Data breach notices in 2026 have already blown past last year's record total — and artificial intelligence is playing a growing role in the attacks, according to new reports from the Identity Theft Resource Center (ITRC) and IBM, covered by CNBC.
The ITRC, a nonprofit that tracks publicly reported breaches, counted more than 471 million victim notices in the first half of 2026, compared with 297.5 million for all of 2025. A single incident — a cyberattack on the education platform Canvas — accounts for 275 million of those notices. The number of incidents reached 1,803 in the first half, up from 1,732 a year earlier, and is on pace to eclipse the 3,321 incidents reported for all of last year.
AI has become the weapon of choice. In IBM's annual Cost of a Data Breach Report, one in four malicious breaches between March 2025 and February 2026 was AI-enabled — a 56% increase over the previous year — driven largely by deepfake impersonation and AI-assisted malware, and costing companies an average of about $6 million per breach, roughly $1 million more than the average.
The ITRC also flagged an unprecedented jump in "malicious insider" incidents: 21 events in the first half of 2026, versus three in all of 2025. The report attributes part of the surge to disgruntled laid-off employees, and part to a scheme the FBI has warned about in which North Korea places remote IT workers in U.S. businesses using stolen identities, deepfake video interviews and AI-generated resumes — described by the report as "arguably the most significant structural driver of malicious insider attacks."
"We continue to see this ever-increasing number of data breaches," said ITRC President James Lee. "That does not appear to be slowing down." He noted that only 24% of notices sent to consumers in the first half of 2026 included details of the breach, down from 93% in 2021, as companies disclose only the legal minimum under a patchwork of state rules.
Cybersecurity now ranks among the top three priorities for 93% of audit committees at public companies, according to a Deloitte and Center for Audit Quality survey, while 78% of companies worldwide plan to boost their security budgets over the next 12 months, per a PwC survey.




