Surge in ‘mega breaches’ and AI exploits drive record data breach notifications in 2026

INDIANA — A new report from the Identity Theft Resource Center (ITRC) reveals a staggering surge in data breach notifications during the first six months of 2026. Driven by massive “mega breaches,” artificial intelligence-powered exploits, and a sevenfold increase in malicious insider attacks, over 471.2 million victim notifications were issued in the first half of the year alone.

The figure eclipses the 297.5 million notices sent during all twelve months of 2025. If the current rate of 1,803 tracked compromises holds, 2026 is on track to set a record, potentially exceeding 3,600 total data breaches in a single year.

“If you stacked up all of the victim notices that were issued in the first six months, they would reach into space,” said James E. Lee, president of the ITRC, comparing the physical volume of paper to a stack 16 times higher than Mount Everest.

The Return of the ‘Mega Breach’ & Supply Chain Multipliers

The single largest driver behind the astronomical spike in victim notices is the return of “mega breaches”—compromises affecting more than 100 million individuals.

A major cybersecurity event involving Instructure Holdings’ Canvas education platform generated an estimated 275 million victim notices—accounting for 58% of all notices issued across all industries in the first half of the year. The attack, attributed to the threat group ShinyHunters, impacted roughly 9,000 educational institutions. Other significant mega breaches in H1 included incidents at Under Armour (72.7 million notices) and SoundCloud (29.8 million notices).

The ITRC highlighted how deeply interconnected enterprise software has created a severe “multiplier effect”. Just 38 initial supply chain incidents generated more than 280 million victim notices across 206 downstream entities.

AI Tools and Rising Insider Threats

Security experts emphasize that changing tactics and technology are altering the threat landscape:

  • AI-Accelerated Exploits: Cybercriminals are increasingly leveraging artificial intelligence to scan software for zero-day flaws at speeds human defense teams cannot match. The ITRC recorded 14 zero-day attacks in H1 2026—nearly matching the 17 recorded across the entirety of 2025.
  • Spike in Malicious Insiders: The report documented 21 malicious insider threat events in the first six months of 2026—a sevenfold increase over all of 2025 (3 incidents). Before 2026, the ITRC had never recorded more than three employee-driven breaches in a full year. Experts attribute the surge to tech-sector economic uncertainty, mass layoffs, and aggressive recruitment schemes by foreign nation-states targeting workers with elevated system access.

Industry Sector Impact & The ‘Transparency Crisis’

While the technology sector produced the highest overall volume of victim notices due to the Canvas breach, other sectors experienced significant volatility:

  • Financial Services: Led all sectors in breach frequency with 387 total compromises.
  • Healthcare: Experienced 281 compromises, reversing a brief downward trend observed in late 2025.
  • Manufacturing: Saw victim notices skyrocket from 1.97 million in 2025 to 74 million in H1 2026 due to supply chain vulnerability exposure.

Parallel to these attacks is what the ITRC calls a growing “transparency crisis.” Only 24% of breach notices issued in H1 2026 disclosed the specific attack vector (such as phishing, ransomware, or software vulnerabilities)—the lowest disclosure rate ever recorded by the organization.

Actionable Steps for Consumers and Businesses

Because of the massive volume of exposed credentials, the ITRC warns that consumers should operate under the assumption that their personal information has already been compromised.

Recommendations for Individuals

  • Freeze Credit Files: Place a freeze on credit reports via official portals such as FrozenPII.com or major credit bureaus to prevent unauthorized account creation.
  • Adopt Passkeys & MFA: Transition away from traditional passwords toward passkeys and enforce multi-factor authentication (MFA) across all personal and work accounts.

Recommendations for Businesses

  • Zero-Trust Architecture: Implement strict “zero-trust” security framework protocols and “least-privilege” access policies to minimize potential damage from insider threats.
  • Supply-Chain Vetting: Real-time monitoring and continuous security vetting of third-party vendors and software integrations.
  • Public Transparency: Voluntarily detail attack vectors when reporting incidents to help industry peers patch vulnerabilities and build consumer trust.