The Identity Theft Resource Center reported at least 1,803 data compromises during the first half of 2026, with the current pace indicating that the annual total could exceed 3,600 incidents if the same rate continues through the remainder of the year.
Data Compromise Totals
The H1 2026 Data Breach Report recorded 1,803 data compromises during the first six months of 2026. The report stated that maintaining the same pace would result in more than 3,600 data compromises for the full year.
Among those incidents, 1,394 were confirmed data breaches, excluding leaks, exposures, and incidents with unknown classifications. Confirmed data breaches accounted for 77% of all reported data compromise events.
More than 471 million victim notices had been issued by the midpoint of 2026. That total already exceeded the number of victim notices issued during all of 2025. The report stated that, despite this increase, the current rate is unlikely to surpass the total number of victim notices recorded in 2024. Even with only six months of data available, 2026 ranks among the years with the largest numbers of affected individuals.
Mega Data Breaches
The report attributed part of the increase in victim notices to the return of mega data breaches. The largest reported incident involved the Instructure Holdings Canvas platform and accounted for an estimated 275 million victim notices. The Under Armour data breach resulted in more than 72.7 million victim notices. The SoundCloud data breach resulted in 29.8 million victim notices.
Healthcare Data
The report stated that no healthcare data breaches appeared in the top ten data compromise list during the first half of 2026.
The report contrasted that result with the first half of 2025, when three healthcare data breaches ranked among the five largest incidents.
Based on breach reporting to the HHS Office for Civil Rights, the report stated that relatively few healthcare incidents required notices to more than one million individuals during the first half of 2026. Seven healthcare data breaches exceeded that threshold.
Those incidents involved:
- TriZetto Provider Solutions with 3,433,965 affected individuals.
- QualDerm Partners, LLC with 3,117,874 affected individuals.
- Nacogdoches Memorial Hospital with 2,507,073 affected individuals.
- Navia Benefit Solutions, Inc. with 2,151,330 affected individuals.
- Insightin Health, Inc. with 1,949,534 affected individuals.
- New York City Health and Hospitals Corporation with 1,800,000 affected individuals.
- Xsolis, Inc. with 1,396,519 affected individuals.
The Identity Theft Resource Center tracked 281 healthcare data compromises during the first half of 2026. Healthcare ranked second among industries after financial services, which recorded 387 data compromises.
The report stated that healthcare data compromises increased from 270 during the first half of 2025 to 281 during the first half of 2026. More than 11.7 million patients were affected across those 281 healthcare data breaches.
The report also stated that HHS Office for Civil Rights data dated July 23, 2026, showed the total had already increased to more than 28.8 million affected individuals. That figure remained below the first half of 2025 total of 42.8 million healthcare victims.
Breach Notice Transparency
The report stated that 76% of breach notices did not identify the attack vector, representing 1,378 notices. Only 24% of breach notices included information about the attack vector. The report identified this as the lowest reporting rate since the Identity Theft Resource Center began publishing its data breach reports. The report also stated that 93% of victim notices included attack vector information in 2021.
Incident Trends
The report identified 21 insider wrongdoing incidents during the first half of 2026. The report stated that only three such incidents were identified during all of 2025.
The report tracked 14 zero-day attacks during the first half of 2026 compared with 17 during all of 2025.
The report identified 38 supply chain incidents during the first half of 2026. Those incidents generated more than 280.6 million victim notices. The report stated that supply chain cyberattacks affected 199 of 206 impacted entities and accounted for 280.6 million of the combined victim notices associated with supply chain incidents.
Cyberattacks accounted for 69.7% of reported data breaches and 92.3% of all victim notices during the first half of 2026.
System and human error accounted for 6.9% of reported breaches and 0.9% of victim notices.
The report identified phishing, smishing, and business email compromise as the most common cyberattack category with 157 incidents. System and human error accounted for 125 incidents. Ransomware accounted for 76 incidents. The report also stated that 402 events remained unclassified because sufficient information about the cause was not available.
The report stated that total cyberattacks declined by 7.8% compared with the first half of 2025, while ransomware attacks increased by 4.1%. The report did not state whether HIPAA compliance had any direct relation with the decline of cyberattacks.
