---
title: Breach Tracker ITRC Reports Data Compromises on Pace for Record Fourth Straight Year, With Insider Threats Surging Sevenfold
description: The Identity Theft Resource Center tracked 1,803 data compromises in H1 2026, with 471M victim notices already issued. Insider wrongdoing rose sevenfold.
author: Darie Nani (Editor-in-Chief)
date: 2026-07-24T09:25:02.301Z
updated: 2026-07-24T09:34:04.293Z
canonical: https://www.sovereignmagazine.com/article/itrc-h1-2026-data-breach-report-insider-threats
image: https://cdn.nanimediahouse.com/itrc-h1-2026-data-breach-report-24629.webp
categories: Science &amp; Tech
content_type: News
region: United States
publication: Sovereign Magazine
schema_type: Article
---

More than 471 million victim notices were issued in the first six months of 2026, a figure that already exceeds the 297.5 million issued across all of 2025 and points toward a fourth consecutive record-breaking year for data compromises in the United States.

The Identity Theft Resource Center, a San Diego-based nonprofit that tracks breaches across sectors, recorded 1,803 data compromises in H1 2026. The second quarter alone produced 1,029 events, the second-highest single-quarter total in ITRC history. At the current pace, the annual count could reach approximately 3,600 compromises, extending a streak that has exceeded 3,000 events each year since 2023.

Founders and operators reading those figures should note that the headline number understates the structural shift underway. The composition of attacks is changing in ways that expose organisations previously considered lower-risk, while the information available to defenders is shrinking at the same time.

## The Canvas Breach and the Return of Mega-Compromises

A single event dominated the H1 victim count. A compromise of Instructure Holdings' Canvas education platform generated an estimated 275 million victim notices, representing 58 percent of the half-year total. The breach, which affected approximately 9,000 schools and exposed names, email addresses, and private messages, was attributed to the ShinyHunters hacking group. No confirmed US-only victim count has been released.

The Canvas event illustrates a pattern the ITRC calls a severe multiplier effect in supply chain attacks. Across H1 2026, just 38 initial breach events tied to supply chain compromises generated 280.6 million victim notices and affected 206 total entities. That ratio reflects how deeply interconnected enterprise software stacks have become and how a single vendor failure now propagates across entire customer bases.

Public companies sit at the apex of this concentration risk. They accounted for only 10.3 percent of compromises but generated 83.4 percent of all victim notices in H1 2026.

## Insider Wrongdoing, Zero-Days, and a Transparency Collapse

Beyond the mega-breach numbers, three operational trends are accelerating simultaneously.

Insider wrongdoing recorded 21 events in the first half of the year, compared with three in all of 2025, a sevenfold increase. The ITRC attributes the surge to two drivers: tech-sector layoffs creating a pool of disgruntled or financially pressured employees, and nation-state recruitment schemes actively targeting workers with privileged access. The financial services sector recorded the highest frequency of compromises overall at 387 events, while healthcare reversed a mild downward trend to reach 281 compromises.

Zero-day attacks, which exploit software flaws before patches exist, rose to 14 events in H1 2026, nearly matching the 17 recorded across all of 2025. The ITRC links the acceleration partly to AI tools capable of uncovering vulnerabilities faster than human security teams can identify and remediate them.

Manufacturing produced 74 million victim notices in H1 2026, against 1.97 million for the whole of 2025, driven by supply chain exposure. Running parallel to all of this is what the ITRC describes as a transparency crisis: only 24 percent of breach notices issued in H1 2026 contained information about the attack vector, the lowest disclosure rate the organisation has ever recorded.

> "Data breaches are not predictable, but the fact that we are more than halfway to another record-breaking year is a sign that there are a lot of identity scams and fraud headed our way. At the same time, we are facing an unprecedented transparency crisis that leaves consumers and businesses largely in the dark about their actual risk exposure because the state laws designed to inform and protect us simply do not work."
> — James E. Lee, President, Identity Theft Resource Center

## What Founders and Operators Should Do Now

The ITRC's operational recommendations break into two tracks.

For individuals, the centre advises a credit freeze through FrozenPII.com, a switch to passkeys to eliminate credential-theft exposure, and the activation of multifactor authentication on all accounts. Given that 471 million notices have already been issued in a country of roughly 335 million people, the statistical case for assuming personal data has already been exposed is straightforward.

For businesses, the centre's guidance centres on four controls: adopting zero-trust architecture to limit lateral movement, implementing least-privilege access to reduce the blast radius of both external attacks and insider wrongdoing, vetting supply chain vendors on a continuous rather than point-in-time basis, and voluntarily disclosing attack vectors when a breach occurs. That last point cuts against the instinct toward legal minimalism in disclosure, but the ITRC frames transparency as a trust asset rather than a liability.

The insider threat figure deserves specific attention from operators managing post-layoff workforces or contractors with elevated system access. Least-privilege access controls, regular access audits, and offboarding checklists are not new concepts, but the sevenfold increase in insider events suggests they are not yet standard practice at most organisations.

[The ITRC's H1 2026 Data Breach Report](https://www.idtheftcenter.org/post/mega-breaches-malicious-insiders-h1-2026-data-breach-report/), which includes sector-by-sector breakdowns and trend data, was released on 22 July 2026.

The ITRC's H1 2026 Data Breach Report and free consumer support are available at [idtheftcenter.org](https://www.idtheftcenter.org/).

## FAQ

**Q: Is the Identity Theft Resource Center a legitimate organisation?**
Yes. The ITRC is a nationally recognised nonprofit founded in 1999 with a stated mission to prevent and reduce the impact of identity theft, scams, and fraud. It provides free consumer support and publishes regular research on data breach trends. Its H1 2026 report is the source for the figures in this article.

**Q: What should you do if you suspect your identity has been stolen in 2026?**
The ITRC recommends freezing your credit files through FrozenPII.com, which prevents new accounts from being opened in your name. Beyond that, switching to passkeys where available eliminates one of the most common theft vectors, and enabling multifactor authentication on financial and email accounts limits the damage if credentials are already exposed. Free support is available through the ITRC at idtheftcenter.org or by calling 888.400.5530.

**Q: What should you do if your Social Security number was part of a data breach?**
A credit freeze is the most effective immediate step. Unlike a fraud alert, which asks lenders to verify identity before extending credit, a freeze prevents new credit inquiries entirely until you lift it. You can also place fraud alerts with the three major credit bureaus. The ITRC advises monitoring financial accounts and benefit statements for unusual activity, since Social Security numbers are frequently used in tax fraud and benefits theft rather than immediate financial account takeover.
