← Back to the cybersecurity blog

Three in four breach notices no longer say how the attacker got in

By Adrián González · CEO y socio fundador · Published: 21 August 2026 · Updated: 21 August 2026
Three in four breach notices no longer say how the attacker got in

Three in four breach notices issued in the United States during the first half of 2026 said nothing about how the attacker got in. Only 24 per cent disclosed the attack vector, the lowest share the Identity Theft Resource Center (ITRC) has recorded in twenty years of tracking, according to its half-year report. Press coverage went to a different number in the same report: 471.2 million victim notices in six months, more than the full-year total for 2025.

In aggregate, that omission is rarely accidental. Whether it reflects a considered decision or an investigation that never closed, more notices arrive without the detail every year. A European team assessing a supplier with US operations will sooner or later end up in that public record, and what made it worth opening is now usually missing.

What the numbers show

The ITRC report, published on 22 July 2026, counts 1,803 data exposure events between January and June. April to June alone produced 1,029, the second-highest quarterly figure in the organisation's series. At that pace the year would close near 3,600 events.

Victim notices reached 471.2 million. A single compromise at an education platform produced roughly 275 million of them, 58 per cent of the total. That concentration matters: when one incident carries more than half a six-month total, the average describes nobody.

Beneath the headline sit four signals that explain where it comes from:

  • Suppliers as multipliers. 280.6 million notices came from just 38 initial breaches that reached 206 entities. That figure includes the education platform compromise rather than sitting alongside it. In a supply chain attack, the leverage lies in the shared provider more than in the attacker's technique.
  • Staff turning on their employer. 21 cases of insider wrongdoing in six months, against 3 across the whole of 2025. The ITRC ties the jump to technology-sector redundancies and to recruitment schemes run by state actors, which makes insider threat as much a matter of economic climate as of access control.
  • Concentration. Publicly traded companies accounted for 10.3 per cent of events and 83.4 per cent of all victim notices: a handful of large organisations produce the volume.
  • Flaws with no patch. 14 events tied to zero-day vulnerabilities in six months, close to the 17 recorded across all of 2025.

These figures need a caveat. The half-year release compares 471.2 million with 297.5 million notices for all of 2025, while the annual report the same organisation published in January put 2025 at 278,827,933 notices. The series gets revised between publications. When the baseline moves by 7 per cent between two documents from the same body, what you have are orders of magnitude, and they should not be quoted to the decimal.

The series that matters is not the breach count

It is the omission count, measured in notices rather than in people. The ITRC annual report for 2025 records that 2,324 breach notices, 70 per cent of those issued that year, carried no attack information. In 2024 the figure was 2,049 (65 per cent); in 2023, 1,449 (45 per cent). The first half of 2026 pushes the share to 76 per cent.

Thirty points in three years is a change of practice across a whole market, not statistical noise. The same source sets the starting point: in 2020, the ITRC records, nearly every breached organisation gave clear detail on how it happened.

Why did organisations stop explaining how attackers got in?

Because almost nothing requires them to. Neither the federal healthcare rule nor most state notification statutes ask for a description of the entry point; they ask what happened, which categories of data were involved and what the recipient should do next. Disclosing the attack vector is optional, as Paubox's analysis of the finding sets out.

From there the calculation writes itself. Confirming that access arrived through a credential with no second factor, an unpatched server or a compromised subcontractor feeds a class action, invites a regulatory inquiry and puts up the price of the next insurance renewal. Legal teams know it and so do insurers. None of this requires bad faith from any particular company: it is the predictable response of any organisation inside a framework that makes candour expensive and reticence free.

ITRC president James E. Lee is blunter than his own report. He describes an unprecedented transparency crisis and argues that the state laws written to inform and protect people, in his words, simply do not work. In January he asked organisations to put transparency ahead of liability management. Six months on, the aggregate has moved the other way.

