Of all the identity theft statistics 2026 has produced, the one worth remembering is 229: the number of separate exposure records SpyCloud found circulating on criminal markets for the average breached consumer. The figure comes from SpyCloud's 2025 Annual Identity Exposure Report, published in March 2025 and built on data recaptured during 2024, and it's still the most recent per-person count the company has released. Those 229 records include 52 unique usernames, 27 unique email addresses and 227 username-and-password pairs. Nearly three quarters (74%) of consumer records carried a physical or IP address, and the report lists Social Security or national ID numbers, addresses, and credit card or bank information among the data it routinely recovers.
Nobody gets breached 229 times. A single leak gets copied, sold, merged with other leaks and resold, and the copies pile up in places that never appear in a breach headline. This page collects the current identity theft statistics from the FTC, the FBI, Javelin, the Identity Theft Resource Center, SpyCloud and Pew Research Center, all from 2025 or 2026 editions unless marked otherwise, and then covers the part the other statistics roundups skip: what data brokers add to your exposure, and what we see when we file removals ourselves.
Identity theft statistics 2026: the key numbers
Every figure below carries the year its data covers, which is often a year earlier than the report's publication date. Most pages ranking for this query recycle 2023 or 2024 data under a new headline; these are the latest editions available as of September 2026.
- 229 exposure records per breached consumer, including 227 credential pairs. SpyCloud, 2025 Annual Identity Exposure Report, 2024 data.
- 65.7 billion distinct identity records recaptured from breaches, malware logs and combolists, up 23% in a year. SpyCloud, 2026 Annual Identity Exposure Report, 2025 data.
- About 1.4 million identity theft reports filed with the FTC in 2025, against more than 1.1 million in 2024. FTC Consumer Sentinel Network identity theft dashboard, data as of June 30, 2026; the FTC hasn't published a 2025 data book.
- $27.3 billion lost to traditional identity fraud in 2025, affecting 18 million US adults; $38 billion once scams are added, down $9 billion from 2024. Javelin, 2026 Identity Fraud Study, April 2026.
- Hacked devices went from 15.3% to 27.2% of identity compromises, a 78% jump, and overtook scams for adults aged 35 to 64. ITRC, 2026 Trends in Identity Report, covering April 2025 to March 2026.
- 25.6% of victims were dealing with two or more identity incidents at the same time, up from 23.5%. Same ITRC report.
- 3,322 data compromises in 2025, a record, and another 1,803 in the first half of 2026 alone, which generated 471.2 million victim notices in six months, more than the whole of 2025 produced; one education-platform breach accounted for roughly 275 million of those on its own. ITRC, 2025 Annual Data Breach Report and H1 2026 Data Breach Report.
- $20.9 billion in losses across 1,008,597 complaints to the FBI's IC3 in 2025, the first year over a million complaints. FBI, 2025 Internet Crime Report.
- 81% of Americans are concerned about how companies use the data collected about them, and 73% feel they have little or no control over it. Pew Research Center, How Americans View Data Privacy, May 2023 survey data.
- Sophisticated, multi-step identity fraud grew from 10% to 28% of the fraud Sumsub detected, a 180% rise in share, even as the overall fraud rate on its platform fell. Sumsub, Identity Fraud Report 2025–2026, November 2025.
- $20.9 billion, by coincidence the same figure as the FBI's total, is what congressional staff estimated four data broker breaches have cost consumers. Joint Economic Committee minority staff, Opt-Out Obstacles, February 2026.
How common is identity theft in 2026?
The FTC's Consumer Sentinel Network is the closest thing the US has to a national tally, and it counts reports filed, which understates the number of victims. Its public identity theft dashboard, refreshed July 28, 2026 with data through June 30, shows about 1.4 million identity theft reports for 2025. The 2024 Consumer Sentinel Data Book, released March 2025, counted more than 1.1 million identity theft reports for 2024 out of 6.5 million reports of all kinds. The FTC hasn't published a 2025 data book, so the 2025 count comes from the dashboard rather than a finished report, and late-arriving reports can still nudge it.
