The Identity Theft Resource Center released its H1 2026 Data Breach Report on July 22. The number at the top of it is hard to process: 471.2 million victim notices issued in six months. That already beats every notice sent out across all of 2025 combined, and it happened in half the time. If you run a small business or manage HR and benefits, this is not just a scary headline. It is a set of specific, actionable signals about where risk actually sits right now. Most of it does not look like the breach coverage you are used to reading, and that gap is exactly why this report is worth your time.
Last Updated: August 2026
According to the H1 2026 data breach report, the ITRC tracked 1,803 data compromises in the first half of the year. That pace puts 2026 on track to pass the 3,321 compromises recorded in all of 2025. Q2 alone accounted for 1,029 of those compromises, the second highest single quarter in ITRC’s tracking history. But the compromise count is not what makes this report unusual. It is where the notices came from, and what that concentration means for any company that relies on outside vendors. That describes almost every company, including yours.
What the H1 2026 Data Breach Report Actually Reveals
A single incident involving Instructure Holdings’ Canvas education platform generated an estimated 275 million victim notices on its own. That is the Canvas learning management system used in thousands of schools, not the Canva design tool. One breach, 58 percent of the entire H1 total. Attackers reportedly used a support ticket submitted through a teacher account as their entry point. From there, they pulled an estimated 3.65 terabytes of data. The fallout has already touched nearly 9,000 schools.
Zoom out and the pattern holds across the whole report. Supply chain attacks generated 280.6 million victim notices from just 38 initial breach events in H1 2026. Those 38 events spread across 206 downstream entities. One vendor gets hit, and the notice count multiplies across every organization that trusted that vendor with data. Financial services led all sectors in raw compromise frequency at 387 incidents, with healthcare close behind at 281. Publicly traded companies made up only 10.3 percent of compromises. They still accounted for 83.4 percent of all victim notices. When a large platform goes down, it takes its entire customer base down with it.
None of this requires your company to be the one that gets breached. It requires your company to use software, payroll providers, benefits administrators, or any other vendor that touches employee or customer data. Most SMBs check that box several times over, often without a clear inventory of which vendors hold what.
Insider Wrongdoing Is Up Sevenfold, and the Number Is Small on Purpose
The report also documented 21 malicious insider wrongdoing events in H1 2026, compared to just 3 across all of 2025. That sevenfold jump is the ITRC’s own framing, and it holds up. It is also worth reading correctly. Twenty one events is still a small, high severity category. It is not a sign that a fifth of the workforce has gone rogue. The ITRC ties the rise to two forces converging at once. Tech sector layoffs are creating disgruntled or financially desperate former employees with lingering access. At the same time, nation state recruitment schemes are targeting insiders directly, offering payment in exchange for data or system access.
The financial exposure behind that category is real even at small scale. The Ponemon Institute’s 2026 Cost of Insider Risks Global Report puts the average cost of a malicious insider incident at $742,125. Organizations spend an average of $19.5 million annually managing insider risk overall. Those figures come from large enterprise data sets, so treat them as a ceiling rather than a prediction for a 40 person company. But the underlying math does not disappear at smaller scale. It just means there is far less budget available to absorb a single bad incident, and far less room for a slow response.
For HR and benefits teams specifically, this is the offboarding conversation nobody wants to have twice. Access review at termination, not just at hire, is no longer optional. A departing employee with valid credentials and thirty days of unrevoked access is exactly the profile the ITRC is describing.
The Transparency Crisis: Notification Is Not the Same as Information
Only 24 percent of H1 2026 breach notices disclosed any information about the attack vector. That is the lowest rate the ITRC has ever recorded. It means roughly three out of four people will receive a breach notice this year with no real explanation attached. The same is true for three out of four HR departments handling the fallout. Nobody learns whether it was phishing, ransomware, an unpatched vulnerability, or an insider. They get told they were exposed. They do not get told how. That gap makes it nearly impossible to know what to actually change in response, so the same vulnerability often stays open long after the notice arrives.
This gap matters more than it sounds like it should. A notice with no attack vector gives an employee nothing to act on beyond generic advice. It gives an employer nothing to defend against beyond generic controls, applied everywhere and tailored to nothing. Fourteen zero day events were recorded in H1 2026 alone, nearly matching all of 2025’s total of 17. That trend line matters because zero day attacks target flaws nobody knew existed yet. No amount of employee training would have stopped them.
