2026 May Become an Ominous Year for ID Theft; The Number of Victims Already Exceeds 2025s Total – Digital Transactions
Identity theft appears to be, unfortunately, having a banner year. The total number of victims—471.2 million—in the first six months of 2026 is 58% greater than the total for all of 2025, 297.5 million, finds the Identity Theft Resource Center.
And the number of data breaches has soared, too. In the first six months of 2026 there have been 1,803 incidents, up 4.1% from 1,732 in the same period in 2025.
There were 387 data-theft incidents in the financial-services category in the 2026 first half, down from 396 in the 2025 first half. Healthcare incidents, at 281 this year, were down from 270 in the corresponding 2025 period. Rounding out the top three targets, professional services counted 269 incidents in the first six months of 2026, up from 248 a year prior.


These figures do not portend well for the rest of the year, the ITRC president suggests.
“Data breaches are not predictable, but the fact that we are more than halfway to another record-breaking year is a sign that there are a lot of identity scams and fraud headed our way,” James E. Lee, ITRC president, says in a statement. “At the same time, we are facing an unprecedented transparency crisis that leaves consumers and businesses largely in the dark about their actual risk exposure because the state laws designed to inform and protect us simply do not work.”
A few factors are driving the 2026 surge. There were 21 events that came from insider wrongdoing, much higher than the three events in all of 2025, ITRC says. “Insider threats are particularly costly because they bypass perimeter defenses, often involve sensitive high-value data, and can go undetected longer than external attacks. The jump may reflect both a genuine increase in malicious insider activity and improved detection capabilities,” the ITRC report notes.
Mega-breaches also increased. Just two breaches so far, Canvas with 275 million victims and Under Armour with 72.7 million victims, account for more victim notices than in all of 2025. El Cajon, Calif.-based ITRC says that zero-day attacks— when an attacker takes advantage of an unknown or unaddressed security flaw in computer software, IBM says—are approaching last year’s total. There have been 14 in the first half of 2026, compared with 17 in all of 2025.
Other factors also are having an impact. ITRC says only 24% of the first-half 2026 breach notices revealed the attack-vector details, the lowest rate ever recorded. In 2020, by comparison, nearly 100% of notices disclosed the root cause of the incidents.
“The Cyberattacks: Not Specified subcategory now absorbs 972 events in H1 2026 alone. This opacity prevents consumers, businesses, and policymakers from understanding their true risk exposure or taking meaningful preventive action,” ITRC says.
Attackers may see publicly traded companies as potential targets. While these businesses only account for 10% of compromises, they generated 83% of breach notices. This is a reflection of the scale of consumer data held by these businesses, ITRC says, which might make them more attractive targets.