Fraud losses reported to the FTC, a broader category that takes in imposter scams, investment scams and the rest, reached about $16 billion in 2025. The FTC's June 2026 release calls that the highest on record and about 25% above the $12.5 billion reported for 2024. Imposter scams alone accounted for $3.5 billion.
The FBI's numbers run higher because they cover internet crime of every kind. The 2025 Internet Crime Report from IC3 logged 1,008,597 complaints, the first year past a million, with $20.9 billion in reported losses, up 26% from $16.6 billion in 2024. Of those complaints, 67,456 were filed specifically as personal data breaches and 31,675 as identity theft.
Survey-based counts run higher still. Javelin's 2026 study, drawn from more than 115,000 consumers, estimates 18 million US adults were victims of traditional identity fraud in 2025, and 36 million once scam victims are included. Reports to the FTC and FBI capture only the people who filed, which is why the two sets of numbers differ by an order of magnitude.
Identity fraud losses 2025: what identity theft costs
Javelin Strategy & Research's 2026 Identity Fraud Study, titled "The Illusion of Progress" and published April 21, 2026 with sponsorship from TransUnion, Fiserv, Plaid and Mastercard, puts traditional identity fraud losses at $27.3 billion for 2025. That's essentially flat against $27.2 billion in 2024. Combined losses from identity fraud and scams came to $38 billion, down $9 billion from the $47 billion Javelin reported for 2024 in its AARP-cosponsored 2025 study. The drop sits entirely on the scam side, where losses fell 45%, from $19.5 billion to $10.7 billion.
The underlying fraud types moved in opposite directions. Account takeover, where a criminal gets into an existing account of yours, cost more than $15 billion, down 4%, but the victim count rose 18% to 6 million. New-account fraud, where someone opens credit in your name, grew to $7 billion (up 13%) across 5.4 million victims (up 31%). Losses per victim fell while the number of victims rose, which is what you'd expect from automated fraud run against bulk data.
For the people on the receiving end, the losses are unevenly spread. The ITRC's 2025 Consumer Impact Report, published October 28, 2025, found 36.9% of the general-population victims it surveyed lost more than $10,000. The FBI's 2025 report attributes $7.7 billion of its losses to complainants aged 60 and over, from 201,266 complaints; identity theft complaints from that age group came to 5,359, up from 4,064 in 2024.
What changed year over year
The table pairs each metric with its previous reading from the same source. Periods differ by source, so each row stands on its own.
| Metric | Previous | Latest | Source |
|---|---|---|---|
| Hacked devices as a share of identity compromises | 15.3% (prior 12 months) | 27.2% (Apr 2025–Mar 2026) | ITRC 2026 Trends in Identity |
| Scams (victim shares own data) as a share of compromises | 43.1% | 36.1% | ITRC 2026 Trends in Identity |
| Victims managing two or more concurrent incidents | 23.5% | 25.6% | ITRC 2026 Trends in Identity |
| Sophisticated multi-step fraud, share of detected identity fraud | 10% (2024) | 28% (2025) | Sumsub 2025–2026 |
| Traditional identity fraud losses | $27.2B (2024) | $27.3B (2025) | Javelin 2026 |
| Identity fraud plus scams, combined | $47B (2024) | $38B (2025) | Javelin 2025 / 2026 |
| Distinct identity records recaptured | 53.3B (2024 data) | 65.7B (2025 data) | SpyCloud 2025 / 2026 |
| Identity theft reports to the FTC | 1.1M+ (2024) | ~1.4M (2025) | FTC Consumer Sentinel dashboard |
| Fraud losses reported to the FTC | $12.5B (2024) | ~$16B (2025) | FTC, June 2026 |
| Internet crime losses reported to the FBI | $16.6B (2024) | $20.9B (2025) | FBI IC3 2025 |
The first row is the one to watch. The loss figures moved by a few percent each; the share of compromises that came through a hacked device grew by 78%.