What SMB Owners and HR Teams Should Do Differently in the Second Half of 2026
The ITRC’s own guidance for businesses centers on three moves. Adopt a zero trust posture instead of assuming internal network traffic is automatically safe. Apply least privilege access controls so any single compromised account, whether it belongs to an employee or a vendor, can only reach what it strictly needs. Vet supply chain vendors on an ongoing basis rather than once at signing. None of that requires an enterprise security budget. It requires treating vendor access the way you would treat a new hire’s access. Review it on a schedule, limit it by default, and revoke it the moment it is no longer needed.
A few concrete starting points for the second half of the year:
- Audit which vendors currently hold employee Social Security numbers, banking details, or health information. Confirm each one has a breach notification obligation spelled out in its contract, not just implied.
- Review offboarding procedures specifically for access removal timing. Paperwork completion and system access removal are two different clocks, and they should not run on different days.
- Assume any breach notice your company receives this year will not tell you how the breach happened. Build your response plan around that assumption instead of waiting for details that likely will not come.
- If your organization does not already offer identity monitoring as a benefit, H1 2026’s numbers make the business case on their own. With 471 million notices already issued, the odds that an employee receives one this year are no longer low.
- Ask new and existing vendors directly what their own insider access controls look like. A vendor that cannot answer that question is a bigger liability than the report’s numbers suggest on their own.
- Put a specific person’s name next to breach response, not just a department. When a notice arrives at 5pm on a Friday, “someone in IT will handle it” is not a plan.
The Small Business Post-Breach Playbook walks through the first 48 hours after your own company gets hit directly. This report describes the more common scenario for most SMBs in 2026: a vendor gets hit, and your employees end up holding the notice instead of you.
Frequently Asked Questions
What is the ITRC H1 2026 Data Breach Report?
It is the Identity Theft Resource Center’s midyear analysis of U.S. data compromises, published July 22, 2026. It tracked 1,803 compromises and an estimated 471.2 million victim notices issued between January and June 2026. That already exceeds the total for all of 2025.
How many people were affected by data breaches in the first half of 2026?
The ITRC estimates 471.2 million victim notices were issued in H1 2026 alone. That figure reflects total notices issued, not unique individuals. One person can receive multiple notices from different breaches in the same period, so the true number of unique people affected is lower than the headline figure.
Why did one breach account for more than half of all H1 2026 notices?
A supply chain breach involving Instructure Holdings’ Canvas education platform generated an estimated 275 million victim notices, or 58 percent of the H1 2026 total. It illustrates how a single vendor compromise can multiply across every organization and individual connected to that vendor, far beyond the original target.
Why are insider threats increasing in 2026?
The ITRC recorded 21 malicious insider wrongdoing events in H1 2026 versus 3 in all of 2025, a sevenfold increase. The report attributes this to tech sector layoffs and nation state recruitment efforts that specifically target employees who already have legitimate data access.
What does the ITRC mean by a transparency crisis?
Only 24 percent of H1 2026 breach notices disclosed how the breach occurred, the lowest rate ever recorded. Most people and businesses receiving a notice have no information about the attack method behind it, which limits their ability to respond with anything more specific than general precautions.
What should small businesses do differently after this report?
The ITRC recommends zero trust architecture, least privilege access controls, and ongoing supply chain vendor vetting rather than one-time onboarding checks. Reviewing offboarding access removal timing and confirming vendor breach notification obligations are practical starting points for smaller teams without a dedicated security staff.
Does identity theft protection help employees after a vendor data breach?
Yes. Most H1 2026 notices originated from third-party vendor breaches rather than direct attacks on the employer. Identity monitoring and recovery support give employees a resource regardless of which vendor was responsible. The employee usually has no direct relationship with that vendor and no easy way to hold it accountable, which is exactly the gap a monitoring benefit is designed to close.
The H1 2026 numbers make one thing clear. Breach exposure is no longer something only large enterprises need to plan around, and a strong password policy alone will not address it. If your company has not reviewed how identity protection fits into your benefits package this year, now is the moment to do it. Talk to Defend-ID about what a turnkey identity protection benefit looks like for a team your size.
Related Articles
- Q1 2026 Data Breach Report: What It Means for Your Employees
- Small Business Post-Breach Playbook: What to Do First
- Identity Theft Protection Voluntary Benefit: 2025’s Top Pick
- How Workplace Identity Theft Hijacks Paychecks