Identity Theft Resource Center
Reports
All Statistics
Zero-day attacks rose to 14 events in H1 2026, nearly matching the 17 events recorded in all of 2025.
Only 24% of H1 2026 breach notices contained attack-vector details, the lowest rate ever recorded by the ITRC.
A single Canvas data compromise generated an estimated 275 million victim notices, accounting for 58% of the H1 2026 total.
53% of victims with no financial loss reported a resolution.
Account-problems scams are the highest-volume scam type, with 74% of victims sharing high-value personally identifiable information (PII).
25.6% of identity crime victims managed two or more concurrent incidents, up from 23.5% the previous year.
The Identity Theft Resource Center tracks 3,322 data compromises in 2025 (2025)
Data compromises in 2025 represent a 79 percent jump over five years (2025)
Seventy percent (2,324) of data breach notices in 2025 do not include attack information, compared to 65 percent (2,049) in 2024 and 45 percent (1,449) in 2023 (2023–2025)
AI-powered attacks were identified as a root cause in more than 40% of small business cyber events.
81% of small businesses reported suffering a security breach, a data breach, or both in the past year.
In 2025, only 38.4% of small business leaders felt 'very prepared' for a cyberattack, down from 56.5% in 2024.
19.6 percent of self-identified victims in the general population reported losses under $500 in 2025.
From August 2024 to July 2025, the ITRC responded to requests for direct assistance from 4,122 individuals seeking help with identity theft, fraud, and scams.
More than 20 percent of ITRC victims reported losses exceeding $100,000 in 2025.
69% of 2025's breach notices did not include an attack vector. This is an increase from 65% for the full year 2024.
About 0.5% of all security breaches in the first half of 2025 were supply‑chain incidents, but these incidents generated nearly half of all breach notifications, affecting almost 700 companies.
78% of compromises reported in the first half of 2025 were true data breaches. These accounted for 69% of the breach notices issued in the first half of 2025.
Of attempted misuse attempts that involved financial accounts, 14% involved checking accounts.
New types of scams reported included toll road scams, which accounted for 3% of all reported scams.
For attempted misuse, thieves tried to open a new account (69%) more often than attempting to take over an existing account (31%).
Among men (~54%), the number of people who would ban biometrics was significant.
91% of respondents provided a biometric identifier even if they had concerns about doing so.
36% of respondents did not believe biometric use should be banned.
The Financial Services industry was the most breached in 2024, followed by Healthcare, Professional Services, Manufacturing and Technology.
Stolen credentials were the leading attack vector in 133 cyberattacks against publicly traded companies.
Six "mega-breaches" accounted for more than 1.4 billion of the 1.7 billion victim notices issued in 2024.
Financial services recorded the highest frequency of compromises by sector at 387.
Healthcare compromises rose to 281, reversing a slight downward trend from the previous year.
Manufacturing produced 74 million victim notices in H1 2026 compared to 1.97 million in all of 2025.
There were 1,803 data compromises in the first half of 2026.
Q2 2026 tallied 1,029 compromises, the second-highest single-quarter total on record.
2025 recorded 3,321 compromises, and 2026 is on pace to set a new annual record above that.
Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
The number of victim notices issued during the first six months of the year reached an estimated 471.2 million, eclipsing the 297.5 million notices in all of 2025.
Publicly traded companies accounted for 10.3% of compromises but generated 83.4% of all victim notices.
Supply chain attacks generated 280.6 million victim notices from 38 initial breach events, impacting 206 entities.
62.1% of attempted misuse cases involved new account applications, and 37.9 percent involved attempted account takeovers.
By account type, credit cards accounted for 41% of all attempted misuse, checking accounts account for 17.7%, and personal loans account for 8.5%.
Unauthorized access to computers and mobile devices accounted for 27.2% of identity compromises, a 78% increase from 15.3% the previous year.
0% of victims who experienced three or more financial impacts reported a resolution.
Fraudulent employment accounted for 40% of misuse cases for children and dependents.
49% of Colorado residents reported multi-layered identity incidents, the highest rate among states.
9% of victims with any financial impact were able to resolve their cases.
Attempted misuse cases caught by financial institutions increase by 26.8%.
Scams involving the sharing of personal information accounted for 36.1% of identity compromises, down from 43.1% the previous year.
Fifty percent of affected consumers cite immediate financial fraud as their primary fear, and 54 percent of consumers report an increase in targeted phishing attempts after a breach (2025)
The Identity Theft Resource Center sets a new record with 3,322 data compromises in 2025, up four percentage points from the previous all-time high in 2023 (3,202) (2025)
Eighty-eight percent of consumers who received a data breach notice experience at least one negative consequence after a breach; 40 percent experience an increase in phishing or scam attempts; 49 percent experience an increase in spam emails or robocalls; 40 percent experience attempted takeover of an existing account (2025)
In 2025, Financial Services had 739 compromises; Healthcare had 534 compromises; Professional Services had 478 compromises; Manufacturing had 299 compromises; Education had 188 compromises (2025)