US Data Breach Victim Notices Exceed 2025 Total in H1 2026

US Data Breach Notices in H1 2026 Already Exceed All of 2025

HIGH
July 29, 2026
5m read
Data BreachThreat IntelligenceSupply Chain Attack

Impact Scope

People Affected

471.2 million

Industries Affected

EducationFinanceHealthcareManufacturing

Geographic Impact

United States (national)

Related Entities

Products & Tech

Canvas

Other

Instructure HoldingsUnder ArmourSoundCloud

Full Report

Executive Summary

The first half of 2026 has seen an alarming escalation in data breaches in the United States, with the number of individuals impacted already surpassing the total for the entire previous year. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), 1,803 data compromises were reported, resulting in a staggering 471.2 million victim notices. This figure eclipses the 297.5 million notices from all of 2025. The primary drivers of this surge are the return of "mega-breaches" and the cascading impact of supply chain attacks. A single incident involving the Canvas education platform from Instructure Holdings accounted for 275 million notices alone. The report also uncovers disturbing trends in the rise of insider threats and a continued lack of transparency from breached organizations.


Threat Overview

The ITRC report highlights several critical trends shaping the data breach landscape in 2026:

  • Mega-Breaches and Supply Chain Attacks: The data is heavily skewed by a small number of massive breaches. Just 38 supply chain attacks were the root cause of incidents that impacted 206 downstream entities and generated over 280 million victim notices. Publicly traded companies, while representing only 10% of breached entities, were responsible for 83% of all victim notifications, underscoring the scale of incidents at large enterprises.
  • Surge in Insider Threats: Malicious insider incidents increased sevenfold, with 21 events in H1 2026 compared to only three in all of 2025. The ITRC links this rise to layoffs in the technology sector and increased recruitment efforts by nation-state actors.
  • Accelerated Zero-Day Exploitation: 14 zero-day attacks were recorded in H1 2026, nearly matching the 17 from all of 2025. This acceleration is partly attributed to AI tools that help attackers discover and weaponize vulnerabilities faster.
  • Lack of Transparency: A record low of only 24% of breach notices provided any information about the attack vector. This opacity hinders the ability of other businesses and individuals to take proactive defensive measures based on real-world threat intelligence.

Technical Analysis

The report's findings reveal key attacker TTPs:

  • Targeting the Supply Chain (T1199 - Trusted Relationship): Attackers are focusing on compromising software vendors, managed service providers, and other third parties to gain access to a multitude of downstream targets. The Instructure/Canvas breach is a prime example of this one-to-many attack model.
  • Insider Threats (T1548 - Abuse Elevation Control Mechanism): Malicious insiders, whether acting out of financial motivation or coercion, abuse their legitimate access to steal data. This vector bypasses perimeter defenses entirely.
  • Exploiting Zero-Days (T1190 - Exploit Public-Facing Application): The rapid exploitation of newly discovered or undisclosed vulnerabilities remains a potent initial access vector, giving defenders little to no time to patch.

Impact Assessment

  • Massive Scale of Exposure: With nearly half a billion notices issued in just six months, a significant portion of the U.S. population has likely been affected by a data breach this year, increasing their risk of identity theft and fraud.
  • Erosion of Trust: The lack of transparency in breach notifications erodes trust between consumers and businesses. When companies fail to explain how a breach occurred, it creates uncertainty and prevents collective defense.
  • Compounding Risk: The data stolen in these breaches (credentials, PII) is often used to fuel further attacks, such as phishing campaigns and credential stuffing, creating a vicious cycle of compromise.

IOCs — Directly from Articles

This article is a trend report and does not contain specific Indicators of Compromise.


Cyber Observables — Hunting Hints

To detect insider threats and supply chain risks, security teams should hunt for:

  • Anomalous Data Access: Monitor for user accounts, especially those with privileged access, accessing large volumes of data or sensitive files that are outside their normal job function. This is key for User Behavior Analysis.
  • Unusual Data Egress: Look for large data transfers to personal cloud storage, USB drives, or external email addresses, particularly from employees who are leaving the company.
  • Third-Party Login Anomalies: Closely monitor login and access patterns from third-party vendor accounts. Alert on logins from new IP ranges or access to new systems.

Detection & Response

  1. Insider Threat Program: Establish a formal insider threat program that combines technical monitoring (UBA, DLP) with HR processes (e.g., monitoring during off-boarding). This aligns with D3FEND's Job Function Access Pattern Analysis (D3-JFAPA).
  2. Third-Party Risk Management (TPRM): Implement a robust TPRM program that includes continuous monitoring of your software and service providers. Require SBOMs (Software Bill of Materials) from vendors to gain visibility into your software supply chain.
  3. Data Discovery and Classification: You can't protect what you don't know you have. Implement tools to continuously discover and classify sensitive data across your environment, so you can apply the strongest protections to your most critical assets.

Mitigation

  1. Zero Trust Architecture: Adopt a Zero Trust mindset. Assume that no user or system is trustworthy by default. Enforce strict access controls, micro-segmentation, and continuous verification for all access requests. This is a core principle of M1030 - Network Segmentation.
  2. Data Loss Prevention (DLP): Deploy comprehensive DLP solutions at the endpoint, network, and cloud levels to detect and block unauthorized exfiltration of sensitive data.
  3. Security Awareness Training: While not a panacea, ongoing training can help employees recognize phishing attempts and understand their role in protecting company data, which can help mitigate both external attacks and unintentional insider risks.

Timeline of Events

1
June 30, 2026
End of the H1 2026 reporting period analyzed by the ITRC.
2
July 29, 2026
This article was published

MITRE ATT&CK Mitigations

Use User Behavior Analytics (UBA) to detect anomalous activity indicative of an insider threat.

Implement Zero Trust principles and micro-segmentation to limit the blast radius of a compromised account or system.

Enforce the principle of least privilege for all users and third-party vendors.

Timeline of Events

1
June 30, 2026

End of the H1 2026 reporting period analyzed by the ITRC.

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachITRCSupply Chain AttackInsider ThreatMega-breachStatistics

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.