By KARA KENNEY
WISH-TV | wishtv.com
A new report highlights the growing impact of “mega breaches,” data breaches that result in more than 100 million victim notices.
When a company or government agency experiences a data breach, it is legally required to notify individuals if their personal information was compromised.
The Identity Theft Resource Center (ITRC) released its Data Breach Report for the first half of 2026. It found that 471.2 million victim notices were issued in the first six months of the year, far surpassing the 297.5 million sent in 2025.
“If you stacked up all of the victim notices that were issued in the first six months, they would reach into space,” said James Lee, president of the ITRC.
Mega breaches, like the one that affected the education platform Canvas, are driving the increase, Lee said. The Canvas compromise prompted an estimated 275 million victim notices.
“We have already surpassed the number of victim notices issued last year, and if we stay on the same pace we’re on for actual data breaches this year, we will set another record,” Lee said. “We’ll exceed 3,600 data breaches in a single year for the first time if we stay on this same pace.”
Lee said artificial intelligence is also driving the increase. AI software can find software flaws at a rate humans cannot match.
The ITRC report also notes a spike in malicious insider attacks, which can include employees, former employees and vendors with access to personal information.
“The most we had ever seen data breaches caused by insider employees was two, and that was several years ago. We’ve already had 21 instances just this year,” Lee said. “That stands out to me that what is going on with the economy right now, with mass layoffs – particularly in the technology sector – is having an impact.”
The ITRC recommends that individuals freeze their credit files via FrozenPII.com, switch to passkeys to prevent credential theft and enable multifactor authentication.
For businesses, the ITRC advises adopting a “zero-trust” architecture, implementing “least-privilege” access controls to combat insider threats, vetting supply chain vendors in real time and prioritizing transparency by voluntarily disclosing attack vectors to build consumer trust.
“Don’t wait to fight back,” Lee said. “Go ahead and build your defenses before any of this ever happens.”
Due to the Canvas breach, the technology sector saw the highest volume of victim notices. By sector, financial services recorded the highest number of compromises at 387, according to the ITRC.
Healthcare compromises rose to 281, reversing a slight downward trend from the previous year. Manufacturing also experienced a surge, producing 74 million victim notices compared to 1.97 million in 2025.
This story was originally published by WISH-TV at wishtv.com/news/i-team/mega-breaches-driving-increase-in-victim-notifications-hits-record-high.

Be the first to comment on "‘Mega breaches’ and AI drive surge in data breach notifications"