A new ITRC report says mega data breaches drove 471.2 million victim notices in early 2026. Here’s why the surge matters and how you can better protect your information online.
Table of Contents
What Happened?
The report found that organizations issued 471.2 million victim notices during those six months. That already exceeds the 297.5 million notices sent during all of 2025.
The ITRC calls incidents that produce more than 100 million notices “mega breaches.” These very large events are driving much of the increase.
For example, a breach involving the education platform Canvas led to an estimated 275 million victim notices.
The ITRC said reported data breaches could exceed 3,600 in 2026 if the current pace continues.
With so many breaches happening, you may not always know when your information has been leaked. Automatic monitoring can help you notice problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Leaked?
The report covers people who received notices after their personal information was involved in a company or government data breach.
The technology sector produced the most victim notices, mainly because of the Canvas incident. Financial services recorded the most individual breaches, with 387 cases.
Healthcare organizations reported 281 breaches. Meanwhile, manufacturing produced 74 million victim notices, compared with 1.97 million during 2025.
The report summary did not list every type of personal information involved. The details can differ greatly from one breach to another.
Depending on the incident, leaked information may include names, email addresses, passwords, financial details, or other personal records.
Criminals can use these details for phishing, fraud, or identity theft. Many people also do not know their information was leaked until suspicious activity appears later.
Futureproof keeps your data safer with simple guidance to set a strong password, turn on 2-step verification, and lock down your account.
Check my safetyHow AI and Insider Access Are Driving More Breaches
The report did not describe how criminals entered every affected system. However, it highlighted three factors behind the growing number of notices.
First, one mega breach can generate hundreds of millions of notices. That can quickly push yearly totals far above earlier records.
Second, AI tools can search for software flaws faster than people can. A software flaw is a weakness criminals may use to enter a system.
AI can help attackers find more possible entry points in less time. However, the report did not identify which specific incidents involved AI-assisted attacks.
Finally, the ITRC recorded 21 malicious insider incidents during the first half of 2026.
A malicious insider may be an employee, former employee, or vendor who intentionally misuses access to private information.
ITRC President James Lee said layoffs, especially in the technology sector, may be contributing to the increase.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
