TL;DR:

  • The Identity Theft Resource Center counted 3,322 U.S. data compromises in 2025, a record and a 79% increase over five years.[1]
  • Seventy percent of notices omitted the attack method. The share was 65% in 2024 and 45% in 2023.[1]
  • Financial services led the count with 739 incidents, followed by healthcare with 534 and professional services with 478.[1]

The Transparency Collapse

The Identity Theft Resource Center's 20th annual report counted 3,322 U.S. data compromises in 2025. That was up from 3,152 in 2024 and represented a 79% increase over five years.[1]

The report's sharper warning concerned what companies did not disclose. Seventy percent of notices, covering 2,324 incidents, gave no information about the attack. The share was 65% in 2024 and 45% in 2023. In 2020, nearly every breached organization disclosed attack details.[1]

Insurance Journal summarized the problem with the report's blunt phrase: "Transparency is on life support." It also reported that consumers and small businesses are left "operating blind" when notices omit useful details.[2]

More Incidents, Less Useful Information

Financial services recorded 739 compromises. Healthcare had 534, professional services 478, manufacturing 299, and education 188.[1]

The victim-notice count fell from 1.37 billion in 2024 to about 279 million in 2025. The ITRC attributed that drop to the absence of the huge incidents that drove the previous year's total, not to a broad improvement in security.[1]

One of the largest 2025 compromises reused data stolen from AT&T in 2021. Old records remain useful to criminals, especially when they include identifiers that cannot be replaced as easily as a payment card.[2]

What Victims Said

The ITRC surveyed 1,040 U.S. consumers. Eighty percent had received at least one breach notice in the previous 12 months, and nearly 40% had received three to five. Among notice recipients, 88% reported at least one negative consequence. Increased spam and robocalls were the most common, followed by phishing and account-takeover attempts.[1]

The survey also found immediate anxiety among 60% of recipients and frustration among 59%. Half feared financial fraud.[1]

State Rules Still Vary

GovTech reported that 34 states require organizations to notify a state agency after qualifying breaches. Thresholds differ: Oregon uses 250 affected people, Pennsylvania 500, and Alabama 1,000.[3]

California's SB 446 took effect on January 1, 2026. It generally requires notice to affected residents within 30 calendar days. When at least 500 Californians are notified, the organization must also notify the attorney general within 15 calendar days of the individual notice.[4]

Oklahoma's SB 626 also took effect on January 1, 2026. It expanded covered information to include biometric data and additional government and financial identifiers. Breaches affecting at least 500 Oklahoma residents trigger attorney-general notice requirements.[4]

What You Can Do

  • Freeze your credit with Equifax, Experian, and TransUnion.
  • Replace reused passwords and use a password manager for unique credentials.
  • Turn on phishing-resistant authentication, such as passkeys or security keys, where available.
  • Read the notice closely. The absence of an attack explanation does not mean the exposed data is harmless.

Sources

  1. Identity Theft Resource Center via PR Newswire: 2025 Annual Data Breach Report (January 29, 2026)
  2. Insurance Journal: ITRC Says Data-Breach Transparency Is on Life Support (February 18, 2026)
  3. GovTech: 2025 Data Breach Report Finds More Compromises, Less Transparency (January 29, 2026)
  4. Alston & Bird: California and Oklahoma Breach Notification Updates for 2026