HomeSecurityUS Q3: 23 million people affected by data breaches

US Q3: 23 million people affected by data breaches

Data breaches in the United States showed a slight decline in the third quarter of 2025, according to the Identity Theft Resource Center (ITRC) ’s latest Data Breach Analysis . However, the overall picture remains concerning: the US is still on track for a record year in cyber breaches.

data breaches

There were 835 separate data breaches in the third quarter , affecting an estimated 23 million people . While this number is down from the first half of the year—when there were 1,732 incidents and over 165.7 million victim notifications —the indicators still underscore the unprecedented scale of the threat to the personal data of American citizens.

In total, in the first three quarters of 2025, the ITRC has recorded 2,563 breaches, resulting in nearly 202 million victims. If this pace continues, the US is just 640 incidents away from an all-time high.

See also: Over 13,000 unique domains use Cloudflare for Clickfix attacks

Cyberattacks dominate – but “physical” breaches are also on the rise

The vast majority (83%) of incidents are due to cyberattacks, either through ransomware, phishing, or exploiting vulnerabilities.

This is followed by 46 incidents attributed to human or system errors, attacks supply chain and 19 physical attacks, i.e. cases where physical storage media was compromised or devices containing data were stolen.

It is noteworthy that "physical" attacks are showing an upward trend: the ITRC has recorded 53 incidents since the beginning of the year, compared to just 33 in all of 2024. This shows that attackers are not abandoning more traditional methods.

US Q3: 23 million people affected by data breaches
US Q3: 23 million people affected by data breaches

The sectors most affected

The financial sector proved to be the most vulnerable in the third quarter, with 188 breaches, followed by healthcare, professional services, manufacturing and education.

Among the most significant incidents recorded in the third quarter were:

  • Anne Arundel Dermatology, with over 9 million notifications sent to victims.
  • DaVita ahealthcare company, with 7 million victims.
  • Radiology Associates of Richmond, with 4 million alerts.
  • TransUnion oneof the largest credit reporting companies, with 4.4 million victims.
  • And Absolute Dental Group, with about 2 million victims.

The recurrence of incidents in critical sectors, such as health and finance, raises serious questions about organizations' preparedness and compliance with cybersecurity standards.

See also: Chinese 'Jewelbug' was on Russian IT provider's network for months

Data Breaches: Lack of Transparency in Notifications

One of the report's most disturbing findings is the increase in "silent" notifications — that is, notifications to victims that do not include details about how and why the breach occurred.

According to the ITRC, 68% of notifications in the first quarter did not provide such information, a percentage that rose to 71% in the third quarter.

US Q3: 23 million people affected by data breaches

This lack of transparency leaves consumers exposed to the risks of identity theft, as they do not know exactly what has been leaked and how to protect themselves.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: F5 – Data Breach: Hackers stole BIG-IP source code

Data Breaches: What This All Means for 2026

Although the third quarter appeared to offer a temporary dip, the overall trend shows that cybercriminals remain more active than ever. Experts estimate that 2026 will be a year of strategic shifts, with more supply chain and increased use of artificial intelligence for automated phishing attacks.

At the same time, pressure on businesses to adopt “zero trust” practices and enhanced anomaly detection systems will increase, especially in sectors that process sensitive personal or financial data.

The third-quarter slowdown, analysts say, is not a reason for complacency. Rather, it is a warning that cybersecurity must remain a strategic priority for any organization that handles customer data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS