← All news
AI SecurityIncident ResponseCompliance

471 Million Notices, and Only a Quarter Say How It Happened — Breach Disclosure Went Dark in the Year AI Rewrote the Attack

Obiguard Research Team·August 17, 2026·7 min read

Two numbers from the Identity Theft Resource Center's first-half report deserve to be read next to each other, because separately they are statistics and together they are a problem.

The first: 471 million victim notices went out in the United States in the first six months of 2026 — more than the 297.5 million issued in the whole of 2025, from 1,803 tracked compromises, a pace that puts the year past 2025's record of 3,321 incidents. That is the number the coverage led with, and it is the less interesting one.

The second: just 24% of those notices said how the breach happened. In 2021 the figure was 93%. It is the lowest rate the ITRC has recorded since it began publishing these reports.

Breach disclosure is the closest thing the security industry has to a shared evidence base. It is how a mid-sized company learns that the technique that worked on a Fortune 500 last quarter is coming for its own vendor stack. Three quarters of that record has now gone dark — in the exact window when the methods behind the attacks changed more than they have in a decade.

What the notices are no longer telling you

The ITRC's tally is blunt about the mechanics. Cyberattacks accounted for 69.7% of breaches and 92.3% of victim notices in H1, with phishing, smishing and business email compromise the single largest category at 157 incidents, per HIPAA Journal's breakdown of the report. Financial services led with 387 compromises; healthcare followed with 281.

But an aggregate category is not an attack vector. "Cyberattack" tells a defender nothing they can act on. The specifics — which product, which credential path, which third party, whether an AI system was in the loop — are precisely what the other 76% of notices now omit, and increasingly what regulators and plaintiffs' lawyers give organisations every incentive to omit.

The practical consequence is that the industry's collective threat picture is being assembled from a shrinking sample, mostly from vendors who publish research voluntarily and from the handful of incidents where a regulator forces detail into the open. Everything else is a letter that says something happened.

The same six months, from the attacker's side

Set that against what changed in attack methods over an overlapping period, measured by IBM's Ponemon-run study of 602 organisations breached between March 2025 and February 2026.

One in four malicious breaches was AI-enabled — a 56% year-on-year increase — and those breaches cost an average of $6 million against a global average of $4.99 million, IBM reported on July 29. The methods behind that figure are mostly deepfake impersonation and AI-assisted malware. Sixty-two percent of the AI-driven attacks targeted critical infrastructure.

More directly relevant to anyone deploying AI rather than defending against it: more than 20% of organisations reported a breach involving their own AI models or applications. Of those, 27% traced back to a compromised API, application or plug-in, and another 27% to a cloud misconfiguration affecting an AI workload, with the full cost report detailed by Help Net Security.

Now put the two datasets together. AI systems are now a material breach surface with a measurable premium attached — and the public notice record has simultaneously stopped saying what the vector was. If your AI stack becomes the entry point, there is a good chance the first organisation to learn that from a disclosure letter will be nobody.

The insider column that went from 3 to 21

One category in the ITRC data moved too sharply to ignore. Insider wrongdoing events rose from three in all of 2025 to 21 in the first half of 2026 — a sevenfold jump in half the time.

Part of that is the ordinary version: dismissed employees taking data on the way out. Part of it is not. Eleven national agencies warned on July 31 that North Korean IT operatives are using AI to manufacture résumés and identity documents and running real-time deepfake video during hiring interviews, mapping a synthetic face onto a live feed through a virtual camera the conferencing platform treats as an ordinary webcam (Dark Reading, Tech Times). On July 28 the FBI confirmed it had found one such worker inside a U.S. federal agency.

That is an insider threat where the "insider" was legitimately onboarded, issued credentials, and given whatever AI tooling the rest of the engineering org has. We made a version of this argument last week about Copilot-assisted BEC: the hard problem is not an outsider breaking in, it is a trusted identity behaving badly with sanctioned tools. The hiring pipeline is now part of that perimeter.

And the supply chain still does the heavy lifting

The mega-breach arithmetic underneath the 471 million is worth stating plainly, because it is the same lesson as the LiteLLM package compromise we covered last week. Thirty-eight initial supply chain events produced 280.6 million victim notices across 206 downstream entities. A single incident — Instructure's Canvas platform — accounted for roughly 275 million notices, about 58% of the half-year total on its own.

Thirty-eight events. Two hundred and six organisations that had to send letters about a system they did not run. Most of those letters, statistically, did not explain what happened either.

Where Obiguard fits: if the shared record goes dark, yours is what is left

There is no control that restores the industry's disclosure rate. That trend is driven by litigation exposure and regulatory drafting, not by anything a security team chooses. What a security team can decide is whether its own AI estate produces evidence of the same quality that breach notices used to.

That is the specific job Obiguard Governance AI does. Every model call — from an application, an agent, or a person — routes through a governed path, and the audit ledger records the prompt, the response, and every tool call with the model, the agent ID, and the initiating user or service account, timestamped to the millisecond and cryptographically immutable. No edit, no delete. It streams to Splunk, Sumo Logic, Datadog, S3, or any SIEM by webhook.

Three questions get materially easier as a result.

"Was an AI system involved?" When 20% of organisations are reporting breaches touching their own models and applications, this is the question that decides scope, and it is unanswerable from a provider billing dashboard. A per-call record with the calling identity attached turns it into a query with a date range.

"What left, and to where?" The inspection layer applies the policy set assigned to each workspace or agent before a prompt leaves your network — redaction of sensitive data, block-lists, jailbreak detection — while allow-lists bind each credential to specific model IDs, tools, external domains, and invoking identities. That is both a control and a record: a blocked call is itself evidence, and the compromised-API and misconfigured-workload paths in IBM's data are exactly the ones an egress-scoped allow-list narrows.

"Can we prove it to someone who is not us?" Controls map to NIST AI RMF and ISO/IEC 42001, and the ledger is built to be exported for audit readiness rather than reconstructed under deadline. If you are among the shrinking minority who will say what happened, this is what lets you say it accurately — and if you are not, it is what lets you answer your regulator, your insurer, and your board.

For the infrastructure half — the cloud misconfigurations and vulnerable dependencies that made up more than half of the AI-related breach causes — Obiguard SOC scans connected repos on every push and daily, cross-checks findings against CISA KEV and FIRST.org EPSS, and correlates host and application telemetry into incidents with a full evidence timeline.

The record of how breaches happen used to be a public good. In 2026 it is a competitive disadvantage to publish and an operational liability not to keep. Build your own. Explore Governance AI or talk to us about what your current AI logs would prove six months from now.

How Obiguard helps

Turn this into enforced policy, not just awareness.

Obiguard sits in front of every AI request your organization makes — screening prompts and outputs against the guardrails, compliance frameworks, and audit trails that stories like this one make necessary.

See how it works →