Two things break once the vector disappears

Supplier assessment loses its raw material

Supplier assessment questionnaires ask about previous incidents. The standard reply, that the supplier had an incident in 2025, notified it as the law required and has since remediated it, is true and tells you nothing.

Without the vector there is no way to tell whether the supplier failed at identity management, at patching, or at controlling the access it grants its own subcontractors, and those are the failures most likely to recur. Any third-party risk management programme fed only by public sources is scoring suppliers with the most important field left blank.

Then comes the knock-on. One failure at a shared provider becomes a problem for the 206 entities the ITRC counts behind those 38 breaches: organisations that never ran the compromised system and cannot audit it either. This is the dynamic that already forced a rethink of supplier control after the public package repository intrusions and the abuse of authorised integrations over the past year, a dynamic revisited in five lessons from the digital supply chain.

Defensive prioritisation loses its cheapest shortcut

The second effect draws less attention. A team working out which techniques are landing against organisations like theirs could once read public notices for a free, sector-specific and reasonably current signal. Today three in four stop at the impact, and that signal has to be replaced by paid threat intelligence, by sector information-sharing arrangements, or by nothing.

In practice, prioritisation can no longer lean on other people's incident narratives; it has to run on observed exploitation. Models such as KEV, EPSS and SSVC carry more weight now because they do not depend on anyone telling their story.

Where the vector is still on the record

Some sources still describe the entry point, and it is worth being precise about what each is good for.

  • Joint government advisories, which describe techniques and usually publish indicators. They arrive late and cover only what CISA, national CSIRTs or ENISA choose to release.
  • Platform confirmations, where the provider whose service was used in the attack states publicly what happened. Useful, and rare.
  • The CISA KEV catalogue, which rarely explains a specific incident but does confirm which flaws are being exploited.
  • Sector information-sharing groups and national CSIRTs, which circulate to members material the trade press does not carry.

None of these replaces what a supplier knows about its own incident. They are good for steering attack surface management and threat hunting, not for scoring a third party.

Is Europe better off? The root cause is documented, and stops at the regulator

Reading this as an American problem would be convenient. It is not one, and it does not leave Europe in the clear.

European rules do require the root cause. Article 23 of NIS2 sets three clocks for significant incidents: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month, and that final report must contain a detailed description of the incident together with the type of threat or root cause that likely triggered it. Financial services follow the same pattern: under DORA, entities file initial, intermediate and final reports, and the final one carries the root cause analysis and the corrective measures taken.

The same article also requires entities to inform the recipients of their services where a significant incident is likely to affect service provision. So the customer does hear about the incident. The analysis itself travels to the competent authority and the CSIRT, and stays there: whoever is assessing that supplier cannot read the final report filed with its national authority, and has no standing to demand it. Europe has built a root cause channel that ends at the supervisor.

ENISA concedes as much in the methodology of its Threat Landscape: open sources and voluntarily shared information do not add up to a complete picture of the threats, and some incidents, cyberespionage above all, are documented years after the fact. Europe's cybersecurity agency is acknowledging, in diplomatic terms, that its portrait of the problem is incomplete.

Controls that have expired, and what replaces them

What has expired is supplier assessment fed by public sources, and with it the assumption that a provider with no incidents in the press is a provider with no security problems. With 76 per cent of notices stopping at the impact, silence no longer separates one supplier from another.

What takes its place is less impressive-looking and considerably more laborious:

  • The contract clause. Requiring the supplier to tell affected customers the attack vector and the timeline within an agreed window now counts for more than any questionnaire. A supplier who refuses that clause has handed you a finding.
  • A right to evidence. Audit reports with their scope and non-conformities, dated penetration test results, patch management records. Documents that carry a date and a signature.
  • Your own telemetry on everything the supplier operates. Where a third party holds federated access, service accounts or integrations into your estate, the supplier's problem shows up in your logs before it shows up in its statement.
  • Response rehearsed in advance. Knowing which questions to ask, and of whom, in the first hours of a supplier incident is a crisis communications exercise, and those first hours are no time to write the script.
  • Internal accountability. NIS2 places the duty on the management body, and that accountability for third-party risk cannot be delegated to a supplier spreadsheet.

