Key Takeaways
- U.S. data compromises generated an estimated 471.2 million notices during the first six months of 2026.
- A Canvas education platform incident accounted for an estimated 275 million notices, highlighting the renewed impact of mega-breaches.
- Only 24% of notices explained how the breach occurred, creating transparency and risk-management problems for consumers and businesses.
The Identity Theft Resource Center has recorded extensive data compromises in the first six months of 2026, incidents that generated an estimated 471.2 million consumer notices (source). That notice volume has already exceeded the total for all of 2025, marking a sharp reversal from a year in which the number of incidents rose but mass notifications fell.
One caveat matters: 471.2 million notices does not mean 471.2 million different people were affected. Individuals can receive multiple notifications after separate incidents, and a single compromise may involve overlapping data sets. Even so, the scale shows how a handful of extremely large events can reshape the annual picture and create months of downstream work for security, legal, and customer-service teams.
The acceleration follows a record 3,322 U.S. data compromises in 2025, according to the Identity Theft Resource Center. That was 5% higher than in 2024 and 79% above the level recorded five years earlier. Yet victim notifications fell 79% year over year because 2025 lacked the kind of mega-breaches that had produced mass mailings in 2024.
Now those outsized incidents are back. The ITRC estimates that an incident involving the Canvas education platform generated 275 million notices by itself, although the confirmed number of affected people based in the United States remains pending. That single estimate represents well over half of the first-half notice volume.
The education connection raises a particularly difficult set of risks. Canvas records can relate to current students, former students, employees and, in some cases, parents. Many affected people may be children or young adults with limited credit histories and little reason to monitor identity activity closely. Their information can remain useful to criminals for years. A compromised password can be changed quickly; biographical and educational information is much harder to retire.
“That’s a treasure trove of information,” the ITRC president said, pointing to a growing concentration on data belonging to younger people. For education providers and their technology partners, the business question is not limited to whether systems have been restored. How much historical data is being retained, who can access it, and is every stored field still serving a legitimate purpose?
The notice itself often does not answer those questions. Only 24% of the notices reviewed by the ITRC explained how the compromise happened, the lowest rate the organization has recorded. Sparse disclosures may reflect an active investigation, legal constraints, or incomplete forensic findings. But they can also leave recipients unsure whether to change a password, replace a payment card, freeze their credit, or watch for a more targeted form of fraud.
The transparency gap has operational consequences for businesses as well. Corporate security teams cannot readily assess exposure when an employee receives a vague notice from a payroll processor, education provider, or other third party. Procurement teams also have less information for evaluating vendor controls. A notice that identifies the affected data, attack method, relevant dates, and remediation steps tends to be more useful than one built mainly around general assurances.
This is not solely a U.S. trend. The Office of the Australian Information Commissioner received 1,205 notifiable data breach reports in 2025, up 8% from 2024 and the highest annual total since Australia’s mandatory notification regime began in 2018. Cyber-hacking was the primary cause. In the European Union, the DLA Piper GDPR Fines and Data Breach Survey found that average GDPR personal data breach notifications climbed 22% to 443 per day in 2025.
More reporting does not automatically mean every exposed record will be misused. The ITRC president emphasized that consumers still have an opportunity to make stolen information less valuable. Credit freezes can restrict new-account fraud, while passkeys can reduce reliance on reusable passwords. Strong, unique passwords remain relevant where passkeys are unavailable, and multi-factor authentication can add protection to email, banking, and retirement accounts. For enterprises, the same principle applies at scale: reduce retained data, limit privileges, prepare clearer notices, and assume that compromised information may be combined with records from other incidents.
⬇️