Data Breach Notifications This Year Have Already Surpassed Last Year's Total, with Artificial Intelligence's Role Expanding

Deep News08-14 20:41

Even as companies allocate more resources to cybersecurity, the number of disclosed data breaches involving consumer personal information is on track to break last year's record. The Identity Theft Resource Center (ITRC), a nonprofit that assists victims of identity theft and tracks publicly disclosed data breaches, reports that in the first half of 2026, various data breaches generated over 471 million victim notifications. A cybersecurity incident at the educational platform Canvas accounted for more than half of these, involving 275 million notifications.

ITRC data shows that the total number of breach notifications sent in all of 2025 was 297.5 million, meaning the first half of this year alone has already exceeded that figure. There were 1,803 security incidents in the first half of this year, up from 1,732 in the same period of 2025. If the frequency of incidents in the second half matches the first half, the total number of incidents for 2026 will surpass last year's 3,321. ITRC President James Lee stated, "The number of data breaches continues to climb, and there are currently no signs of a slowdown."

Increase in Breaches Involving Artificial Intelligence

Continuous advancements in 人工智能 capabilities are making it easier for attackers to exploit vulnerabilities in enterprise systems, leading to an increase in data breaches. A new study by IBM shows that between March 2025 and February 2026, one-quarter of data breaches were carried out with the help of 人工智能, a 56% increase year-over-year. A 2025 survey by Deloitte's Center for Board Effectiveness and the Center for Audit Quality found that 93% of public company audit committees rank cybersecurity as one of their top three priorities; among 237 respondents, half placed cybersecurity first. A survey of 3,887 corporate executives and technology leaders across 72 countries by accounting firm PwC in October last year revealed that 78% of global companies plan to increase their cybersecurity budgets in the next 12 months.

Surge in Incidents Involving Malicious Insiders

Meanwhile, the ITRC report notes that 21 "malicious insider" incidents were recorded in the first half of this year, compared to just three in all of 2025. Malicious insiders are individuals within an organization who use their access privileges to steal data. "The absolute numbers don't seem huge, but historically, insiders haven't been a primary source of data breaches," said James Lee. "In previous years, malicious insider incidents never exceeded three, yet we've seen 21 in just half a year." Some of this growth stems from disgruntled laid-off employees who "steal company information upon departure." The ITRC report also mentions that some companies have encountered a scam previously warned about by the FBI: North Korean groups steal identities, use deepfake interview videos and AI-generated resumes, and arrange for remote IT technicians to infiltrate US companies. The report states, "This is arguably the most central structural factor driving malicious insider attacks." Lee indicated that the actual number of malicious insider attacks is likely higher than what is publicly reported. In the first half of 2026, only 24% of breach notifications sent to victims included details of the incident; in 2021, that figure was 93%. However, Lee noted that related lawsuits have prompted companies to condense notification content, only including information mandated by state laws, which vary widely. "There is no national standard," Lee said. "Which state you live in determines whether you receive a breach alert; and even if you get a notification, how much information you see differs by location."

Consumers Can Adopt 'Fort Knox-Level' Protection

Experts suggest that the key to protecting personal information from misuse lies in credit protection. John Ulzheimer, a credit expert and head of the Atlanta-based credit counseling firm The Ulzheimer Group, pointed out that consumers can obtain free credit reports from the three major credit bureaus (Equifax, Experian, and TransUnion) weekly through AnnualCreditReport.com, without negatively impacting their credit scores. They can also sign up for free credit monitoring services that send alerts when suspicious changes appear on their reports. Additionally, consumers can place a fraud alert on their credit reports, which "requires lenders to verify the application's authenticity with you when someone applies for credit using your identity." The most secure way to prevent others from using your identity to apply for loans is to request a **credit freeze** from all three credit bureaus. Once frozen, third parties cannot access your credit report. This free protective measure typically prevents banks from opening accounts or issuing loans in your name. However, if you need to take out a loan or apply for credit yourself, you must temporarily lift the freeze. Ulzheimer acknowledged that this process can be inconvenient. "But it's the Fort Knox of credit protection. If you are very worried that your personal information has been leaked, I always recommend enabling a credit freeze and just remembering to thaw it when you need to apply for credit."

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Comments

We need your insight to fill this gap
Leave a comment