229 Exposed Records Per Person: What 2026's Identity Theft Numbers Say About Data Brokers

If your information has ever appeared in a data breach, the dark web doesn't hold one record about you. It holds, on average, 229. That's what SpyCloud's identity exposure research found when it linked recaptured darknet data to actual people: the average exposed identity carries 229 separate exposure records, including 52 usernames and 141 username-and-password pairs, and often far more sensitive material — home addresses, Social Security numbers, even passport numbers. Not 229 mentions of your name — 229 separate, discoverable records. That's the number sitting underneath this year's identity theft statistics for 2026, and it's not a one-time breach tally. It's a running total that keeps climbing, and the reason it keeps climbing has less to do with any single hack than with what happens to your data after the hack.

What the ITRC actually measured

On June 9, 2026, the Identity Theft Resource Center published its "2026 Trends in Identity Report," built from 9,253 identity crime cases reported by 6,188 people who contacted the organization between April 1, 2025 and March 31, 2026.

The headline: "hacked devices" — jumped 78% year-over-year, going from 15.3% of all identity compromises to 27.2%. For the first time on record, device hacking has overtaken scams as the leading way working-age adults get victimized. Over that same stretch, scams that rely on convincing someone to hand over their own information voluntarily dropped from 43.1% of compromises to 36.1%. Attackers aren't giving up on tricking people, they're just finding it's often faster to just break into the device directly.

Why this shift changes what defense looks like

For years, identity theft prevention advice was built around one assumption: someone has to trick you. Don't click the link. Don't give your Social Security number over the phone. Hang up on the "grandkid in jail." That advice still matters, but it's now protecting against a shrinking share of the problem.

Device compromise doesn't need you to make a mistake in the moment. It exploits a stale password reused across accounts, malware sitting quietly on a phone, a login credential purchased on a criminal marketplace. The ITRC's numbers line up with a broader trend: threat-intelligence firm Recorded Future documented a 160% surge in credential theft in 2025 alone, with roughly 1.8 billion logins stolen from 5.8 million infected devices. That's not 1.8 billion people getting fooled by a phone call. That's 1.8 billion credentials sitting on infected machines, harvested automatically, and sold in bulk. The defense for that is unique passwords, multi-factor authentication, and keeping fewer accounts and fewer exposed data points in the first place.

Victims are now fighting on more than one front

The ITRC's report also flags something it calls identity crime becoming "multi-layered." In the twelve months covered by the report, 25.6% of victims dealt with two or more concurrent identity incidents at the same time — up from 23.5% the year before. That's the same underlying exposure getting used more than once: a stolen credential opens one account, which surfaces enough personal data to open a second fraud attempt somewhere else, sometimes before the first one is even resolved.

This tracks with what fraud researchers are seeing on the attack side. Sumsub, a fraud-detection firm, documented a 180% year-over-year increase in sophisticated multi-step fraud — attacks that stack deepfakes, synthetic identities, and social engineering together rather than relying on one technique jumped from 10% of all identity fraud in 2024 to 28% in 2025. A single piece of leaked data doesn't just cause a single incident anymore.

The figures behind the trend

Put the ITRC's compromise-method data next to the most recent full-year financial numbers and the shape of the problem gets clearer. Javelin Strategy & Research puts direct identity fraud losses at roughly $27.3 billion for 2025, while the FTC's Consumer Sentinel Network logged more than 1.1 million identity theft reports in its latest annual count.

Widen the lens to include the scams riding on that stolen data and Javelin's estimate, from research sponsored by AARP, climbs to roughly $47 billion in total consumer cost. Account-takeover fraud accounts for more than $15 billion of that by itself, which lines up directly with the ITRC's finding that device access, not persuasion, is now the primary entry point.

Zoom out further and the scale gets almost hard to hold onto: SpyCloud's researchers have recaptured more than 53 billion distinct identity records circulating across breach dumps, stealer logs, and resale marketplaces. The 229 figure this post opened with isn't that number divided across the population — it's what SpyCloud finds when it links those records to actual people, one exposed identity at a time.

Why data brokers keep that number climbing

Here's the part that most identity theft coverage leaves out: 229 records per person doesn't come from 229 separate breaches happening to any one individual. It comes from the fact that data that leaks once doesn't stay in one place. Data brokers exist specifically to buy, aggregate, and resell personal information, then repackage it under dozens of different site names, each running its own database, each with its own security posture, each a fresh target.

A single leaked email-and-address pair doesn't just sit in the original breach dump. It gets scraped by one broker, licensed to another, bundled into a "people search" profile on a third, and resold as a background-check result on a fourth. None of those four companies caused the original breach. All four are now holding a copy of your data, and all four are now a place where it can leak again. That's the multiplier: it isn't only new hacks that push the exposure count up. It's the resale layer turning one exposure into a dozen future ones.

What actually brings that number down

You can't undo a breach that already happened. But the number of active places currently holding your data is not fixed — it's a moving target that either shrinks or grows depending on whether anyone is managing it. Every broker listing removed is one less database that can leak your information again, one less source feeding the next scraper, one less entry in that 53-billion-record pool.

The problem is that broker sites relist people routinely, often within months of a successful removal, because the underlying data gets re-licensed from the same upstream sources over and over. A one-time opt-out doesn't hold. It only works as an ongoing process — someone checking broker sites on a recurring basis and resubmitting removals as they reappear.

Delist My Data is still in pre-launch. We're building the removal process now and taking waitlist signups ahead of launch. If the number of places holding your data sounds like something worth getting under control before it grows any further, join the waitlist for founding-member access.

Sources

Get founding-member access when we open the doors.

No spam. One email when Delist My Data opens for your area.