Identity theft is having a banner year, and not in a good way for the consumers on the other end of collection calls.
The Identity Theft Resource Center tracked 1,803 data compromises in the first six months of 2026, generating an estimated 471.2 million victim notices. That six-month victim total is 58% higher than the 297.5 million notices issued in all of 2025. With more notices issued than there are people in the United States, the ITRC says consumers should simply assume their data has been exposed.
Why it matters: Financial services was the most frequently targeted sector, with 387 compromises in the first half, ahead of healthcare (281) and professional services (269). For an industry that handles sensitive consumer financial data every day, and routinely fields disputes from consumers who are, or believe they are, identity theft victims, the numbers point to more fraud claims, more disputes, and more scrutiny ahead.
The big picture: The surge is being driven by the return of mega-breaches. A single incident involving Instructure Holdings’ Canvas education platform accounted for an estimated 275 million victim notices, 58% of the first-half total. A breach at Under Armour added 72.7 million more. Together, those two events alone generated more victim notices than all of 2025.
Insider wrongdoing is also spiking. The ITRC counted 21 insider incidents in the first half, a sevenfold increase over the three recorded in all of 2025, fueled in part by tech-sector layoffs and North Korean operatives infiltrating U.S. companies as remote IT workers. Zero-day attacks reached 14, approaching the full-year 2025 total of 17.
What they’re saying: “Data breaches are not predictable, but the fact that we are more than halfway to another record-breaking year is a sign that there are a lot of identity scams and fraud headed our way,” said James E. Lee, president of the ITRC. He also pointed to an “unprecedented transparency crisis,” noting that state breach notification laws “simply do not work.”
Only 24% of first-half breach notices disclosed how the attack occurred, the lowest rate the ITRC has ever recorded. In 2021, 93% of notices included that detail.
One more stat worth noting: Publicly traded companies accounted for just 10.3% of compromises but 83.4% of all victim notices, a reflection of the massive consumer databases those companies hold.
At the current pace, 2026 would end with roughly 3,600 compromises, surpassing 2025’s record of 3,321.