How identity theft happens in 2026: hacked devices overtook scams
On June 9, 2026, the Identity Theft Resource Center published its 2026 Trends in Identity Report, built from 9,253 identity crime cases reported by 6,188 people who contacted its helpline between April 1, 2025 and March 31, 2026. Unauthorized device access ("hacked devices" in the report's shorthand) rose from 15.3% of compromises to 27.2%, a 78% increase. Scams in which the victim was talked into sharing their own information fell from 43.1% to 36.1%. For adults aged 35 to 64, device access passed scams as the leading route to compromise for the first time. The ITRC is careful to say its cases come from people who chose to contact it and aren't a random sample; the direction of the shift is what matters here.
That shift changes what defending yourself looks like. Most identity theft advice assumes someone has to fool you first: don't click the link, don't read your Social Security number out to a caller. A hacked device skips the conversation. Malware on a phone, a password reused from a 2019 breach, a session cookie lifted by an infostealer; none of those need you to make a mistake on the day it happens. Our guide on what to do if you've been hacked covers the recovery order once it has.
Where the stolen logins come from
The raw material for device-based identity theft is stolen credentials, and 2025 produced them at a record pace. Check Point's External Risk Management unit (formerly Cyberint) reported a 160% increase in compromised credentials in 2025 to date compared with 2024, in an August 2025 analysis. Flashpoint's Global Threat Intelligence Index, 2025 Midyear Edition counted more than 1.8 billion credentials stolen in the first six months of 2025 alone, which Flashpoint described as an 800% increase. Its 2026 midyear report counted another 1.7 billion credentials harvested from 7.4 million compromised systems in the first half of 2026. Recorded Future's 2025 identity threat report, Inside the Infostealer Economy, tallied 1.95 billion credential exposures from malware combo lists and 892 million from malware logs during 2025, with the average compromised device yielding 87 stolen credentials.
SpyCloud's 2026 report tells the same story from its own dataset: 13.2 million infostealer infections exposing 642.4 million credentials during 2025, roughly 49 per infected machine, plus 8.6 billion stolen cookies. The company also found that 65% of consumers still reuse passwords across accounts, which is what turns one infected laptop into access to a dozen services.
How many records are exposed on the dark web per person?
The answer, from SpyCloud's 2025 Annual Identity Exposure Report built on 2024 data, is 229 for the average consumer identity it could link to a real person: 52 unique usernames, 27 unique email addresses and 227 credential pairs, with 74% of consumer records carrying a physical or IP address. SpyCloud didn't publish an updated per-consumer count in its 2026 edition, so 229 remains the reference point until it does.
The total pool keeps growing. The 2025 report counted 53.3 billion distinct identity records, up 22% from 43.7 billion. The 2026 report counted 65.7 billion, up another 23%, of which 5.3 billion are username-and-password pairs. Expect the per-person number to be higher whenever SpyCloud next publishes it, since the total has grown by nearly a quarter in a year.
A caution on what these counts measure. A "record" is a recaptured artifact, and one person accounts for hundreds of them; the same email address in a 2019 dump and a 2025 infostealer log is two records. SpyCloud strips exact duplicates, but each surviving record is still a separate copy in a separate place a criminal can buy.
Data breach statistics 2026: how many breaches hit the average person?
The ITRC's 2025 Annual Data Breach Report, published January 29, 2026, gives the closest thing to a direct answer. In its survey of 1,040 consumers, 80% had received at least one breach notice in the previous 12 months, and nearly 40% had received three to five. The report counted 3,322 compromises in 2025, a record, 5% more than 2024 and 79% more than five years earlier. Victim notices fell 79% to 278.8 million, because 2024 had been inflated by a handful of mega-breaches. Seventy percent of 2025's notices gave no details of how the attack happened.
The first half of 2026 ended the lull. The ITRC's H1 2026 Data Breach Report, published July 22, 2026, logged 1,803 compromises and an estimated 471.2 million victim notices in six months, against a restated 297.5 million for all of 2025. A single incident at Instructure, maker of the Canvas education platform, accounted for roughly 275 million notices, 58% of the half-year total. Malicious insider events jumped to 21 from three in all of 2025, and the ITRC projects around 3,600 compromises for the full year.
