Malicious insider breaches surged sevenfold in H1 2026, ITRC finds

The Identity Theft Resource Center recorded 21 malicious insider incidents in the first half of 2026, up from just three in all of 2025.

MedRisk Staff
By
2 Min Read

Internal security threats within healthcare organizations multiplied sevenfold during the first six months of 2026, according to the Identity Theft Resource Center’s mid-year data breach analysis published July 23. The ITRC documented 21 incidents involving employees or contractors who intentionally misused their access, up from just three reported throughout all of 2025.

The ITRC counted 1,803 data compromises across all industries during the first six months of 2026, a rate that projects to more than 3,600 events by the end of December. Notification letters sent to affected individuals passed 471 million in just half a year, exceeding the total volume for the entire previous year. Three mega breaches accounted for the bulk of those notices: Instructure’s Canvas platform at 275 million, Under Armour at 72.7 million, and SoundCloud at 29.8 million.

Healthcare placed second in sector rankings with 281 compromises, behind financial services at 387. The largest healthcare incidents included TriZetto Provider Solutions with 3.4 million affected individuals, QualDerm Partners at 3.1 million, and Nacogdoches Memorial Hospital at 2.5 million. OCR data shows the cumulative healthcare victim count has reached at least 28.8 million so far this year.

Ransomware remained a persistent threat with 76 confirmed attacks, up 4.1 percent from the prior year. Supply chain compromises continued to carry outsized impact: 38 such incidents produced 280.6 million victim notices. The ITRC tracked 14 zero-day exploits during H1 2026, closing in on the 17 recorded for all of 2025. Transparency around breach causes continued to decline, with 76 percent of notices failing to specify the attack vector.

Share This Article