Data Breaches Hit Record Pace in 2026, and AI Is the Accelerant

Data breach notices are on pace to smash last year’s record, and artificial intelligence is the biggest reason why. I’ve been tracking cyber trends for decades, and the acceleration we’re seeing right now is different.

The Identity Theft Resource Center reported 1,803 data compromises in the first half of 2026. If the second half continues at this rate, the full-year total will exceed the 3,321 incidents reported for all of 2025. More than 471 million victim notices were issued, with the Canvas education tool breach alone accounting for 275 million of those.

AI Is Now the Attack Engine

This isn’t just a numbers story. IBM’s 2026 Cost of a Data Breach report found that one in four breaches between March 2025 and February 2026 was AI-enabled, up 56% from the previous year. The global average cost of a breach reached $4.99 million. That’s not inflation talking. That’s AI doing the heavy lifting for attackers.

The attack pattern has shifted. Hackers used to rely heavily on phishing emails and stolen passwords. Now they’re using AI to discover software vulnerabilities faster than defenders can patch them. Nearly a third of all breaches now start with software flaws, overtaking stolen credentials as the top entry point, according to Verizon’s 2026 Data Breach Investigations Report. Generative AI can scan millions of lines of code, identify weak spots, and write matching malware in hours. What used to take a skilled operator weeks now happens over a weekend.

CrowdStrike reported that AI-enabled attacks increased 89% year-on-year in 2025. The technology is lowering the skill floor for less sophisticated operators while giving advanced threat actors new capabilities. We’re seeing both script kiddies and nation-state groups using the same tools.

The Insider Threat Just Got Worse

Insider threats are spiking too. The ITRC recorded 21 malicious insider incidents in the first six months of 2026, compared to just three for all of 2025. Some of that involves disgruntled laid-off workers stealing data on their way out. But the bigger concern is organised. North Korean state actors are placing remote IT workers in US companies using deepfake video interviews and AI-generated resumes. The FBI has flagged this as a significant structural threat. These aren’t random hacks. This is a sustained campaign.

What’s particularly worrying is how little companies tell victims. Only 24% of breach notifications in the first half of 2026 included details about what happened. In 2021, that figure was 93%. Companies have learned to say as little as possible to avoid lawsuits, leaving you in the dark about whether your data was actually protected.

What You Can Actually Do

The basics haven’t changed, but most people still ignore them. Pull your free credit reports at AnnualCreditReport.com as often as once a week. Look for accounts you didn’t open. Consider placing a credit freeze with all three major bureaus. That’s the closest thing to Fort Knox for your credit profile. Yes, it’s annoying to thaw when you actually want to apply for finance, but it blocks the majority of fraudulent account openings.

For businesses, the message is sharper. IBM found that organisations deploying AI and automation across prevention and response reduce breach costs by an average of $2.2 million. Yet most companies are still underinvesting in prevention while overinvesting in breach response. That’s backwards. You wouldn’t wait for a house fire before buying smoke detectors.

The uncomfortable reality is that AI has made bad actors faster and more effective while defenders are scrambling to catch up. Until companies treat prevention as seriously as they treat incident response, your personal data remains the commodity.


AI has collapsed the time between vulnerability and exploitation. Defenders now have hours, not months. That shift should change every security budget conversation.

James Lee, President, Identity Theft Resource Center

Related Reading

The views expressed on this site are my own and do not represent those of any current or former employer. Articles are based on publicly available information and are provided for general educational purposes.

Subscribe

Related articles

Google’s Gemini AI Autonomously Hacked Three Companies. Here’s What Happened.

Google has confirmed its Gemini AI autonomously hacked three real companies during a security test. The model guessed passwords, searched for leaked credentials, and accessed protected systems before stopping itself.

440 AI Agents Broke Into 395 Organisations in 26 Seconds. Nobody Stopped Them.

A swarm of 440 AI agents exploited two PaperCut flaws and compromised 395 organisations across 48 countries. The agents reached domain admin in 6 hours and ignored explicit instructions to stay out of 28 countries.

For $3,000 and a Few Days, Researchers Used Claude to Hack OpenAI

Security researchers used Anthropic's Claude AI to hack OpenAI's internal systems for less than $3,000 in tokens. What the HEIF Heist tells us about the new economics of cyber attacks.

The AI Hacking Crisis Is Already Here. Six New Incidents Prove It

OpenAI disclosed six new incidents where its models concealed mistakes, sought unauthorised credentials and uploaded files to the public internet. Cybersecurity experts say the real risk is powerful models meeting poor security controls.

Inside OpenAI’s Log of Misbehaving Models: Rewriting Jailbreaks and Covering Up Errors

OpenAI published six new reports of its models rewriting jailbreak instructions and concealing errors during training, alongside a faster public disclosure framework.
Philip Hall
Philip Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.