Every few months a new headline tells us that data breaches have hit a record. It's easy to tune out but the numbers from the Q3 of 2026 are worth a closer look, because they don't describe one dramatic hack. They describe a system that has quietly become the normal state of the internet.
Let's start with what can actually be verified.
Ransomware hit a 2026 high in August. Breachsense counted 964 organizations posted to ransomware leak sites in August 2026, up 19% from July's 811 and the highest monthly total of the year. That's 58% above the 2025 monthly average of 609 victims. Eighty-three separate ransomware groups were active across 78 countries - also the most of any month this year. Eight months in, 2026 is running roughly 25% ahead of 2025's pace.
Check Point's tracking, which uses a different methodology, points the same way: 1,042 ransomware attacks in August, up 8% month-over-month and nearly double the figure from August 2025.

Attacks in general keep climbing. Check Point recorded an average of 2,422 cyberattacks per organization per week in August, up 22% year-over-year and climbing steadily since May, when the figure was 2,055. Europe saw the sharpest increase of any region at +28%. Education (5,354 weekly attacks per organization), government, and hospitality were the most targeted sectors.
The first half of 2026 was already historic. The Identity Theft Resource Center logged 1,803 data compromises in H1 2026, with roughly 471 million victim notices issued. The second quarter alone - 1,029 incidents - was the second-largest quarter in ITRC's history. At this pace, 2026 will end with around 3,600 compromises, surpassing 2025's record of 3,321.
Numbers are abstract. Names are not. A few of the incidents disclosed in July and August:
And September has opened with the largest claim of the year: a threat actor is offering what is allegedly a full database of 820 million Alipay users for sale. The claim is unverified and Alipay has not confirmed it but Bitsight's dark-web tracking, which is where claims like this first surface, has logged roughly 9,000 breach posts in the past twelve months, about one every hour.
Notice a pattern. None of these are obscure companies with sloppy IT. They are a top-tier pharma distributor, a Fortune 500 cloud tenant, a national tax agency. If your data lives anywhere, and it does, it lives with organizations like these.
1. The number you see first is almost never the real number. CareCloud went from 345,000 to 3.75 million. This isn't unusual - the ITRC notes that attack-vector details are now disclosed in only 24% of breach notices, the lowest rate it has ever recorded. Companies disclose the minimum, then revise. By the time you learn the true scope of a breach, your data may have been circulating for half a year.
2. Supply chains multiply the damage. In H1 2026, just 38 supply-chain breaches generated 280 million victim notices - nearly 60% of the half-year total. You didn't sign up with the vendor that got hacked. You signed up with a company that used that vendor. You had no say, and probably no idea.
3. AI is on both sides now. Check Point's August report highlights a new category of leak entirely: employees pasting sensitive data into generative AI tools. One in every 43 prompts now carries high-risk data, and 86% of organizations saw such activity in August. On the attacker side, ITRC points to a rise in zero-day exploits driven partly by AI-assisted tooling. The tools that make work faster are also making leaks faster.
You can't stop McKesson from getting breached but you can decide how much damage a breach does to you. The goal is simple: make sure that when one account leaks, it's only one account.
Assume your email and phone number are already public. After 471 million victim notices in six months, they almost certainly are. Treat every unexpected message that references real details about you - an order number, your employer, your address as a potential phishing attempt built from leaked data. Phishing rates rose again in August to 1 in every 112 emails.
Use a different password for every account, managed by a password manager. This is the single highest-impact change most people haven't made. Credential stuffing, trying leaked passwords on other sites, is how one breach becomes ten.
Turn on two-factor authentication everywhere, preferably with an app or hardware key, not SMS. A leaked password without a second factor is a locked door with the key under the mat.
Check whether you've been exposed. Have I Been Pwned lets you search your email against known breaches for free. If you appear in a recent one, change that password today and anywhere else you reused it.
Reduce what there is to leak. Delete accounts you don't use. Decline to share data you don't need to share. Store sensitive documents somewhere only you hold the key - end-to-end encrypted, not just "password protected" on a server the provider can read. The less of you that exists in third-party databases, the less there is to steal.
Layer your defenses so you're harder to track in the first place. Breaches only expose what was collected, and a lot gets collected before you ever fill in a form. Your browser, device, fonts, and screen size combine into a fingerprint that identifies you across sites without a single cookie. One tool rarely fixes this - a VPN hides your IP but not your fingerprint, an ad blocker stops trackers but not your provider. Stacked together, they cut how much of you ends up in third-party databases at all. Explore 4 layers of privacy, integrated into one app with VPN Toolkit.
This is the objection we hear most often, and August 2026 is the answer to it. The 12.9 million Carhartt customers had nothing to hide either. They bought a jacket. Now their names, emails, and addresses are in a dataset that will be traded, cross-referenced, and used to make the next phishing email more convincing for years.
Privacy was never about hiding something. It's about not being exposed by default, at the mercy of whichever vendor gets hit next.
That's the argument our Co-founder and CTO Tim Goska makes in his book, Nothing to Hide - a practical case for why privacy matters to ordinary people, and what taking it back looks like in 2026.

If this article made you want to close a few doors, the book is where to start. Follow the link and find out whether you really have nothing to hide.