Data Breaches Hit Record Pace as AI Fuels Cyberattacks
First-half 2026 victim notices already exceed all of 2025, with AI-enabled attacks and malicious insiders driving the surge.

Corporate cybersecurity investments are climbing, yet data breaches continue accelerating at an alarming rate. The first six months of 2026 generated more than 471 million victim notices from data compromises—already surpassing the 297.5 million notices issued during all of 2025, according to a new report from the Identity Theft Resource Center.
The nonprofit, which tracks publicly reported breaches and assists identity-theft victims, recorded 1,803 security incidents in the first half of 2026, up from 1,732 in the same period last year. If the trend holds, 2026 will exceed the 3,321 incidents reported for all of 2025.
Why it matters
The surge demonstrates that even substantial security spending cannot keep pace with evolving attack methods. For enterprises, this means traditional defenses are insufficient against AI-augmented threats and insider risks. Organizations must reassess their security architectures while regulatory pressure for breach disclosure continues to fragment across state lines, creating compliance complexity and inconsistent consumer protection.
AI amplifies attack capabilities
Artificial intelligence is reshaping the threat landscape. Between March 2025 and February 2026, one in four breaches involved AI-enabled attacks—a 56% increase from the prior year, according to IBM research. The technology's advancing capabilities make it easier for attackers to identify and exploit system vulnerabilities.
Corporate boards recognize the urgency. Cybersecurity ranks among the top three priorities for 93% of audit committees at public companies, according to a 2025 Deloitte survey. Globally, 78% of organizations plan to increase cybersecurity budgets over the next year, PwC research shows.
Insider threats multiply
Malicious insider incidents jumped dramatically, with 21 events recorded in the first half of 2026 compared to just three for all of 2025. James Lee, president of the ITRC, noted this represents a significant departure from historical patterns.
"We've never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months," Lee said.
The increase stems partly from disgruntled laid-off employees stealing information during their departure. More concerning is a sophisticated scam flagged by the FBI in which North Korean operatives use stolen identities, deepfake videos, and AI-generated resumes to secure remote IT positions within U.S. companies. The ITRC report identifies this as "arguably the most significant structural driver of malicious insider attacks."
Disclosure transparency declining
Only 24% of breach notices sent to consumers in the first half of 2026 included incident details, down sharply from 93% in 2021. Lee attributes this decline to companies limiting disclosures to state-mandated minimums following court cases, creating a patchwork of consumer protections.
"Where you live determines if you find out about a breach, and if you do find out, what you're told," Lee said.
Consumer protection steps
Security experts recommend credit freezes as the most robust defense against identity theft. This free measure prevents credit bureaus from releasing reports to potential lenders, blocking fraudulent account openings. Consumers can temporarily lift freezes when legitimately applying for credit.
Alternatively, fraud alerts compel lenders to verify identity before approving applications, while free credit monitoring services notify users of suspicious activity. Consumers can review credit reports weekly at no cost through AnnualCreditReport.com.
These details were first reported by CNBC.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call