At Hard2bit this now surfaces in board discussions, and rarely as a debate about tooling. It is a debate about what can be demanded contractually and what is being accepted out of habit.

How this could be turned round

Only two routes would turn this round: a jurisdiction making root cause a mandatory element of the notice, or large buyers demanding it contractually before any regulator arrives. As long as disclosing the vector stays voluntary in the market that produces most public notices, and continues to carry a legal cost, the data gives no reason to expect the share to recover.

Of the two, only the second is within a single organisation's control. One question stays open: nobody knows how much of this decline is deliberate withholding and how much is investigation that never happened. A notice that stops at the impact may be hiding the origin, or may reflect that no one ever established it. The ITRC data does not separate the two, and the distinction matters. A market that does not investigate its own incidents has a worse problem than one that investigates and keeps the answer to itself.

This article analyses data published by third parties, with the information available on 21 August 2026. The ITRC figures are estimates drawn from public notifications in the United States, and the organisation's own historical series has been revised between publications, so they should be read as orders of magnitude. Nothing here is legal advice: the specific notification duties and the content required in each report depend on the framework applicable to each entity and should be confirmed with legal counsel and the relevant competent authority.

Frequently asked questions

What share of breach notices explains how the attacker got in?

In the first half of 2026, 24 per cent of notices published in the United States included details of the attack vector, according to the Identity Theft Resource Center. It is the lowest share the organisation has recorded. The decline goes back years: 55 per cent of notices gave the vector in 2023, 35 per cent in 2024 and 30 per cent in 2025.

Are organisations legally required to disclose how a breach happened?

It depends on the jurisdiction and on who is receiving the information. In the United States, describing the entry point is voluntary in most cases, which is why the share can collapse without anyone breaking a rule. In the European Union the root cause is mandatory, but it goes to the supervisor: the customer is told about the incident, not about why it happened. Neither model produces public information useful for comparing one supplier against another.

Which part of the Article 23 information under NIS2 reaches a customer?

The notification of the incident itself, where it is likely to affect delivery of the service. The 24-hour, 72-hour and one-month timetable binds the entity to its CSIRT and competent authority, and it is the one-month final report that carries the root cause. That report is neither public nor something a customer can demand, so a European business can learn of its supplier's incident and still have no idea how the attacker got in.

Why do so many companies leave the attack vector out of their statements?

It is an exposure calculation more than deliberate concealment. Every technical detail published can resurface in litigation, in a regulatory file or in the next insurance renewal, and across most US jurisdictions no statute compels publication. There is also a less-discussed explanation: in some cases the investigation never established the origin, and the statement reflects that lack of a conclusion.

How do you assess a supplier when its statement omits the vector?

Ask for it directly and in writing, and record the answer. If a supplier cannot or will not explain the entry point of its own incident, that refusal is part of the assessment result. From there the score has to rest on what the customer can observe first-hand: the access the third party holds into the customer's estate, the telemetry that access generates, and how long the supplier takes to answer a technical question.

What can realistically be demanded of a supplier by contract?

It is reasonable to agree that the supplier will tell affected customers the attack vector, the timeline and the scope within a defined window, alongside a right to dated documentary evidence of the state of its controls. Timing matters as much as wording: these clauses are far easier to agree at signing or at renewal than in the middle of an incident, when the customer's negotiating position is at its weakest.

How large is supply chain risk within these figures?

It is the main multiplier. In the first half of 2026, 38 initial supplier breaches generated 280.6 million victim notices and reached 206 entities: more than five organisations dragged in per initial intrusion. That is why third-party control has stopped being a documentation exercise: the impact lands on organisations that never ran the compromised system and cannot audit it.

Want to know what's actually exposed, and what to fix first?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours