Cyberattacks Show No Signs of Slowing Down

Illustration of a cybercriminal using phishing, smishing, and vishing tactics to steal personal information

By Mark Pribish | Founder at IDentity Theft Brokers, LLC.

In the last five months, the three leading identity theft, data breach, and cybercrime research reports (ITRC, IBM, and FBI) have indicated that cybercrime is growing in both frequency and sophistication with no signs of slowing down.

The rising attack volumes against both businesses and consumers are breathtaking as evidenced by the following three research reports:

The first report is the July 22, 2026, Identity Theft Resource Center (ITRC) Data Breach Report for the first half of 2026 which found that 471 million victim notices were issued in the first six months of this year, far surpassing the 297 million victim notices sent in all of 2025. The ITRC also reported a sevenfold increase in “insider wrongdoing incidents” in the first half of 2026 compared to 2025.

The second report is IBM’s 2026 Cost of a Data Breach report—released on July 29, 2026 – where the average cost of a data breach has risen 12% to $4.99 million, with US companies paying more than twice the global average, at $11.5 million. The IBM report said that companies lacking both proper cybersecurity hygiene and an AI-enabled security strategy suffered the most, in terms of cost and reputation.

The third and final report is the FBI’s 2025 Internet Crime Report—released on April 6, 2026—which highlighted how cybercrimes defrauded Americans of nearly $21 billion with an average loss of $20,699 in 2025. In addition, cyber-enabled fraud accounted for nearly 85% of all reported losses, including business email compromise and phishing schemes.

Based on the above, who are the bad cyber actors and what can we do about it?

They are individuals or organizations who attack computer, cyber and/or information systems with malicious intent for financial gain and political/corporate disruption. These bad cyber actors include individual cybercriminals, organized crime, state-sponsored hackers, cyberterrorists, hacktivists, and the insider threat (including current and former employees, contractors, and vendors).

All of the above are very good at exploiting human vulnerabilities by using phishing (fraudulent emails), smishing (fraudulent texts), vishing (fraudulent phone calls and voicemails), and social media.

These bad cyber actors depend on human nature, human trust, and human weakness and they continue to intentionally engage in harmful, illegal, and/or unethical behavior.

The current information security and governance climate shows that many businesses still detect and neutralize threats every day and continue to make cybersecurity investments.

However, the balance is shifting as attackers close the capability gap, and businesses along with consumers face more complex, persistent cyber threats.

The fact is that new and evolving attack vectors are happening every day where cybercriminals are stealing Personally Identifiable Information (PII) such as your name, email address, phone number, social security number, drivers license, and financial information to use against individual consumers to create personalized scams. And in some cybersecurity circles, cyber experts say that your cell phone number is more important to cybercriminals than your Social Security number.

Example scams that are happening every day include:

As mentioned in the above referenced FBI 2025 Internet Crime Report, these scams generate thousands of dollars for cybercriminals. In addition, these same scams can impact your financial health, reputation, mental health, and physical health.

Social engineering – where human psychology is used to convince consumers to give away personal information such as your Social Security number or credit card details – is a very effective scam tactic used by cybercriminals. For example, a scammer might impersonate your bank and say your account is at risk, using fear to get information they can use to steal your identity.

Social engineering scams are particularly dangerous in the evolution of AI, where cybercriminals can impersonate someone’s voice or writing style.

But it’s not just consumers; businesses – especially small businesses – are often targeted by cybercriminals with similar social engineering tactics to gain access to an employee’s account or identify vulnerabilities in an organization’s security.

To conclude, while cyberattacks show no signs of slowing down, both businesses and consumers need to focus on defending, detecting, and responding to cyber threats.

The key is for businesses and consumers to be proactive by using new and emerging technology that helps identify fraud and scams in real time, rather than just reacting to cyber-attacks.

Share this post :