure rules, supply chain oversight, and systemic risk to consumers.
- End users and the public: ITRC’s count — an estimated 471.2 million victim notices in six months — means that large numbers of people already received breach notifications in 2026, often from a small group of very large incidents. Supply chain compromises account for a major share of those notices, underscoring how third-party exposures can affect individuals beyond a single company’s customer base.
The ITRC dataset paints a year of concentration and contrast: a relatively modest number of events creating enormous consumer impact, an increase in insider and zero-day activity, and a simultaneous fall in how often attack vectors are disclosed. If the current trajectory holds, 2026 will set a new annual record for recorded compromises — and the specific mix of mega-breaches, supply-chain fallout, and limited transparency will determine how policymakers, corporate boards, and security teams respond through the remainder of the year.