So the average adult with an email address has been through several breaches and received notices for a few of them, and the 229-record figure is what that history looks like from the criminal side. Our guide to how data breaches happen explains the main causes and what to do when a notice arrives.
How Americans feel about online privacy and data collection
The numbers above describe what happens to people's data. Pew Research Center's surveys describe how people feel about it, and the two line up. Pew's report How Americans View Data Privacy, published October 18, 2023 from a survey of 5,101 US adults conducted May 15 to 21, 2023, found:
- 81% of Americans are very or somewhat concerned about how companies use the data they collect about them; 71% say the same about the government, up from 64% in 2019.
- 73% feel they have little or no control over what companies do with their data, and 79% say that about the government.
- 67% say they understand little to nothing about what companies do with their personal data, up from 59% in 2019. Most people never find out: 56% say they frequently click "agree" on a privacy policy without reading it, and 61% think privacy policies are ineffective at explaining how companies use data anyway.
- 72% want more government regulation of what companies can do with people's data; 7% want less.
Pew's earlier report, Americans and Privacy: Concerned, Confused and Feeling Lack of Control Over Their Personal Information, based on a June 3 to 17, 2019 survey of 4,272 adults, is the baseline those comparisons point back to. In it, 81% said the risks of company data collection outweigh the benefits, 79% were concerned about how companies use their data, and 72% felt that all, almost all or most of what they do online or on their phone is being tracked by advertisers, technology firms or other companies.
Both surveys describe a gap between how much people worry and how little they feel they can do about it. The people-search sites that republish home addresses and relatives' names are the most visible form of the data collection Pew's respondents say they can't control, and they're also the one form an individual can push back on. If you're wondering how your details ended up on them, our guide on where data brokers get your information traces the supply chain.
Data broker exposure stats: what Congress counted, and what we see
Data brokers rarely appear in identity theft roundups, though Congress has now put a number on them. In February 2026 the minority staff of the Joint Economic Committee published Opt-Out Obstacles, which estimates $20.9 billion in consumer losses from four data broker breaches: Equifax in 2017 (147 million people), Exactis in 2018 (230 million), National Public Data in 2023 (about 270 million, which the report describes as nearly eight in ten Americans) and TransUnion in 2025 (4.4 million). The method is deliberately conservative. It starts from a 2016 Javelin finding that 31.7% of people notified of a breach experienced fraud the same year, imposes a 10% drop in that share for each year after the breach, then multiplies by the Bureau of Justice Statistics' 58% to 69% share of identity theft victims who suffer a financial loss and its $200 median loss. The report also quotes the FTC's description of broker opt-out options as "largely invisible and incomplete" and documents brokers hiding their opt-out pages from search engine results.
Those are the breach-side numbers. The exposure that never shows up in a breach count is the ordinary, lawful republishing that people-search sites do every day, and a few things we've learned while building removal coverage for them fill in the picture:
- Brand names overstate the number of holders. In our broker catalog, a large share of the differently branded "people search" storefronts turn out to be white-label fronts. Submit a search and the site hands you off to one of a handful of real data holders (InfoTracer, TruthFinder, Intelius, BeenVerified, Spokeo, Instant Checkmate). A long run of near-identical county-arrests-style sites all route to InfoTracer, and several of them serve the same search form byte for byte. One record at a holder appears under many names, and one storefront leaking is the holder's copy leaking. California's data broker registry shows the same thing from the corporate side: one Mississippi company operates FastBackgroundCheck, CyberBackgroundChecks, FastPeopleSearch and USPhonebook.
- The free preview is already a profile. When we screenshot broker result pages for our opt-out guides, searching a placeholder name like John Smith, the preview shown before any paywall lists age, a partial address history and relatives by full name. Fuzzy matching also surfaces entirely different people with similar names, so a profile can be wrong about you and still expose your family. That preview is also the raw material for doxxing, which needs no breach at all.
