The Identity Theft Resource Center published its H1 2026 Data Breach Report, and the headline number is the one that will get quoted: 471.2 million victim notices issued in six months, against 297.5 million across the whole of 2025.

The number that should get quoted instead is 76% — the share of notices that disclose no attack vector at all.

The Figures

  • 1,803 data compromises tracked in H1 2026
  • 1,394 confirmed breaches, 77% of total events
  • 471+ million victim notices, exceeding all of 2025
  • Q2 2026: 1,029 compromises, the second-highest single quarter in ITRC’s tracking history
  • Projected annual pace: ~3,600 events, against 3,321 in 2025

Three incidents account for most of the notice volume:

  • Instructure Holdings (Canvas) — 275 million notices, 58% of the entire H1 total
  • Under Armour — 72.7 million
  • SoundCloud — 29.8 million

That concentration is the first thing to understand about the 471 million figure. It is not evidence that breaches got 58% more common. It is evidence that one edtech platform holding student records for a quarter of a billion people got breached, which we covered at the time in the Instructure Canvas breach and again when Instructure paid the ransom.

Victim-notice totals are a measure of where data is concentrated, not how often defenses fail. Compromise counts measure the latter, and they rose about 8% on an annualized basis — a real increase, not a crisis-level one.

The Insider Number Is the Real Signal

21 malicious insider incidents in H1 2026. Three in all of 2025.

That is a sevenfold increase in half the time, off a base small enough that a handful of incidents moves the percentage wildly — so treat the multiple with caution. Treat the direction seriously.

Insider incidents are the hardest category to detect and the least likely to be disclosed, which means 21 confirmed cases in six months probably understates the real figure by a wide margin. They also break the control model most organizations run: an insider does not need an exploit, does not trip perimeter detection, and operates inside the exact access grant their job requires.

The North Korean IT worker programs are part of this trend, and so is the straightforward recruitment of employees by extortion groups — the mechanism behind CrowdStrike’s confirmed insider incident linked to the Scattered Lapsus$ Hunters alliance. When a criminal group can pay an employee more than the employee’s annual salary for a session token, the recruitment economics work in a way they did not five years ago.

ITRC also counted 14 zero-day attacks and 38 supply chain incidents — the latter requiring 280.6 million notices on their own. Thirty-eight incidents produced 60% of the year’s notice volume. That ratio is the whole argument for third-party risk being the dominant structural exposure, made numerically.

Healthcare

  • 281 healthcare data compromises in H1 2026
  • 11.7 million patients affected by ITRC’s tracking
  • 28.8 million by HHS OCR data as of July 23
  • 7 healthcare mega-breaches exceeding 1 million notices each

The gap between 11.7 million and 28.8 million is not an error in either dataset. ITRC counts what it can confirm from public notices; OCR counts what covered entities report to the regulator. The regulator’s number is 2.5 times larger, which tells you how much healthcare breach impact never reaches a public notice a tracker can read.

The Disclosure Problem

1,378 of 1,803 notices — 76% — included no information about the attack vector. Only 24% said what happened.

ITRC has been raising this for years and the number keeps getting worse. It is worth being clear about the consequences, because “companies should disclose more” sounds like a preference rather than an operational problem.

It makes the data unusable for defense. ITRC’s own vector breakdown shows 157 phishing/smishing/BEC incidents, 125 system and human error, 76 ransomware — and 402 unclassified events. The largest category is “we don’t know.” No CISO can prioritize controls against a threat distribution where the plurality bucket is empty.

It prevents victims from acting appropriately. A person notified of a ransomware breach at a healthcare provider faces a different risk profile than one notified of an insider exfiltration at a data broker. Both get the same letter and the same twelve months of credit monitoring.

It hides the timelines. No public dataset measures the interval between intrusion and notification, which is the point we made in our analysis of the notification delay liability gap. Vector omission compounds it: not only can nobody measure how long organizations take to notify, nobody can measure what they were slow about.

The 76% is not accidental. Attack-vector disclosure creates litigation exposure and regulatory attention, and no statute in the US requires it in most notification contexts. Companies omit it because omitting it is free.

Reading the Report Correctly

Three takeaways, in order of confidence:

Concentration risk is the dominant variable. One breach produced 58% of the notices. Thirty-eight supply chain incidents produced 60%. The organizations that hold data on hundreds of millions of people are a small set, and their individual security posture now determines national breach statistics. This tracks what we found in the 2026 mid-year breach review.

Insider risk is moving and undermeasured. Twenty-one confirmed incidents from a base of three. Small numbers, clear direction, and a category that structurally underreports.

The notice volume is a bad headline metric. 471 million is a real count of letters sent, and it means almost nothing about whether defenses are improving. Compromise counts, dwell time and notification latency would tell you that. Two of those three are not tracked at all.

The ITRC report is the best public dataset available on US breach activity, and its most valuable finding this cycle is a measurement of its own blind spot. Three quarters of the record says a breach occurred and declines to say how.

Sources