Three in four breach notices issued in the United States during the first half of 2026 said nothing about how the attacker got in. Only 24 per cent disclosed the attack vector, the lowest share the Identity Theft Resource Center (ITRC) has recorded in twenty years of tracking, according to its half-year report. Press coverage went to a different number in the same report: 471.2 million victim notices in six months, more than the full-year total for 2025.
In aggregate, that omission is rarely accidental. Whether it reflects a considered decision or an investigation that never closed, more notices arrive without the detail every year. A European team assessing a supplier with US operations will sooner or later end up in that public record, and what made it worth opening is now usually missing.
What the numbers show
The ITRC report, published on 22 July 2026, counts 1,803 data exposure events between January and June. April to June alone produced 1,029, the second-highest quarterly figure in the organisation's series. At that pace the year would close near 3,600 events.
Victim notices reached 471.2 million. A single compromise at an education platform produced roughly 275 million of them, 58 per cent of the total. That concentration matters: when one incident carries more than half a six-month total, the average describes nobody.
Beneath the headline sit four signals that explain where it comes from:
- Suppliers as multipliers. 280.6 million notices came from just 38 initial breaches that reached 206 entities. That figure includes the education platform compromise rather than sitting alongside it. In a supply chain attack, the leverage lies in the shared provider more than in the attacker's technique.
- Staff turning on their employer. 21 cases of insider wrongdoing in six months, against 3 across the whole of 2025. The ITRC ties the jump to technology-sector redundancies and to recruitment schemes run by state actors, which makes insider threat as much a matter of economic climate as of access control.
- Concentration. Publicly traded companies accounted for 10.3 per cent of events and 83.4 per cent of all victim notices: a handful of large organisations produce the volume.
- Flaws with no patch. 14 events tied to zero-day vulnerabilities in six months, close to the 17 recorded across all of 2025.
These figures need a caveat. The half-year release compares 471.2 million with 297.5 million notices for all of 2025, while the annual report the same organisation published in January put 2025 at 278,827,933 notices. The series gets revised between publications. When the baseline moves by 7 per cent between two documents from the same body, what you have are orders of magnitude, and they should not be quoted to the decimal.
The series that matters is not the breach count
It is the omission count, measured in notices rather than in people. The ITRC annual report for 2025 records that 2,324 breach notices, 70 per cent of those issued that year, carried no attack information. In 2024 the figure was 2,049 (65 per cent); in 2023, 1,449 (45 per cent). The first half of 2026 pushes the share to 76 per cent.
Thirty points in three years is a change of practice across a whole market, not statistical noise. The same source sets the starting point: in 2020, the ITRC records, nearly every breached organisation gave clear detail on how it happened.
Why did organisations stop explaining how attackers got in?
Because almost nothing requires them to. Neither the federal healthcare rule nor most state notification statutes ask for a description of the entry point; they ask what happened, which categories of data were involved and what the recipient should do next. Disclosing the attack vector is optional, as Paubox's analysis of the finding sets out.
From there the calculation writes itself. Confirming that access arrived through a credential with no second factor, an unpatched server or a compromised subcontractor feeds a class action, invites a regulatory inquiry and puts up the price of the next insurance renewal. Legal teams know it and so do insurers. None of this requires bad faith from any particular company: it is the predictable response of any organisation inside a framework that makes candour expensive and reticence free.
ITRC president James E. Lee is blunter than his own report. He describes an unprecedented transparency crisis and argues that the state laws written to inform and protect people, in his words, simply do not work. In January he asked organisations to put transparency ahead of liability management. Six months on, the aggregate has moved the other way.
Two things break once the vector disappears
Supplier assessment loses its raw material
Supplier assessment questionnaires ask about previous incidents. The standard reply, that the supplier had an incident in 2025, notified it as the law required and has since remediated it, is true and tells you nothing.
Without the vector there is no way to tell whether the supplier failed at identity management, at patching, or at controlling the access it grants its own subcontractors, and those are the failures most likely to recur. Any third-party risk management programme fed only by public sources is scoring suppliers with the most important field left blank.
Then comes the knock-on. One failure at a shared provider becomes a problem for the 206 entities the ITRC counts behind those 38 breaches: organisations that never ran the compromised system and cannot audit it either. This is the dynamic that already forced a rethink of supplier control after the public package repository intrusions and the abuse of authorised integrations over the past year, a dynamic revisited in five lessons from the digital supply chain.