- The sites cross-sell each other. Submitting a search on USPhoneBook landed us on ThatsThem's homepage, and a search on ThatsThem dropped into a Spokeo funnel. The traffic moves between those sites in a single click, and every hop is another company with a commercial reason to hold a copy of the record you searched for.
Broker exposure works as a multiplier on everything else in this article. A breach puts your data on the criminal market once. Brokers put a lawful, searchable version of your biography (address, age, relatives, phone) next to it, and that biography is what a scammer uses to answer a bank's security questions once a breach has supplied the password.
Repeat victims and the re-listing problem
Identity theft repeats. In the ITRC's 2026 Trends data, 25.6% of victims were managing two or more identity incidents at the same time, up from 23.5% the year before, and the ITRC's 2025 Consumer Impact Report found 31.5% of general-population victims had been hit twice in the past year and 24.6% three times. Sumsub's Identity Fraud Report 2025–2026 documents the attacker-side version: "sophisticated" fraud, Sumsub's term for multi-step attacks, grew 180% year over year, from 10% to 28% of the identity fraud it detected, with synthetic identities, social engineering and deepfakes among the most common schemes. The overall fraud rate on Sumsub's platform fell from 2.6% to 2.2%; what grew is the share of detected fraud that is multi-step.
The same pattern shows up on the removal side, and it's one of the reasons we screenshot every listing before and after we file. A successful takedown looks identical, afterwards, to a listing that was never there, so without the before shot there's no proof anything happened. Removed listings come back often enough that we plan for it as the normal case. Several sites we cover share a single backend (BeenVerified, PeopleLooker, NeighborWho, Ownerly, ReversePhone and NumberGuru run on one), so a removal at any of them is really a request to the holder, and the holder re-ingests fresh data on its own schedule. The re-listing entry in our glossary explains why a one-time opt-out doesn't hold.
What actually shrinks your exposure
You can't fix any of the numbers above at the source. Instructure's servers and the 7.4 million compromised systems Flashpoint counted are out of your hands. What you control is how much of that 229-record profile still works when someone tries to use it.
- Unique passwords and multi-factor authentication on everything. SpyCloud's 65% consumer reuse rate is the reason 227 credential pairs per person matters; with unique passwords, a leaked pair unlocks one account and only that one. Prefer app-based codes over SMS where you have the choice.
- Freeze your credit at all three bureaus. It's free, and it blocks the new-account fraud that Javelin says grew 31% by victim count in 2025. Thaw it for the afternoon when you apply for something.
- Cut the number of accounts holding your data. Dormant accounts get breached too, and nobody is watching them. Close what you don't use.
- Treat every breach notice as a to-do. The ITRC found 70% of notices in 2025 said nothing about how the breach happened, so assume the worst category of data leaked and act on that assumption.
- Remove the public half of your profile from broker sites, and keep removing it. This is the slow part. Opt-outs are free but vary a lot in friction: PeopleConnect-family sites (TruthFinder, Instant Checkmate, Intelius) require phone verification before they'll process anything, and several forms sit behind Cloudflare interstitials you have to clear before the form even loads. Expect an evening for the first pass and a recheck every few months after that, because the holders keep re-ingesting. Our step-by-step removal guide walks the major sites in a sensible order, and the individual opt-out guides cover each site's form.
Frequently asked questions
How many people were victims of identity theft in 2025? Javelin's survey-based estimate is 18 million US adults for traditional identity fraud and 36 million once scams are included. The FTC logged about 1.4 million identity theft reports, and the FBI's IC3 just over a million internet crime complaints of all kinds. The gap is reporting; most victims never file.
How much money is lost to identity theft each year? $27.3 billion in traditional identity fraud losses in 2025 per Javelin, or $38 billion with scams added. The FTC's $16 billion covers fraud reported to it and the FBI's $20.9 billion covers all internet crime, so the figures measure different things and shouldn't be added together.
