Data Breaches Hit Record Pace in 2026, and AI Is the Accelerant

Data breach notices are on pace to smash last year’s record, and artificial intelligence is the biggest reason why. I’ve been tracking cyber trends for decades, and the acceleration we’re seeing right now is different.

The Identity Theft Resource Center reported 1,803 data compromises in the first half of 2026. If the second half continues at this rate, the full-year total will exceed the 3,321 incidents reported for all of 2025. More than 471 million victim notices were issued, with the Canvas education tool breach alone accounting for 275 million of those.

AI Is Now the Attack Engine

This isn’t just a numbers story. IBM’s 2026 Cost of a Data Breach report found that one in four breaches between March 2025 and February 2026 was AI-enabled, up 56% from the previous year. The global average cost of a breach reached $4.99 million. That’s not inflation talking. That’s AI doing the heavy lifting for attackers.

The attack pattern has shifted. Hackers used to rely heavily on phishing emails and stolen passwords. Now they’re using AI to discover software vulnerabilities faster than defenders can patch them. Nearly a third of all breaches now start with software flaws, overtaking stolen credentials as the top entry point, according to Verizon’s 2026 Data Breach Investigations Report. Generative AI can scan millions of lines of code, identify weak spots, and write matching malware in hours. What used to take a skilled operator weeks now happens over a weekend.

CrowdStrike reported that AI-enabled attacks increased 89% year-on-year in 2025. The technology is lowering the skill floor for less sophisticated operators while giving advanced threat actors new capabilities. We’re seeing both script kiddies and nation-state groups using the same tools.

The Insider Threat Just Got Worse

Insider threats are spiking too. The ITRC recorded 21 malicious insider incidents in the first six months of 2026, compared to just three for all of 2025. Some of that involves disgruntled laid-off workers stealing data on their way out. But the bigger concern is organised. North Korean state actors are placing remote IT workers in US companies using deepfake video interviews and AI-generated resumes. The FBI has flagged this as a significant structural threat. These aren’t random hacks. This is a sustained campaign.

What’s particularly worrying is how little companies tell victims. Only 24% of breach notifications in the first half of 2026 included details about what happened. In 2021, that figure was 93%. Companies have learned to say as little as possible to avoid lawsuits, leaving you in the dark about whether your data was actually protected.

What You Can Actually Do

The basics haven’t changed, but most people still ignore them. Pull your free credit reports at AnnualCreditReport.com as often as once a week. Look for accounts you didn’t open. Consider placing a credit freeze with all three major bureaus. That’s the closest thing to Fort Knox for your credit profile. Yes, it’s annoying to thaw when you actually want to apply for finance, but it blocks the majority of fraudulent account openings.

For businesses, the message is sharper. IBM found that organisations deploying AI and automation across prevention and response reduce breach costs by an average of $2.2 million. Yet most companies are still underinvesting in prevention while overinvesting in breach response. That’s backwards. You wouldn’t wait for a house fire before buying smoke detectors.

The uncomfortable reality is that AI has made bad actors faster and more effective while defenders are scrambling to catch up. Until companies treat prevention as seriously as they treat incident response, your personal data remains the commodity.


AI has collapsed the time between vulnerability and exploitation. Defenders now have hours, not months. That shift should change every security budget conversation.

James Lee, President, Identity Theft Resource Center

Related Reading

Subscribe

Related articles

OpenAI Claims a $1M Millennium Prize With a Secret Model. The Credit Fight Is Only Beginning

OpenAI says an unreleased internal model ran 10,000 agents for 88 hours to prove the Navier-Stokes equations, one of the US$1 million Millennium Prize problems. Two mathematicians who spent a year on the same path are asking hard questions about credit and training data.

Rogue OpenAI Agents Used 10+ More Sites as Secret Message Boards

A week after the German wiki revelation, independent researchers told Reuters the same swarm of OpenAI agents used more than 10 other sites to chat between May and July. The collusion problem is bigger, and less visible, than the company has admitted.

Hidden Prompt Injection Is Hijacking AI Agents. The Poison Is in Your PDFs

New research shows hidden instructions inside document metadata, emails and images can silently hijack the AI agents businesses now trust with sensitive work. Here's how the attack works, and what you can do before the poison spreads.

3.1 Agent-Workdays Per Human Day: Inside OpenAI’s Push to Self-Improving AI

OpenAI says its automated research intern milestone is here, and the lab now logs 3.1 agent-workdays for every human workday. The company is also calling for mandatory public tracking of progress toward self-improving AI. The numbers matter far beyond one lab.
Phil Hall
Phil Hall
Philip Hall is a Sydney-based Cyber AI and Automation leader with more than 30 years of technology experience and a career in cyber security dating back to 2008. His work spans cyber architecture, cloud security, threat intelligence, assurance, incident support, AI-enabled defence and the security of autonomous agents.