Data Breaches Are Getting Bigger and Companies Are Telling Us Less


The next time a company tells you it suffered a “cybersecurity incident,” don’t expect much of an explanation.

The Identity Theft Resource Center tracked 1,803 publicly reported data compromises during the first half of 2026, according to its new data breach report. Those incidents generated an estimated 471.2 million victim notices, more than double the revised total from the same period last year, and 58% more than were issued during all of 2025.

Victim notices are issued to people whose information was exposed or potentially exposed. They aren’t a count of unique individuals, though — someone caught up in multiple breaches can be counted more than once.

That jump was driven by the return of megabreaches, led by an attack involving the Canvas education platform that accounted for more than half of this year’s victim notices.

Meanwhile, companies are revealing less about how these attacks happen. Only 24% of the breach notices analyzed by the ITRC included details about the attack method, the lowest rate the organization has ever recorded.

That leaves consumers caught up in larger breaches with less information about what went wrong or whether it could happen again.

The number of breaches barely increased, but their reach exploded

The ITRC recorded only 3.3% more breaches than its revised count for the same period last year, but victim notices more than doubled.

That is a sharp reversal from last year, when breaches remained frequent but generally affected fewer people. That smaller scale didn’t last.

An attack involving Instructure’s Canvas education platform generated an estimated 275 million victim notices, accounting for 58% of the 2026 total. An Under Armour breach affected an additional 72.7 million accounts. Those two incidents alone generated more victim notices than the total data compromises recorded last year.

Instructure said it detected unauthorized activity in Canvas on April 29 and a second intrusion on May 7. According to the company’s incident page, the exposed information included usernames, email addresses, course names, enrollment information and messages.

The company said it blocked the attackers’ access and patched the vulnerabilities they exploited, but its incident page doesn’t confirm the ITRC’s estimate of 275 million.

Most breach notices don’t explain what went wrong

The Canvas incident may be an outlier in size, but vague breach notices have become the norm.

Only 24% of the 1,803 breach notices explained what caused the incident. That is the lowest disclosure rate the ITRC has recorded and a sharp drop from 2021, when 93% of notices included that information.

In 77% of cases tracked by the ITRC, the notices didn’t identify the specific nature of the breach — phishing, ransomware, malware or something else. 

Another 402 incident reports contained so little information that the ITRC couldn’t determine even the broad cause.

For consumers, the most important detail is what information was exposed. A stolen password calls for a different response than a stolen Social Security number or credit card number. But people should also be told whether attackers stole employee credentials, exploited an unpatched vulnerability, entered through a third-party vendor or may still have access to the company’s systems.

Knowing the cause can also help other businesses defend themselves against similar attacks.

In the ITRC’s press release, the organization’s president, James E. Lee, called the growing lack of information “an unprecedented transparency crisis” that leaves consumers and businesses unable to understand their actual risk.

A notice saying that an “unauthorized party” accessed “certain information” may meet a company’s legal requirements, but it doesn’t offer much help to the people whose information was taken.

Large layoffs may be fueling insider breaches

Insider wrongdoing — employees or contractors abusing access they already have — was the third most common named attack vector in the first half of 2026, behind phishing and ransomware. The raw total was still relatively small: the ITRC counted 21 incidents, but that was seven times the three it recorded during all of 2025.

The report points to mass layoffs as one possible reason. Employees don’t have to break into a system if they already have access to source code, customer information or internal files, and the risk may begin before anyone is officially let go. Research from data security company Cyberhaven found that data theft by departing employees spikes 720% in the 24 hours before a layoff notification, and can begin months earlier.

That doesn’t mean layoffs automatically turn workers into thieves. The ITRC says improved detection may explain part of the increase, and its report doesn’t say how many of the 21 incidents were directly connected to layoffs.

The report also points to a very different kind of insider — North Korean operatives who use stolen identities and AI-generated resumes to land remote IT jobs at US companies. Okta Threat Intelligence says it tracked more than 130 identities tied to more than 6,500 job interviews. Once hired, the workers can use their company access to steal source code and login credentials. And, in some cases, extort their employers.

Both threats exploit the same weakness — the person taking the data already has permission to be inside the system. That can make insider theft harder to detect than an attacker trying to break in from the outside.

How to protect yourself when companies won’t tell you much

You can’t stop a company from losing information it already has about you, but you can make that information harder to use.

Start by freezing your credit with Equifax, Experian and TransUnion. A freeze is free, doesn’t affect your credit score and makes it harder for an identity thief to open a new credit account in your name. You can temporarily lift it when you need to apply for credit yourself.

Use passkeys, which replace passwords with your face, fingerprint or device PIN, wherever they are available. For accounts that still require passwords, use a password manager to create a different password for every account. Turn on two-factor authentication, preferably through an authentication app or physical security key instead of a text message.

If you receive a breach notice, don’t click any links in it. Scammers can imitate legitimate notices to trick people who are already worried about their data. Go directly to the company’s official website to confirm the breach and find its instructions.

Change any exposed passwords and update every other account where you reused them. Enroll in free credit or identity monitoring if the affected company offers it and watch for unfamiliar charges, password reset emails and new accounts opened in your name.

The Federal Trade Commission recommends checking IdentityTheft.gov for steps based on the specific information exposed.



Source link

  • Related Posts

    New airliner sets record flying 24 hrs nonstop from Australia to France

    A new Airbus passenger jet completed an ultra-long test flight between Australia and France lasting more than 24 hours—paving the way for the world’s longest nonstop commercial flights starting up…

    Ebay Has to Pay $55.7 Million in Settlement for Its Unhinged Harassment Campaign

    A civil litigation case against eBay, filed by the founders of a Massachusetts-based news site that covers ecommerce, has just been settled. The gist of it: The company and former…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Trump meets with Zelenskyy and Netanyahu separately amid wars in Iran, Ukraine

    Trump meets with Zelenskyy and Netanyahu separately amid wars in Iran, Ukraine

    New airliner sets record flying 24 hrs nonstop from Australia to France

    New airliner sets record flying 24 hrs nonstop from Australia to France

    Fantasy football rankings 2026: Busts via the model that called Terry McLaurin’s down season

    Fantasy football rankings 2026: Busts via the model that called Terry McLaurin’s down season

    Air Canada Latest To Introduce Basic Business Class Fare With New Restrictions

    Air Canada Latest To Introduce Basic Business Class Fare With New Restrictions

    Councillors in rural county bordering Calgary vote to pause data centres

    Councillors in rural county bordering Calgary vote to pause data centres

    TSX rises over 150 points Tuesday to new high, U.S. markets post mixed results

    TSX rises over 150 points Tuesday to new high, U.S. markets post mixed results