Six months into 2026, the breach numbers were already worse than last year. And last year was a record from the year before.
According to the Identity Theft Resource Center (ITRC), a nonprofit that tracks publicly reported breaches and assists victims of identity theft, U.S. organizations issued an estimated 471.2 million data breach victim notices in the first half of 2026. For all of 2025, the total was 297.5 million.
The ITRC also recorded 1,803 data compromises through June 30, putting 2026 on pace to surpass 2025’s record of 3,321 annual incidents if the second half stays anywhere close to the first.
One thing to point out is that victim notices and unique individuals aren’t the same thing. A single person notified by three different organizations counts three times in that 471 million figure. This means that the headline number reflects notification volume, not necessarily distinct people. That said, that already exceeds the entire U.S. population. Statistically, every American could have been affected more than once.
What’s Driving the Numbers
One of the biggest issues pushing these numbers up is mega-breaches. A breach involving education platform Canvas, operated by Instructure Holdings, accounted for an estimated 275 million of those notices. That’s roughly 58% of the entire first-half total. A handful of very large incidents can dramatically increase the number of breaches.
Then there are supply chain attacks. Thirty-eight initial supply chain compromises generated 280.6 million victim notices and affected 206 total entities. Â This is extremely relevant to small businesses, which are usually the downstream entity rather than the primary target.
Additionally, AI-enabled attacks are increasing. IBM’s analysis found a 56% year-over-year increase in AI-enabled breaches, with one in four malicious breaches from March 2025 to February 2026 involving AI.
Finally, insider threats jumped up significantly. The ITRC recorded 21 insider incidents in H1 2026. That’s seven times the three incidents recorded in all of 2025. The organization attributed the increase to tech-sector layoffs and nation-state recruitment schemes. Most traditional security tools aren’t designed to catch this, and most small businesses aren’t thinking about it at all.
Wondering where your business stands against these trends? MainNerve has been helping organizations understand their exposure for over 20 years. Start the conversation today.
What This Means If You’re a Small Business
The headline numbers are driven by mega-breaches at large organizations. But the downstream implications land on businesses of all sizes.
Most small business owners wonder whether they will be breached directly. In addition, they should be worried about what happens if their vendors get breached.
Supply chain attacks generate a large number of victim notices because a single initial compromise can ripple through hundreds of organizations. Financial services led all industries with 387 compromises in H1, followed by healthcare with 281. Manufacturing accounted for 74 million victim notices, compared with 1.97 million for all of 2025. Small businesses in each of those industries rely on vendors and platforms operating in those sectors.
If your payroll provider gets breached, you send breach notifications. If your accounting software vendor gets breached, you may have regulatory obligations regardless of anything your team did. Or, if the platform your business runs on gets compromised, as Canvas did, your customers receive notifications with your name attached, even though the breach never touched your environment.
Your security posture isn’t just about what’s in your own systems. It’s about what’s in the systems of every vendor and service provider that touches your data.
There’s also a transparency problem. 76% of all breach notices in H1 2026 failed to include any information about the attack vector, meaning most people who received a notice never learned how their data was taken. That information is important when you’re evaluating vendors. A vendor who has experienced a breach and told their customers very little about what happened is telling you something useful about how they handle accountability.
Â
Vetting Your Vendors More Seriously
Many small businesses outsource their work because it’s more cost-effective than hiring a full-time employee. Given the risks mentioned above, here are some questions to ask when evaluating current or new vendors.
First, ask whether they’ve had a breach, and if so, how they handled it. A vendor who had a breach, disclosed it promptly, contained it, and improved their controls is often more trustworthy than one who’s never been tested. What you’re looking for is honesty and what they did next.
Then, ask what data they hold on your behalf and how it’s protected. A vendor who answers quickly and clearly has thought about it. One who struggles to answer probably hasn’t.
Next, ask how they handle their own vendors. Supply chain breaches don’t always start with the vendor you hired. They can also start with the vendor your vendor hired. Whether your critical vendors have security requirements for their own third parties is a reasonable question that most businesses never raise.
You can also check whether they’ve been in the news. Searching a vendor’s name alongside “breach” or “data incident” takes about three minutes. The ITRC’s breach database is publicly searchable.
Finally, read the breach notification clause in your contracts. Most vendor agreements have language about what happens after a security incident. Many small businesses have never looked at it. That clause tells you how quickly they’re required to notify you, what information they have to provide, and what remedies you have. In most standard contracts, those terms favor the vendor. Knowing that before you need it is better than discovering it during a breach.
The Takeaway
“We have already far surpassed the number of victim notices from last year,” said James Lee, president of the Identity Theft Resource Center. “And last year was a record-breaking year for the number of data breaches.”
The trend line isn’t looking good. More breaches, more victims, more AI involvement, more insider activity, more supply chain exposure. The organizations that come through this environment in decent shape are the ones that stopped treating security as a compliance checkbox, including the part of security that lives in their vendors’ systems, not just their own.
If you want to understand where your exposure sits, we’re glad to help you figure that out. MainNerve has been doing this work for over 20 years. Reach out to us today for your free consultation.