Identity Theft Resource Center
Reports
All Statistics
Zero-day attacks rose to 14 events in H1 2026, nearly matching the 17 events recorded in all of 2025.
Only 24% of H1 2026 breach notices contained attack-vector details, the lowest rate ever recorded by the ITRC.
Financial services recorded the highest frequency of compromises by sector at 387.
53% of victims with no financial loss reported a resolution.
Account-problems scams are the highest-volume scam type, with 74% of victims sharing high-value personally identifiable information (PII).
25.6% of identity crime victims managed two or more concurrent incidents, up from 23.5% the previous year.
Seventy percent (2,324) of data breach notices in 2025 do not include attack information, compared to 65 percent (2,049) in 2024 and 45 percent (1,449) in 2023 (2023–2025)
Eighty-eight percent of consumers who received a data breach notice experience at least one negative consequence after a breach; 40 percent experience an increase in phishing or scam attempts; 49 percent experience an increase in spam emails or robocalls; 40 percent experience attempted takeover of an existing account (2025)
The Identity Theft Resource Center tracks 3,322 data compromises in 2025 (2025)
In 2025, more than 80% of small businesses reported being victims of cybercrime.
AI-powered attacks were identified as a root cause in more than 40% of small business cyber events.
81% of small businesses reported suffering a security breach, a data breach, or both in the past year.
19.6 percent of self-identified victims in the general population reported losses under $500 in 2025.
From August 2024 to July 2025, the ITRC responded to requests for direct assistance from 4,122 individuals seeking help with identity theft, fraud, and scams.
More than 20 percent of ITRC victims reported losses exceeding $100,000 in 2025.
H1 2025 compromises resulted in a little more than 165.7 million breach notices.
69% of 2025's breach notices did not include an attack vector. This is an increase from 65% for the full year 2024.
About 0.5% of all security breaches in the first half of 2025 were supply‑chain incidents, but these incidents generated nearly half of all breach notifications, affecting almost 700 companies.
53% of reports of misuse involved account takeover.
Of attempted misuse attempts that involved financial accounts, 56% involved credit card accounts.
Of attempted misuse attempts that involved financial accounts, 14% involved checking accounts.
Among men (~54%), the number of people who would ban biometrics was significant.
91% of respondents provided a biometric identifier even if they had concerns about doing so.
36% of respondents did not believe biometric use should be banned.
Excluding the six mega-breaches, the number of victim notices in 2024 decreased by 36% compared to 2023.
At least 196 compromises and more than 1.2 billion victim notices could have been prevented with better cyber practices.
New Securities and Exchange Commission breach disclosure rules resulted in a 60% increase in disclosures in 2024, however, less than 10% of the notices included details of the event.
Q2 2026 tallied 1,029 compromises, the second-highest single-quarter total on record.
There were 1,803 data compromises in the first half of 2026.
The number of victim notices issued during the first six months of the year reached an estimated 471.2 million, eclipsing the 297.5 million notices in all of 2025.
Publicly traded companies accounted for 10.3% of compromises but generated 83.4% of all victim notices.
A single Canvas data compromise generated an estimated 275 million victim notices, accounting for 58% of the H1 2026 total.
Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
Healthcare compromises rose to 281, reversing a slight downward trend from the previous year.
Manufacturing produced 74 million victim notices in H1 2026 compared to 1.97 million in all of 2025.
Supply chain attacks generated 280.6 million victim notices from 38 initial breach events, impacting 206 entities.
2025 recorded 3,321 compromises, and 2026 is on pace to set a new annual record above that.
62.1% of attempted misuse cases involved new account applications, and 37.9 percent involved attempted account takeovers.
By account type, credit cards accounted for 41% of all attempted misuse, checking accounts account for 17.7%, and personal loans account for 8.5%.
0% of victims who experienced three or more financial impacts reported a resolution.
Fraudulent employment accounted for 40% of misuse cases for children and dependents.
49% of Colorado residents reported multi-layered identity incidents, the highest rate among states.
9% of victims with any financial impact were able to resolve their cases.
Attempted misuse cases caught by financial institutions increase by 26.8%.
Unauthorized access to computers and mobile devices accounted for 27.2% of identity compromises, a 78% increase from 15.3% the previous year.
Scams involving the sharing of personal information accounted for 36.1% of identity compromises, down from 43.1% the previous year.
Data compromises in 2025 represent a 79 percent jump over five years (2025)
Fifty percent of affected consumers cite immediate financial fraud as their primary fear, and 54 percent of consumers report an increase in targeted phishing attempts after a breach (2025)
The Identity Theft Resource Center sets a new record with 3,322 data compromises in 2025, up four percentage points from the previous all-time high in 2023 (3,202) (2025)
In 2025, Financial Services had 739 compromises; Healthcare had 534 compromises; Professional Services had 478 compromises; Manufacturing had 299 compromises; Education had 188 compromises (2025)