(InvestigateTV) — The number of data-compromise notices sent to consumers has already surpassed last year’s total, according to a new report from the Identity Theft Resource Center.
James Lee, president of the Identity Theft Resource Center, known as ITRC, said the increase reflects a real rise in data breaches, not just better detection.
“What we’re actually seeing, we believe, is an actual increase in the number of data breaches,” Lee said. “And it is largely because technology is making it easier. And once they have that information, it’s easier for a cyber criminal to actually commit other crimes.”
The ITRC recorded more than 1,800 data compromises in the first six months of the year. Those compromises generated an estimated 471 million notices, already exceeding 2025’s full-year total. The figure counts notices, not necessarily unique people.
Lee said the return of so-called mega-breaches is driving much of the increase. One of the largest involved the Canvas education platform. The ITRC estimates that incident generated 275 million notices, though the confirmed number of U.S.-based people affected is still pending.
“Those are, in many cases, children or their former students, who are still young adults, as well as the employees and maybe parents of the people who were students at these schools,” Lee said. “That’s a treasure trove of information. And that’s one of the things we’re also seeing over time — more of a concentration on getting information of younger and younger people.”
The report found only 24% of notices explained how the breach happened, the lowest rate the ITRC has recorded.
“The problem keeps getting worse and worse and worse,” Lee said. “And that is the lack of transparency in data breach notices. We’ve got to solve this transparency issue.”
Lee said a data breach does not automatically mean personal information has been misused, and there are still steps consumers can take to reduce their risk.
“Don’t lose hope, because a data breach does not mean your information has been misused,” Lee said. “You still have a chance to make it less valuable. And that becomes the game. It’s not prevention, because you can’t prevent a data breach, unfortunately.”
Lee recommends freezing credit files and using passkeys when they are available. For other accounts, he recommends using strong, unique passwords. The ITRC also advises turning on multi-factor authentication for sensitive accounts, including email, banking and retirement accounts.
Copyright 2026 Gray Media Group, Inc. All Rights Reserved.
