2 Sources
[1]
Data breach notices have already blown past last year's total -- and AI is playing a growing role
* In the first half of 2026, there were 1,803 reported data compromises, compared with 1,732 during the same time last year, according to a new report from the Identity Theft Resource Center. * A higher-than-usual number, 21, involved "malicious insiders," attributed to both disgruntled laid-off workers and a remote-worker job scam involving North Korea. * Consumers should take steps to protect their personal information from being used to open accounts in their name, experts say. In this article * EXPN-GB Follow your favorite stocksCREATE FREE ACCOUNT Daniel De La Hoz | Moment | Getty Images Even as companies devote more resources to cybersecurity, the number of reported data breaches involving consumers' personal data is on pace to surpass last year's record. More than 471 million million victim notices were associated with data compromises in the first half of 2026, according to a new report from the Identity Theft Resource Center, a nonprofit that assists identity-theft victims and tracks publicly reported data breaches. A cyber incident that occurred at education tool Canvas accounted for more than half of those notices, at 275 million. The half-year tally compares with 297.5 million notices issued in all of 2025, the ITRC report shows. The number of incidents reached 1,803 in the first half of the year, up from 1,732 during the same period in 2025. If the second half of the year is as active, the final tally for 2026 will eclipse the 3,321 security incidents reported for all of last year. Read more CNBC personal finance coverage "We continue to see this ever-increasing number of data breaches," said James Lee, president of the ITRC. "That does not appear to be slowing down." AI involved in more breaches The increase in data breaches comes as artificial intelligence's ever-improving capabilities make it easier to exploit vulnerabilities in company systems. Between March 2025 and February 2026, one in four breaches was AI-enabled, up 56% from a year earlier, according to a new study from IBM. Cybersecurity ranks among the top three priorities for 93% of audit committees at public companies, according to a 2025 survey released by Deloitte's Center for Board Effectiveness and the Center for Audit Quality, a nonprofit focused on the integrity of financial reporting. Half of the survey's 237 respondents ranked cybersecurity as the leading priority. Most polled companies around the globe -- 78% -- indicated they would boost their cybersecurity budgets over the next 12 months, according to a survey of 3,887 business and technology executives from 72 countries and territories released by accounting firm PwC last October. More incidents involving malicious insiders Meanwhile, the ITRC report said 21 events in the first half of this year involved "malicious insiders," up from three events for all of 2025. A malicious insider is a person within an organization who uses their access or authority to steal data. "The raw number doesn't look very big, but when you look at the historical trend line, insiders haven't been big sources of data breaches," Lee said. "We've never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months." watch now VIDEO8:5408:54 AI and elderly scams: Sens. Scott & Gillibrand on the new frontier of senior fraud Squawk Box Part of the increase is due to disgruntled laid-off employees who "were stealing information on their way out the door," Lee said. Additionally, the ITRC report notes that some organizations have been targeted by a scam the FBI has flagged in which North Korea places remote information technology workers in U.S. businesses using stolen identities, deepfake videos during interviews and AI-generated resumes. "This is arguably the most significant structural driver of malicious insider attacks," the report reads. Where you live determines if you find out [about a breach], and if you do find out, what you're told. James Lee President of the Identity Theft Resource Center Lee said that malicious insider attacks probably occur more frequently than reported because only 24% of notices sent to affected consumers in the first half of 2026 included details of the data breach. In 2021, 93% of notices sent out included specifics of the incident. However, Lee said court cases may have led companies to reduce what they include in their notices to only what is required, which varies from state to state. "We don't have any uniformity," Lee said. "Where you live determines if you find out [about a breach], and if you do find out, what you're told." Consumers should consider the 'Fort Knox' of protection For consumers, the best way to protect your personal information from being used is to protect your credit, experts say. You can review your credit reports from the credit-reporting firms -- Equifax, Experian and TransUnion -- at AnnualCreditReport.com for free as often as once weekly, said John Ulzheimer, a credit expert and president of The Ulzheimer Group in Atlanta. Doing so does not affect your credit score. You also can sign up for free credit-monitoring services that alert you when something changes on your report that could be indicative of fraud, Ulzheimer said. watch now VIDEO0:2200:22 What's a credit freeze? Your Money Alternatively, you can put a fraud alert on your credit report, which "would compel lenders to contact you if they receive an app in your name to confirm it's authentic," he said. The most secure way to guard against someone getting a loan in your name is to freeze your credit at each of the credit firms, which means your credit report cannot be checked. This free precaution generally will prevent a bank from approving a new account or loan in your name. However, if you need to legitimately apply for a loan or credit account, you have to first lift your credit freeze temporarily. This can be an annoyance to do, Ulzheimer said. "But it's kind of the Fort Knox of credit protection. If you're meaningfully concerned about your information being out there, I always suggest a credit freeze," he said. "Then just remember to thaw it when you want to apply for credit." Choose CNBC as your preferred source on Google and never miss a moment from the most trusted name in business news.
[2]
Data breach notices surpass 2025 record as AI attacks rise
