Pular para o conteúdo principal
Close
Security

471 Million Data Breach Notifications in 6 Months: The ITRC Report Showing That Breach Transparency Is Disappearing

Gabriel Ferraresi· CEO | Tech86August 4, 20264 min
securitydata-breachitrctransparencysupply-chaininsiderzero-daynotificationstatisticscybersecurity

471.2 million data breach victim notifications in the first 6 months of 2026. More than the population of the United States. More than the 278.8 million recorded in all of 2025. According to the ITRC H1 2026 report, presented by James E. Lee on July 22, if you stacked all those notifications one on top of the other, the stack would reach space. We read the report and the signal is clear: the problem is not just scale — it is opacity.

The scale: three incidents, 80% of the total

The numbers in the ITRC H1 2026 report are absurd in concentration. A single incident generated 58% of the total: Instructure, the company behind Canvas, the education platform used by thousands of schools and universities — 275 million notifications. Under Armour contributed another 72.7 million. SoundCloud 29.8 million.

Three incidents. 377.5 million notifications. 80% of the total. According to the ITRC H1 2026 report, 10.3% of compromises generated 83.4% of all notifications. The problem is focal — not diffuse. That changes the defense strategy: blast radius containment matters more than uniform coverage.

Important: 471 million is the number of notifications, not unique individuals. The same person can receive multiple notifications when their data is in several compromised services. The metric measures volume of exposure, not affected population.

The transparency crisis: 24% in 2026, near 100% in 2020

The most alarming number in the report is not notifications — it is transparency. According to the ITRC H1 2026 report, only 24% of notifications issued in the first half of 2026 included attack details. The vector. The root cause. In 2020, this number was near 100%. Every year, it falls. Every year, we know less about what is happening.

The data we have is worrying. The data we do not have is worse. When Tech86 implements security programs for corporate clients, the first diagnosis almost always reveals the same flaw: companies detect the attack. The vector remains unknown. The notification was sent because the law requires it. The vector detail was not included because the law does not require it.

The ITRC frames this as an ecosystem risk, not just a legal failure. When one company does not document the vector, the entire market stays blind to the same attack. The attacker reuses the same technique against a hundred other victims because nobody shared the indicator.

Insider wrongdoing multiplied by 7 and zero-days at the limit

According to the ITRC H1 2026 report, insider wrongdoing multiplied by 7: 21 incidents in 6 months, versus 3 in all of 2025. The report specifically cites fired tech employees recruited by nation-states to sabotage internal infrastructure. This is not conventional insider threat — it is a recruited adversary, with prior access, knowledge of the architecture, and geopolitical motivation.

Zero-days also press: 14 in the semester, nearly matching the 17 of the entire previous year. The window between vulnerability discovery and exploitable patch shrinks. When combined with insider wrongdoing, the kill chain gets shorter and dwell time gets harder to detect.

Supply chain as a structural multiplier

According to the ITRC H1 2026 report, supply chain continues to be a multiplier. 38 initial incidents generated 280.6 million notifications and impacted 206 entities. One attack, 200 victims. The math is simple: compromising one vendor means attacking every downstream at once.

This explains the concentration. When 10.3% of compromises generate 83.4% of notifications, the problem is not diffuse — it is focal. Attack paths concentrate on few surfaces: supply chain vendors, privileged identities, remote access endpoints. Zero Trust and least privilege access shrink the blast radius exactly at those points.

The projection: 3,600 incidents, fourth year above 3,000

The report projects that 2026 may surpass 3,600 incidents. The current record is 3,322, from 2025. If the projection holds, it will be the fourth consecutive year above 3,000. The trend is not stabilization — it is acceleration.

According to the ITRC, the recommendations for organizations are: Zero Trust, least privilege access, real-time vendor verification, and voluntary transparency. For individuals: freeze credit, migrate to passkeys, enable MFA. None of this is new. What changes is the urgency — and the fact that voluntary transparency, not the legal minimum, is what separates an ecosystem that learns from one that repeats the same attacks.

Conclusion: the stack keeps growing and nobody can see

The stack keeps growing. And most of it, nobody can see. 471.2 million notifications in 6 months, but only 24% with vector detail. Companies detect the attack, send the notification, and omit what matters. The legal minimum was met. The ecosystem stayed blind.

At Tech86, we help corporate enterprises build security and incident response programs that go beyond the legal minimum — documenting the vector, containing blast radius with Zero Trust, monitoring insider wrongdoing with offboarding controls, and treating supply chain as a first-class risk. Transparency is not a legal liability. It is a security investment.

Need expert guidance?

Schedule a consultation with our specialists.

Security and Incident Response Program for Corporate Enterprises

Frequently Asked Questions

According to the ITRC H1 2026 report, presented by James E. Lee on July 22, 471.2 million victim notifications were issued in the first 6 months of 2026 — more than the population of the United States and more than the 278.8 million recorded in all of 2025. Three incidents (Instructure with 275 million, Under Armour with 72.7 million, and SoundCloud with 29.8 million) accounted for 377.5 million notifications, or 80% of the total. The report projects that 2026 may surpass 3,600 incidents, against the record of 3,322 in 2025.

According to the ITRC H1 2026 report, only 24% of notifications issued in the first half of 2026 included attack details — vector, root cause. In 2020, this number was near 100%. Every year, it falls. The notification is sent because the law requires it; the vector detail is not included because the law does not require it. The ITRC frames this as an ecosystem risk, not just a legal failure — when one company does not document the vector, the entire market stays blind to the same attack.

According to the ITRC H1 2026 report, insider wrongdoing multiplied by 7: 21 incidents in 6 months, versus 3 in all of 2025. The report specifically cites fired tech employees recruited by nation-states to sabotage internal infrastructure. This is not conventional insider threat — it is a recruited adversary with prior access and knowledge of the architecture. Offboarding controls that revoke access instantly and audit privileged actions for 90 days post-departure are essential.

According to the ITRC H1 2026 report, 38 initial supply chain incidents generated 280.6 million notifications and impacted 206 entities. One attack, 200 victims. Supply chain works as a multiplier because a single vendor compromise propagates to every downstream that depends on it. The report recommends real-time vendor verification and mapping every third-party dependency to its blast radius.

According to the ITRC, for organizations: Zero Trust, least privilege access, real-time vendor verification, and voluntary transparency. For individuals: freeze credit, migrate to passkeys, and enable MFA. The report also projects that 2026 may surpass 3,600 incidents — it would be the fourth consecutive year above 3,000, against the record of 3,322 in 2025.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.