Data breaches involving consumer personal information are on pace to surpass last year record in 2026, with artificial intelligence serving as a force multiplier for cybercriminals targeting organizations worldwide. Between March 2025 and February 2026, one in four data breaches was AI-enabled, representing a 56 percent increase from the prior year, according to a new study from IBM. The finding underscores a sharp acceleration in the use of machine learning and generative AI tools by threat actors to exploit vulnerabilities at scale. The Identity Theft Resource Center, a nonprofit that tracks publicly reported data breaches, reported 1,803 data compromises in the first half of 2026 alone, up from 1,732 during the same period last year. If the second half of the year maintains that pace, the final tally will eclipse the 3,321 security incidents reported for all of 2025. More than 471 million victim notices were associated with those first-half compromises, according to the ITRC report. A single cyber incident at education tool Canvas accounted for more than half of those notices, at 275 million. The half-year total already surpasses the 297.5 million notices issued in all of 2025. ## AI Lowers the Barrier for Attackers The surge coincides with a rapid improvement in AI capabilities that allow threat actors to automate reconnaissance, craft convincing phishing campaigns, and generate polymorphic malware that evades traditional detection systems. CrowdStrike 2026 Global Threat Report documented an 89 percent increase in attacks by AI-enabled adversaries, calling the technology a force multiplier that has reached a critical turning point. Google Cloud Cybersecurity Forecast 2026 echoed that assessment, warning that threat actors will leverage AI to escalate the speed, scope, and effectiveness of their attacks throughout the year. "We continue to see this ever-increasing number of data breaches," said James Lee, president of the Identity Theft Resource Center. "That does not appear to be slowing down." The financial stakes are enormous. Cybersecurity now ranks among the top three priorities for 93 percent of audit committees at public companies, according to a 2025 survey from Deloitte Center for Board Effectiveness and the Center for Audit Quality. Half of the 237 respondents ranked cybersecurity as their leading priority. ## Malicious Insider Threats Spike A separate but related trend is compounding the problem. The ITRC report documented 21 incidents involving malicious insiders in the first half of 2026, compared with just three for all of 2025. "The raw number doesn't look very big, but when you look at the historical trend line, insiders haven't been big sources of data breaches," Lee said. "We've never seen more than three data breaches in a given year related to a malicious insider, and you get 21 in six months." Some of those incidents stem from disgruntled laid-off employees stealing information on their way out the door. Others are linked to a scam flagged by the FBI in which North Korea places remote IT workers in U.S. businesses using stolen identities, deepfake videos during interviews, and AI-generated resumes. The ITRC report described this as "arguably the most significant structural driver of malicious insider attacks." ## Corporate Spending Rises but Gaps Remain Companies are responding with larger budgets. A PwC survey of 3,887 business and technology executives from 72 countries found that 78 percent of organizations plan to increase cybersecurity spending over the next 12 months. Yet the notification landscape remains fragmented. Only 24 percent of notices sent to affected consumers in the first half of 2026 included details of the data breach, down from 93 percent in 2021. "We don't have any uniformity," Lee said. "Where you live determines if you find out about a breach, and if you do find out, what you're told." For consumers, credit experts recommend freezing credit at Equifax, Experian, and TransUnion as the most robust protection against unauthorized account openings. John Ulzheimer, president of The Ulzheimer Group in Atlanta, called it "the Fort Knox of credit protection." The convergence of AI-powered attack tools, insider threats, and inconsistent consumer protections has created what multiple security firms describe as the most challenging cyber threat environment in more than a decade.