Data Compromise Notices Surge to Record High Mid-Year, Driven by Mega-Breaches Targeting Younger Individuals
A new report from the Identity Theft Resource Center reveals a record surge in data compromise notices, exceeding last year's total midway through the current year. This trend is primarily driven by large-scale 'mega-breaches', including a significant incident involving the…

Atlanta, GA, September 9, 2026 —
The Identity Theft Resource Center (ITRC) has released a new report indicating a record-breaking surge in data compromise notices. Midway through the current year, the number of these notices has already surpassed the total recorded for the entirety of the previous year.
This significant increase is largely attributable to the prevalence of large-scale ‘mega-breaches’. These incidents, characterized by their massive scope, are responsible for a disproportionate number of compromised data notifications.
One prominent example highlighted in the report is a substantial data compromise event affecting the Canvas education platform. This single incident alone is reported to have generated hundreds of millions of individual data compromise notices. The scale of this breach suggests a strategic focus on acquiring data, potentially for future exploitation.
The ITRC’s findings also point to a growing trend of targeting younger individuals for data acquisition. The concentration on obtaining data from this demographic signifies a potential shift in the landscape of cyber threats and identity theft. The full implications and the specific methodologies employed in these breaches are subjects of ongoing analysis by cybersecurity experts.
Further details regarding the total number of notices beyond the comparison to last year’s total, specific dates of the identified breaches, names of other affected organizations beyond Canvas, or geographical locations were not provided in the summary of the report. The report’s authors have not yet released additional information concerning the precise methods used by threat actors or the types of data most frequently compromised beyond what is implied by the term ‘data compromise notices’.
Story summarized from the original created by Caresse Jackman on www.atlantanewsfirst.com, see more information here.