The Identity Theft Resource Center tracked 1,803 data compromises in the first half of 2026, putting the year on pace to surpass the record 3,321 incidents recorded in all of 2025. That figure outpaces the 297.5 million victim notices the ITRC recorded across all of 2025. A single breach involving Instructure Holdings' Canvas education platform accounted for an estimated 275 million of those notices, or roughly 58% of the H1 total, according to the ITRC. Supply chain attacks generated another 280.6 million victim notices from just 38 initial breach events, affecting 206 total entities. The surge comes as artificial intelligence is making attacks easier to execute. One in four malicious breaches between March 2025 and February 2026 were AI-enabled, a 56% increase over the prior year, according to an IBM $IBM study based on 602 organizations globally. Those AI-enabled breaches -- driven by deepfake impersonation and AI-enabled malware -- cost companies an average of $6 million, roughly $1 million above the global breach average of $4.99 million. "We continue to see this ever-increasing number of data breaches," ITRC President James Lee told CNBC. "That does not appear to be slowing down." Malicious insiders are also a growing concern. According to the ITRC, insider wrongdoing events jumped from three for the whole of 2025 to 21 in just the opening six months of 2026. Lee told CNBC that dismissed employees exfiltrating data before their departure account for some of the rise, alongside a North Korean scheme the FBI has warned about in which operatives embed themselves in American companies by fabricating identities, submitting AI-generated resumes, and using deepfake video during hiring interviews. Compounding the problem is a sharp decline in breach notice transparency. Just 24% of breach notifications sent to consumers in H1 2026 described how the incident happened, the ITRC reported -- the lowest share the organization has on record. In 2021, 93% of notices included such specifics. "We don't have any uniformity," Lee said. "Where you live determines if you find out [about a breach], and if you do find out, what you're told." The ITRC recommends that consumers freeze their credit files and switch to passkeys to reduce exposure. For businesses, the organization advises adopting a zero-trust architecture and implementing least-privilege access controls.
Share
Copy Link
The Identity Theft Resource Center tracked 1,803 data compromises in the first half of 2026, already surpassing last year's pace. A single Canvas breach affected 275 million people, while AI-enabled breaches now account for one in four incidents. Malicious insider attacks jumped from 3 in all of 2025 to 21 in just six months, driven by disgruntled employees and North Korean operatives using deepfake interviews.
The first half of 2026 witnessed 1,803 reported data compromises, putting the year on track to eclipse 2025's record of 3,321 security incidents, according to a new report from the Identity Theft Resource Center
1
2
. This represents an increase from 1,732 incidents during the same period last year. More alarmingly, data breach notices reached 471 million in just six months, already surpassing the 297.5 million victim notices issued across all of 20251
.A cyber incident at Canvas, an education tool owned by Instructure Holdings, accounted for approximately 275 million of those notices—roughly 58% of the first-half total
2
. Supply chain attacks generated another 280.6 million victim notices from just 38 initial breach events, affecting 206 total entities2
. "We continue to see this ever-increasing number of data breaches," said James Lee, president of the ITRC. "That does not appear to be slowing down."1
Artificial intelligence is playing an expanding role in cybersecurity threats. Between March 2025 and February 2026, one in four breaches was AI-enabled, representing a 56% increase from the previous year, according to an IBM study covering 602 organizations globally
1
2
. These AI-enabled breaches—driven by deepfake impersonation and AI-enabled malware—cost companies an average of $6 million, roughly $1 million above the global breach average of $4.99 million2
.The growing sophistication of AI attacks matters because it lowers the barrier to entry for cybercriminals while making it harder for companies to defend against threats. Despite increased investment—78% of companies globally indicated plans to boost cybersecurity budgets over the next 12 months according to a PwC survey of 3,887 executives—the threat landscape continues to evolve faster than defenses can adapt
1
. Cybersecurity now ranks among the top three priorities for 93% of audit committees at public companies1
.Malicious insider attacks have emerged as a significant new threat vector. The ITRC report documented 21 events involving malicious insiders in the first half of 2026, compared to just three for all of 2025
1
2
. "The raw number doesn't look very big, but when you look at the historical trend line, insiders haven't been big sources of data breaches," Lee explained. "We've never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months."1
Part of this surge stems from disgruntled laid-off employees stealing information before their departure
1
. More concerning is a North Korean scheme flagged by the FBI in which operatives embed themselves in U.S. businesses using stolen identities, AI-generated resumes, and deepfake interviews during the hiring process1
2
. The ITRC report identifies this as "arguably the most significant structural driver of malicious insider attacks."1
Related Stories
A troubling trend compounds the data breach crisis: declining transparency in breach notifications. Only 24% of notices sent to affected consumers in the first half of 2026 included details about how the breach occurred—the lowest share on record and a dramatic drop from 93% in 2021
1
2
. Lee attributes this to court cases that may have led companies to reduce disclosures to only what state laws require, which varies significantly. "We don't have any uniformity," Lee said. "Where you live determines if you find out [about a breach], and if you do find out, what you're told."1
This lack of transparency makes it difficult for consumers to assess their risk and take appropriate protective measures. It also suggests that malicious insider attacks likely occur more frequently than reported
1
.Experts recommend consumers implement credit protection measures immediately. Review credit reports from Equifax, Experian, and TransUnion at AnnualCreditReport.com as often as weekly
1
. The ITRC also advises freezing credit files and switching to passkeys to reduce exposure2
.For businesses, the ITRC recommends adopting zero-trust architecture and implementing least-privilege access controls to limit insider threat exposure
2
. Organizations should scrutinize remote hiring processes more carefully, particularly for IT positions, given the North Korean infiltration scheme involving deepfake interviews. As AI capabilities continue advancing, expect both attack sophistication and breach costs to climb. The current trajectory suggests 2026 could see over 3,600 reported incidents if the second half matches the first, with victim notices potentially exceeding 900 million.Summarized by
Navi
[1]
20 May 2026•Technology

31 Jul 2025•Technology

02 Jan 2026•Technology

1
Technology

2
Technology

3
Policy and Regulation
