Data Breaches Hit Record Pace as AI Attacks Surge 56%
First-half 2026 figures show 1,803 compromises and nearly half a billion victim notices, with one in four attacks now AI-enabled.

Data breaches are accelerating at an unprecedented rate, with the first six months of 2026 recording 1,803 compromises—a pace that would shatter 2025's full-year record of 3,321 incidents, according to the Identity Theft Resource Center.
The scale of exposure is even more alarming. Organizations sent out 475 million victim notices in the first half of 2026 alone, already exceeding the 297.5 million notices issued across all of 2025.
Why it matters
The convergence of AI-powered attack tools, supply chain vulnerabilities, and declining transparency in breach reporting creates a perfect storm for both consumers and enterprises. As artificial intelligence lowers the barrier to sophisticated attacks, organizations face mounting costs while individuals receive less actionable information about how their data was compromised—undermining their ability to protect themselves.
Massive breaches drive victim counts
A single incident involving Instructure Holdings' Canvas education platform generated an estimated 275 million victim notices, representing roughly 58% of the half-year total. Supply chain attacks proved equally devastating, with just 38 initial breach events cascading to affect 206 entities and producing 280.6 million victim notices.
AI becomes attackers' force multiplier
Artificial intelligence now powers one in four malicious breaches, representing a 56% year-over-year increase, according to an IBM study covering 602 organizations globally between March 2025 and February 2026. These AI-enabled attacks—leveraging deepfake impersonation and AI-generated malware—cost companies an average of $6 million per incident, roughly $1 million above the global breach average of $4.99 million.
"We continue to see this ever-increasing number of data breaches," ITRC President James Lee told CNBC. "That does not appear to be slowing down."
Insider threats multiply
Malicious insider incidents jumped from three in all of 2025 to 21 in just the first half of 2026. Lee identified two primary drivers: departing employees exfiltrating data before termination, and a North Korean operation in which operatives use fabricated identities, AI-generated resumes, and deepfake video interviews to embed themselves in American companies—a scheme the FBI has publicly warned about.
Transparency collapses
Just 24% of breach notifications sent to consumers in the first half of 2026 explained how the incident occurred—the lowest rate the ITRC has recorded and a dramatic decline from 93% in 2021. The lack of uniform disclosure requirements means breach notification quality varies by jurisdiction.
"Where you live determines if you find out [about a breach], and if you do find out, what you're told," Lee said.
Recommended defenses
The ITRC advises consumers to freeze credit files and adopt passkeys for authentication. For organizations, the center recommends implementing zero-trust architecture and least-privilege access controls to limit exposure from both external attacks and insider threats.
These findings were first reported by CNBC based on ITRC data and research from IBM.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

