U.S. data breaches are on pace for a record in 2026 — and the notices about them are getting less informative
The Identity Theft Resource Center's H1 2026 report shows U.S. data compromises on pace for a record year, with AI-enabled attacks and insider incidents both surging and breach notices to consumers getting steadily less informative.
On August 14, a national news audience got a fresh look at a number that cybersecurity researchers had already been staring at for weeks. The Identity Theft Resource Center’s H1 2026 Data Breach Report, originally released in late July, put the U.S. on pace for a record year of data compromises — 1,803 reported incidents in the first six months, up from 1,732 in the same stretch of 2025. Behind that headline sat a far larger number: 471 million victim notices generated by just 1,029 of those incidents, per GovTech’s original coverage of the ITRC report. The math alone is a story — under 60% of the incidents accounted for essentially all of the human fallout — but it gets stranger once you look at where most of those notices came from.
A single data breach at the education platform Canvas, owned by Instructure, generated roughly 275 million of the 471 million notices — about 58% of the H1 total — according to Quartz. Add in 38 supply-chain attacks that hit 206 downstream organizations and produced another 280.6 million notices on their own, and the H1 picture resolves into something more concentrated than the raw incident count suggests: a relatively small number of very large events, layered on top of an unusually busy baseline. The 1,803 incident total is the record-pace number; the 471 million notices is the record-pace human cost.
What changed between 2025 and 2026, on the evidence the ITRC and IBM both lay out, is the velocity at which attacks are arriving — and the share of them that AI is now powering. Between March 2025 and February 2026, one in four malicious breaches was AI-enabled, up 56% year over year, per a new IBM study cited by CNBC. Quartz’s reporting on the same IBM figures puts the average cost of an AI-enabled breach at $6 million, against a $4.99 million global average across all breaches. Those two numbers — frequency up by more than half, average cost running roughly 20% above the global baseline — are doing a lot of work in explaining why the ITRC’s framing of 2026 leans so heavily on the word “acceleration.”
The insider threat numbers are sharper still. The ITRC counted 21 insider-threat incidents in H1 2026, against just 3 in H1 2025 — a sevenfold jump in a category that historically moves slowly, as GovTech noted when the report first came out. That figure doesn’t separate malicious insiders from negligent ones, and the ITRC’s own framing treats both as part of the same trend: a human-in-the-loop attack surface that, like the external one, is getting faster and harder to attribute in real time. Whether the jump reflects a real change in insider behavior or simply better detection — or, more likely, some mix of the two — is the part the report itself doesn’t try to settle.
There is one figure in the ITRC’s data, though, that does read as a clean regression. Just 24% of breach notices sent to consumers in H1 2026 actually described how the incident happened. In 2021, that figure was 93%. Quartz flagged the collapse directly, and it sits oddly alongside everything else in the report: record incident counts, record notice volumes, AI attacks up by more than half, and simultaneously, the explanations attached to those notices getting shorter and rarer. The pattern is consistent with companies saying less about how a breach occurred at exactly the moment the underlying attacks are getting more sophisticated — a transparency curve running in the opposite direction from the threat curve.
Taken together, the three layers — the raw incident count, the AI-enabled share of malicious breaches, and the insider-threat jump — point at the same shift the ITRC keeps circling in its commentary: the attacker’s toolkit is compounding faster than the disclosure framework around it. A year that is on pace to set a record by every measure the ITRC tracks is also a year in which the public is being told less about how any individual incident actually unfolded. Both of those things can be true at once, and on the ITRC’s numbers, they are.