ITRC report shows 1,803 data compromises and 471 million victim notices in H1 2026

The Identity Theft Resource Center reports a sevenfold surge in malicious insider incidents and a return of mega data breaches in the first half of 2026.

MedRisk Staff
By
2 Min Read

The Identity Theft Resource Center’s H1 2026 report shows that data compromise volumes are on track for a new annual record, with 1,803 incidents already producing 471 million victim notices that exceed the full-year total for 2025. Malicious insider events surged from three in all of last year to 21 in the first half of this year alone, while zero-day exploits hit 14, approaching the 17 recorded in all of 2025. Healthcare organizations absorbed 281 of the overall incidents, second only to financial services at 387.

HHS Office for Civil Rights data as of July 23 showed 28.8 million healthcare victims across all filings, more than double the 11.7 million captured by the ITRC’s direct tracking. Among the largest healthcare incidents were those affecting TriZetto Provider Solutions, QualDerm Partners, and Nacogdoches Memorial Hospital, each involving more than 2.5 million individuals. Supply chain attacks accounted for only 38 tracked events but drove 280.6 million victim notices, underscoring how third-party compromises can ripple across entire sectors.

The report flagged a continuing decline in breach transparency, with 76% of all notices failing to name the attack vector, the lowest rate since the ITRC began tracking. Among those that did disclose, phishing and business email compromise were the most common causes at 157 incidents, followed by system and human error at 125 and ransomware at 76. Ransomware activity rose 4.1% year-over-year, and cyberattacks as a whole drove 69.7% of all breaches and 92.3% of all victim notices.

Share This Article