Defensive prioritisation loses its cheapest shortcut
The second effect draws less attention. A team working out which techniques are landing against organisations like theirs could once read public notices for a free, sector-specific and reasonably current signal. Today three in four stop at the impact, and that signal has to be replaced by paid threat intelligence, by sector information-sharing arrangements, or by nothing.
In practice, prioritisation can no longer lean on other people's incident narratives; it has to run on observed exploitation. Models such as KEV, EPSS and SSVC carry more weight now because they do not depend on anyone telling their story.
Where the vector is still on the record
Some sources still describe the entry point, and it is worth being precise about what each is good for.
- Joint government advisories, which describe techniques and usually publish indicators. They arrive late and cover only what CISA, national CSIRTs or ENISA choose to release.
- Platform confirmations, where the provider whose service was used in the attack states publicly what happened. Useful, and rare.
- The CISA KEV catalogue, which rarely explains a specific incident but does confirm which flaws are being exploited.
- Sector information-sharing groups and national CSIRTs, which circulate to members material the trade press does not carry.
None of these replaces what a supplier knows about its own incident. They are good for steering attack surface management and threat hunting, not for scoring a third party.
Is Europe better off? The root cause is documented, and stops at the regulator
Reading this as an American problem would be convenient. It is not one, and it does not leave Europe in the clear.
European rules do require the root cause. Article 23 of NIS2 sets three clocks for significant incidents: an early warning within 24 hours, an incident notification within 72 hours and a final report within one month, and that final report must contain a detailed description of the incident together with the type of threat or root cause that likely triggered it. Financial services follow the same pattern: under DORA, entities file initial, intermediate and final reports, and the final one carries the root cause analysis and the corrective measures taken.
The same article also requires entities to inform the recipients of their services where a significant incident is likely to affect service provision. So the customer does hear about the incident. The analysis itself travels to the competent authority and the CSIRT, and stays there: whoever is assessing that supplier cannot read the final report filed with its national authority, and has no standing to demand it. Europe has built a root cause channel that ends at the supervisor.
ENISA concedes as much in the methodology of its Threat Landscape: open sources and voluntarily shared information do not add up to a complete picture of the threats, and some incidents, cyberespionage above all, are documented years after the fact. Europe's cybersecurity agency is acknowledging, in diplomatic terms, that its portrait of the problem is incomplete.
Controls that have expired, and what replaces them
What has expired is supplier assessment fed by public sources, and with it the assumption that a provider with no incidents in the press is a provider with no security problems. With 76 per cent of notices stopping at the impact, silence no longer separates one supplier from another.
What takes its place is less impressive-looking and considerably more laborious:
- The contract clause. Requiring the supplier to tell affected customers the attack vector and the timeline within an agreed window now counts for more than any questionnaire. A supplier who refuses that clause has handed you a finding.
- A right to evidence. Audit reports with their scope and non-conformities, dated penetration test results, patch management records. Documents that carry a date and a signature.
- Your own telemetry on everything the supplier operates. Where a third party holds federated access, service accounts or integrations into your estate, the supplier's problem shows up in your logs before it shows up in its statement.
- Response rehearsed in advance. Knowing which questions to ask, and of whom, in the first hours of a supplier incident is a crisis communications exercise, and those first hours are no time to write the script.
- Internal accountability. NIS2 places the duty on the management body, and that accountability for third-party risk cannot be delegated to a supplier spreadsheet.
At Hard2bit this now surfaces in board discussions, and rarely as a debate about tooling. It is a debate about what can be demanded contractually and what is being accepted out of habit.
How this could be turned round
Only two routes would turn this round: a jurisdiction making root cause a mandatory element of the notice, or large buyers demanding it contractually before any regulator arrives. As long as disclosing the vector stays voluntary in the market that produces most public notices, and continues to carry a legal cost, the data gives no reason to expect the share to recover.
Of the two, only the second is within a single organisation's control. One question stays open: nobody knows how much of this decline is deliberate withholding and how much is investigation that never happened. A notice that stops at the impact may be hiding the origin, or may reflect that no one ever established it. The ITRC data does not separate the two, and the distinction matters. A market that does not investigate its own incidents has a worse problem than one that investigates and keeps the answer to itself.
This article analyses data published by third parties, with the information available on 21 August 2026. The ITRC figures are estimates drawn from public notifications in the United States, and the organisation's own historical series has been revised between publications, so they should be read as orders of magnitude. Nothing here is legal advice: the specific notification duties and the content required in each report depend on the framework applicable to each entity and should be confirmed with legal counsel and the relevant competent authority.