ID Theft Cases Surge in 2026

Identity theft is shaping up to be a record year, with the first half of 2026 already surpassing the total number of victims recorded for the entire previous year.
Victim counts jump 58% in just six months
The Identity Theft Resource Center (ITRC) reports 471.2 million victims in the first six months of 2026. That figure is 58 percent higher than the 297.5 million victims logged for all of 2025.
The surge reflects a broader rise in data breaches, which climbed to 1,803 incidents in the same period, a 4.1 percent increase over the 1,732 breaches recorded in the first half of 2025.
Sector‑specific breach trends vary
Financial‑services breaches numbered 387 in early 2026, down slightly from 396 a year earlier. Healthcare incidents rose to 281, a modest increase from 270 in the comparable 2025 window.
Professional‑services firms saw 269 incidents, up from 248 the previous year. These mixed results suggest that while some sectors are improving, overall exposure remains high.
Related: TSG Partners with Stripe on Payments Data
Two large‑scale breaches dominate the victim count. Canvas suffered a breach affecting 275 million individuals, while Under Armour reported 72.7 million victims. Together, these incidents exceed the total number of breach notices issued in 2025.
Insider wrongdoing appears to be a growing factor. The ITRC identified 21 insider‑related events in the first half of 2026, compared with just three throughout 2025. The report notes that insider attacks often bypass perimeter defenses and may remain undetected longer than external hacks, hinting at both an increase in malicious activity and better detection methods.
Zero‑day attacks are also on the rise.
There have been 14 such incidents in the first half of 2026, approaching the 17 recorded over the entire previous year. Zero‑day exploits target unknown or unpatched software flaws, making them especially difficult to defend against.
Transparency around breach details is at a historic low. Only 24 percent of breach notices in early 2026 disclosed the attack vector, the lowest rate ever reported. In contrast, nearly all notices in 2020 provided that information.
Related: 10 Things You Didn’t Know a POS System Could Do For Your Café
The ITRC’s “Cyberattacks: Not Specified” subcategory now includes 972 events for the first half of 2026, limiting the ability of consumers and businesses to assess risk.
Publicly traded companies, while representing just 10 percent of total compromises, generated 83 percent of breach notices. Their extensive consumer data holdings likely make them attractive targets, according to the ITRC.
James E. Lee, president of the ITRC, cautioned that the current trajectory signals “a lot of identity scams and fraud headed our way.” He added that an “unprecedented transparency crisis” leaves many in the dark about actual risk exposure, because existing state laws fail to provide adequate protection.
When a breach touches millions of people, it can overwhelm credit‑monitoring services, strain law‑enforcement resources, and increase the likelihood of secondary fraud, such as unauthorized loans or account takeovers. The ripple effects extend beyond the immediate victims, influencing overall trust in digital services.
Looking ahead, the ITRC expects the upward trend to continue. With more than half of a potentially record‑breaking year already recorded, the organization warns that identity‑theft scams and fraud are likely to increase further. The combination of insider threats, large‑scale breaches, and limited disclosure of attack methods creates a challenging environment for both consumers and businesses seeking to mitigate risk.

TSG Partners with Stripe on Payments Data
