I have been warning audiences for two years that AI-assisted cyber attacks would move from research labs to everyday crime. The numbers from the first half of 2026 prove that warning was not alarmist. It was simply early.
The Identity Theft Resource Center reported 1,803 data compromises in the first six months of 2026, already beating the 1,732 incidents recorded in the same period last year. More than 471 million victim notices were issued. A single breach at education tool Canvas accounted for 275 million of those notices, but even stripping that out leaves a terrifying baseline. The trend line is not flattening. It is accelerating.
AI is no longer a niche attack vector
Between March 2025 and February 2026, one in four data breaches was AI-enabled, according to an IBM study. That represents a 56% increase from the previous year. We are past the proof-of-concept phase. Attackers are now using artificial intelligence to discover vulnerabilities faster, craft more convincing phishing campaigns, and automate reconnaissance at machine speed.
The Verizon 2026 Data Breach Investigations Report reached a similar conclusion. Nearly a third of breaches now start with software vulnerabilities, overtaking stolen passwords as the primary entry point. AI makes it easier to find and exploit those weaknesses before patches arrive.
The insider threat is being weaponised
One of the most disturbing trends in the ITRC data is the spike in malicious insider incidents. There were 21 such events in the first half of 2026, compared with just three for the entire previous year. Part of that increase comes from disgruntled laid-off workers stealing data on their way out the door. But a larger structural driver is more sinister.
The FBI has flagged a campaign in which North Korean operatives place remote IT workers inside US businesses using stolen identities. They use deepfake videos during interviews and AI-generated resumes to bypass hiring checks. Once inside, they have legitimate access. They do not need to hack the perimeter because they already hold the keys.
What this means for you
Enterprise security budgets are responding. A PwC survey found that 78% of companies plan to increase cybersecurity spending over the next 12 months. Deloitte reported that cybersecurity ranks among the top three priorities for 93% of audit committees at public companies. That is welcome, but it does not help you tonight.
The practical steps remain unchanged, yet most people still ignore them. Review your credit reports at AnnualCreditReport.com as often as weekly. Freezing your credit at each of the major bureaus is the closest thing to a kill switch for identity theft. It is free, it is reversible, and it stops most new-account fraud before it starts.
If you do not want the hassle of lifting freezes when you apply for credit, a fraud alert compels lenders to contact you first. It is weaker than a freeze, but it is better than nothing.
Where you live determines if you find out about a breach, and if you do find out, what you are told.
James Lee, President, Identity Theft Resource Center
Lee is pointing out the patchwork of state breach-notification laws in the US. Only 24% of breach notices sent to consumers in the first half of 2026 included meaningful details about what happened, down from 93% in 2021. Companies have learned that less disclosure means less litigation, so they are telling us the bare minimum. That means you cannot wait for an email to tell you your data is out there. Assume it already is.
The real vulnerability is speed
AI does not create new types of vulnerability. It removes the time constraint that used to give defenders an edge. A human attacker might find one critical flaw in a month. An AI-assisted platform can scan thousands of systems in hours and chain together minor weaknesses into a full compromise. That speed asymmetry is the crisis.
For individuals, the answer is not a new app or a subscription service. It is boring, basic hygiene: credit freezes, password uniqueness, multi-factor authentication on every account that offers it, and scepticism toward unsolicited contact. For organisations, the answer is assuming breach and designing for detection, not just prevention.
The breach numbers will keep climbing until the cost of holding data exceeds the value of exploiting it. Right now, the economics favour the attackers. AI has made them faster, cheaper, and harder to catch. We need to flip that equation.
Related Reading