Offgrid Studio logo Offgrid Studio

Privacy News

Data Breaches Just Broke a Record. Companies Are Explaining Less Than Ever.

August 2026

The Identity Theft Resource Center tracks every publicly reported data breach in the US, and its numbers for the first half of 2026 are already worse than all of last year combined. More than 471 million breach victim notices went out between January and June — compared to 297.5 million for the entirety of 2025. A single breach, involving the Canvas education platform, accounted for around 275 million of those notices on its own. The ITRC now expects 2026 to comfortably beat 2025's record count of 3,321 separate breach events.

The number that actually stopped us

More breaches happening is bad, but not surprising given everything we've been writing about lately. The number that stood out to us was a different one: only 24% of breach notifications sent to consumers in the first half of 2026 explained how the breach actually happened. In 2021, that figure was 93%.

That's not a small drift. It's the difference between "here's what went wrong and what we're doing about it" being the norm, and being the exception. Companies are disclosing that a breach happened — often because they're legally required to — while saying almost nothing about the cause, the scope, or what changed as a result.

Why the explanations are disappearing

Part of the reason, according to ITRC's reporting, is that breach notification laws vary enormously by state and don't require much detail — many companies now write notices to satisfy the legal minimum rather than to actually inform anyone. Litigation risk plays a role too: saying less in an official notice means saying less that could be used against a company later. The result is a predictable outcome from a broken incentive, not a coordinated cover-up. But the effect for the average person is the same either way — you're told something happened to your data, and left to guess at everything else.

Where this connects to how we build

We started publishing our own network audits for the opposite reason most companies write thin breach notices — not because we're required to, but because "trust us" doesn't hold up well against a background rate of one AI-enabled breach in every four incidents. If our apps ever mishandled something, we'd rather over-explain than under-explain. That's easier for us to promise than most companies, mostly because our architecture gives us less to hide in the first place — there's no central database of your recordings or transcripts that could be breached, because it doesn't exist.

What this means practically

If you're on the receiving end of a breach notice this year, the ITRC's advice is worth repeating: freeze your credit files where you can, and move toward passkeys instead of passwords where services support them. For anyone building software that touches personal data, the more useful lesson might be about the notice itself — the number of companies explaining what happened is shrinking exactly when explanations matter most.

More from Offgrid Studio

Also read: It Wasn't Just One AI Lab. Now It's Three. and We Ran Our Own Network Audit. Here's What We Found.

Back to the blog