How many records does the average person have exposed on the dark web? 229, per SpyCloud's 2025 report (2024 data), for consumers whose identity it could link to recaptured records. That includes 227 username-and-password pairs and 27 email addresses.
Who is most at risk of identity theft in 2026? By method, adults aged 35 to 64 are now more likely to be compromised through a hacked device than a scam, per the ITRC. By dollar loss, people 60 and over reported $7.7 billion in losses to the FBI in 2025 across 201,266 complaints, and their identity theft complaints rose from 4,064 to 5,359 in a year.
Is identity theft getting worse? Depends on the measure. Dollar totals are flat (Javelin's $27.3 billion against $27.2 billion), FTC report counts are up, and device hacking is up 78% as a share of compromises. More people are being hit for less money each, through routes that don't require them to make a mistake.
Do Americans care about data privacy? Pew's May 2023 survey found 81% concerned about how companies use their data and 72% in favor of more regulation, while 73% feel they have little or no control over what companies do with their data.
Do data brokers cause identity theft? Indirectly. The JEC's $20.9 billion estimate covers breaches at brokers themselves; the larger everyday effect is that broker profiles supply the biography (address, relatives, age) that makes stolen credentials usable against you.
Where the numbers leave you
Breaches hit a record in 2025 and leaked credentials more than doubled by both year-over-year measures above, while losses held roughly flat because banks and platforms got better at catching fraud in flight. That defense holds until a criminal chains enough of your data to look like you, and it does nothing about the copies sitting on broker sites waiting for the next attempt. Filing removals, then rechecking every few months for re-listed profiles, is the one part of your exposure you can measurably shrink on your own.
Delist My Data files those broker opt-outs for you, then keeps checking the people-search sites and re-files whenever a profile reappears, so a removal holds instead of quietly lapsing. We're in pre-launch; join the waitlist for founding-member access ahead of launch.
Sources
- SpyCloud: 2025 Annual Identity Exposure Report (March 2025, 2024 data)
- SpyCloud: 2026 Annual Identity Exposure Report (March 2026, 2025 data)
- FTC: Consumer Sentinel Network identity theft reports dashboard (published July 28, 2026, data through June 30, 2026)
- FTC: New FTC Data Show a Big Jump in Reported Losses to Fraud to $12.5 Billion in 2024 (March 2025, 2024 data)
- FTC: FTC Data Show People Reported Losing $3.5 Billion to Imposter Scams in 2025 (June 2026, 2025 data)
- Javelin Strategy & Research: 2026 Identity Fraud Study, "The Illusion of Progress" (April 2026, 2025 data)
- AARP: Javelin 2025 Identity Fraud Study summary (March 2025, 2024 data)
- ITRC: 2026 Trends in Identity Report (June 2026, April 2025 to March 2026 data; PDF)
- ITRC: 2025 Annual Data Breach Report (January 2026, 2025 data)
- ITRC: H1 2026 Data Breach Report (July 2026, January to June 2026 data)
- ITRC: 2025 Consumer Impact Report (October 2025, August 2024 to July 2025 data)
- FBI IC3: 2025 Internet Crime Report (April 2026, 2025 data)
- Sumsub: Identity Fraud Report 2025–2026 (November 2025, 2025 data)
- Check Point External Risk Management: The Alarming Surge in Compromised Credentials in 2025 (August 2025, 2025 year-to-date data)
- Flashpoint: Global Threat Intelligence Index, 2025 Midyear Edition (July 2025, January to June 2025 data)
- Flashpoint: Global Threat Intelligence Report, Midyear 2026 (August 2026, January to June 2026 data)
- Recorded Future: Inside the Infostealer Economy, 2025 identity threat report (2025 data)
- Pew Research Center: How Americans View Data Privacy (October 2023, May 2023 survey; chapter 1)
- Pew Research Center: Americans and Privacy: Concerned, Confused and Feeling Lack of Control Over Their Personal Information (November 2019, June 2019 survey)
- Joint Economic Committee minority staff: Opt-Out Obstacles (February 2026)