More Breaches, Fewer Answers

2.format jpeg 1180061972

Publicly reported data compromises are up nearly 30 percent since 2023. The notices explaining them are becoming less useful.

There is a familiar little ceremony that happens after a company loses control of customer data. First, it announces a “security incident.” Then it says it acted immediately, brought in outside experts, and takes YOUR privacy VERY seriously. Somewhere near the bottom, after several paragraphs of verbal furniture, it may finally tell us what happened.

Or it may not.

Sponsored

That ceremony is happening more often.

The Identity Theft Resource Center counted 1,393 publicly reported United States data compromises during the first half of 2023. The total increased to 1,571 in 2024, 1,732 in 2025, and 1,803 in 2026.

Using those published totals, the first half of 2026 produced 29.4 percent more data compromises than the same period in 2023. That is nearly one-third more breaches in three years.

That was not one spectacular explosion. It was a steady ratchet.

Compromises increased 12.8 percent in 2024, another 10.2 percent in 2025, and 4.1 percent in 2026. The rate of growth slowed, but the total never turned around.

A sufficiently creative spokesperson might call that progress. The rest of us might notice that 1,803 is still the highest first half total the ITRC has recorded. If the current pace continues, 2026 could finish with roughly 3,600 compromises and break the record set only last year.

The number of victims tells a much stranger story.

ITRC 2026H1 DataBreachReport Infographic H.jpg 4101174878

The ITRC reported 156.6 million victim notices during the first half of 2023. That figure jumped to nearly 1.08 billion in 2024, fell to 165.7 million in 2025, then climbed to 471.2 million in 2026. (Doesn’t have 153+ million victims in IDSCAN breach).

That is not a useful trend line. It is a warning about how easily one enormous breach can swallow the graph. The Canvas breach alone generated an estimated 275 million victim notices during the first half of l2026. It accounted for about 58 percent of the entire total.

This is why percentages involving victims or exposed records need an asterisk the size of a server rack. The number of compromises tells us how often organizations are losing control of data. The number of victims often tells us whether the largest breach that year was merely awful or cartoonishly enormous.

Then there is the part that makes this more than another annual misery count.

In 2023, the ITRC said 534 breach reports contained no actionable information about the root cause. That was already more than 38 percent of the total.

In the first half 2026, only 76 percent of breach notices tracked by Identity Theft Resource Center did not disclose an attack vector. Put another way, roughly three out of every four notices failed to explain how the attacker got inside.

The measurements are described somewhat differently, but the direction is difficult to miss. More organizations are reporting that a breach occurred while fewer are explaining how it occurred.

Some of that uncertainty is understandable. Modern breaches rarely stay inside neat organizational borders.

During the first half of 2026, just 38 initial supply chain attacks spread across 206 organizations and generated more than 280 million victim notices. A company may discover that its data was exposed long before the original vendor understands how the attacker entered its system.

But temporary uncertainty has a habit of becoming permanent silence.

A notice may tell victims that names, addresses, Social Security numbers, or medical information were exposed. It may offer credit monitoring and recommend a password change. What it often does not say is whether the attacker stole a vendor token, exploited an unpatched internet facing device, abused employee credentials, or received help from someone on the inside.

Those are entirely different doors. They require entirely different locks.

Without that information, other organizations cannot determine whether they share the same exposure. Security teams cannot measure which defenses are failing most often. Customers cannot tell whether the company learned anything beyond how to hire a public relations firm.

The attackers receive a working case study. Everyone else receives a carefully worded apology.

databreaches

Data breach disclosure was supposed to create visibility. Instead, it is drifting toward incident accounting. We count the organizations, tally the victims, send the letters, and move on without explaining the part most likely to prevent the next breach.

Yes, data compromises are up nearly 30 percent compared with the first half of 2023.

But the more troubling number may be 24 percent.

That is the portion of current breach notices that actually tells us how the attacker got in.

If every new breach record arrives with fewer useful details, we are not getting better at understanding cyberattacks.

Until breach reporting becomes more than another KPI, every missing attack vector is a lesson thrown away. We cannot map how attacks are evolving or sharpen our defenses if the most useful part of the story is never told.

It’s time to retire “AI” as the catchall explanation. That label does little to strengthen our defenses if we never learn how the attacker actually got into the network.

We are simply getting very good at counting the wreckage.


Discover more from Solide Info | The Engineer’s Authority on Cyber Defense

Subscribe to get the latest posts sent to your email.