The Identity Theft Resource Center’s half-year report is the closest thing the United States has to a national breach statistic, and the 2026 edition is bad in a specific way that is worth understanding precisely.

The headline figures

471.2 million victim notices in the first half of 2026. For comparison, 297.5 million were issued across the entirety of 2025. Six months of this year exceeded twelve months of last year by more than 170 million.

1,803 tracked data compromises in H1, of which 1,029 fell in the second quarter alone — the second-highest single-quarter total in the ITRC’s tracking history. At that pace, 2026 lands near 3,600 compromises for the full year, against 3,321 in 2025.

Twenty-one insider wrongdoing events, a sevenfold increase over all of 2025. The ITRC attributes this to tech-sector layoffs and nation-state recruitment schemes — displaced employees with retained access and a financial motive, and deliberate recruitment of insiders by state-linked actors.

And 24% attack-vector disclosure, the lowest rate the ITRC has ever recorded. Three-quarters of breach notices in the first half of 2026 did not say what happened.

The Canvas problem

One incident dominates the victim count. Instructure Holdings’ Canvas learning management platform generated an estimated 275 million victim notices — roughly 58% of the entire H1 total.

Canvas is the learning management system used by a very large share of American schools, colleges, and universities. Its records are not marketing data. They are student rosters, coursework, grades, disciplinary and accommodation records, guardian contacts, and in many deployments the institutional identifiers that link a student across systems.

Two features of this make it worse than the number suggests.

Most of the affected population had no relationship with the vendor. Students do not select their institution’s LMS. Parents do not consent to it. The data got there because a school district or university procured a platform, which is a decision made by an administrator in a contract negotiation the affected families never saw.

And a meaningful share of those 275 million are minors. A child’s identity is the most valuable kind to steal precisely because nobody checks it — a compromised Social Security number belonging to a nine-year-old may not surface as fraud until that person applies for their first loan a decade later. The clean-up window on this incident is effectively the rest of those children’s lives.

The 24% is the real story

Everything above is bad. The disclosure figure is the part with structural implications.

Breach notification statutes in nearly every state require that individuals be told a breach occurred, what categories of data were involved, and what remediation is being offered. They generally do not require the notice to say how the attacker got in.

That omission was tolerable when the notices were rare. It is not tolerable at 471 million, because the attack vector is the only part of a breach notice that generates public benefit beyond the individual. If a notice says “exploitation of an unpatched instance of a named product,” every other operator of that product learns something. If it says “an unauthorized third party gained access to certain systems,” nobody learns anything and the same vector works next quarter.

At a 24% disclosure rate, three-quarters of the country’s breach reporting is producing individual harm notices with no systemic learning value at all. The ITRC has been pointing at this for years and the trend is going the wrong way.

The reason is not mysterious: attack-vector disclosure is discoverable in litigation and useful to plaintiffs, so counsel advises against it, and no statute compels it. That is a fixable gap and no legislature has fixed it.

The insider surge deserves attention

A sevenfold increase in insider wrongdoing events is a change in kind, not degree, and it interacts badly with everything else in this ledger.

Insiders bypass the entire security architecture. Encryption at rest, network segmentation, MFA, and endpoint controls are all designed against an external adversary and none of them constrain someone with legitimate credentials and a business reason to query. The controls that work against insiders — least privilege, query logging, anomaly detection on access patterns, and separation of duties — are precisely the controls that get deferred when headcount is cut.

Which is the mechanism the ITRC identifies. Layoffs remove the people who monitor access and create a pool of former and soon-to-be-former employees with retained credentials and grievance. Nation-state recruitment then operates on that pool. The 2026 spike is what a downturn looks like when it hits a sector that holds everyone’s data.

Note the pattern from elsewhere on this site: ALPR misuse by police officers is the same failure — authorised credentials, unauthorised purpose, detected only by query auditing. Insider risk is an access-logging problem across every sector, and access logging is what nobody funds.

What the numbers do not mean

Some care is warranted, because “471 million victims” invites a misreading.

Victim notices are not people. They are notices. One person breached in four incidents generates four notices. Given the concentration in Canvas, a very large share of the 471 million represents overlapping populations. The true count of distinct affected individuals is unknowable and considerably lower.

Notice volume is a poor measure of harm. A notice for an exposed email address and a notice for exposed genetic test results with a Social Security number count identically. The Baylor Genetics breach notified about 310,000 people — a rounding error against Canvas — and involved genomic test results, medical information, and SSNs. Severity and volume are close to uncorrelated.

And rising compromise counts partly reflect better reporting. More states with notification statutes, lower thresholds, and more attorney-general reporting portals mean more incidents are counted that would previously have gone unrecorded. Some of the increase is measurement improving.

None of these caveats rescue the picture. They just mean the honest claim is “the largest breach year on record by notice volume, driven by one enormous education-sector incident, with the worst explanation rate ever measured” rather than “471 million Americans were harmed.”

What it means in practice

Halfway through 2026, breach notification in the United States is functioning as a liability-management ritual rather than an information system. It tells individuals that something happened, offers them a year of credit monitoring, and withholds the one fact — how — that would let anyone else avoid the same outcome.

Meanwhile the incidents themselves have shifted upstream. Canvas, and the vendor breach wave covered earlier this month, are the same story: the compromise happens at a platform or supplier that the affected people never chose and cannot audit, and the organisation they actually trusted sends the letter.

What you can do

  1. Freeze your credit, and your children’s. A freeze is free in all fifty states and is the only measure that reliably prevents new-account fraud. Minor freezes are the specific defence against the Canvas population problem, and almost nobody sets them up.
  2. Treat credit monitoring as detection, not protection. It tells you after the fact. It is worth enrolling in and it is not a remedy.
  3. Read the notice for what it omits. If it does not name a vector, assume the answer is unflattering. If it does not name a date range, assume the dwell time was long.
  4. If you are an institution, ask your vendors the access question. Not “are you SOC 2 certified” but “who at your company can query my records, is every query logged, and will you give me the logs on request.” The insider surge makes that the highest-value procurement question of 2026.
  5. Support attack-vector disclosure in notification statutes. It is a small statutory amendment, it costs nothing, and it converts 3,600 annual private harms into public defensive knowledge. It is the single most under-argued privacy reform in the United States.