Identity Theft Statistics for 2026: Losses, Victims, and What Changed This Year
Identity theft is no longer a single event. In 2025, $27.3 billion was stolen from 18 million U.S. consumers through traditional identity fraud, according to the Javelin Strategy & Research 2026…
Table of Contents
Identity theft is no longer a single event. In 2025, $27.3 billion was stolen from 18 million U.S. consumers through traditional identity fraud, according to the Javelin Strategy & Research 2026 Identity Fraud Study. Add scams to that total and Americans lost $38 billion across 36 million victims. Consumers filed roughly 3 million fraud reports with the Federal Trade Commission in 2025, reporting $15.9 billion in losses, up from 2.6 million reports and $12 billion the year before. And the FBI's 2025 Internet Crime Report logged more than 1 million cybercrime complaints with $20.9 billion in reported losses. Every one of those headline numbers is a record.
This page collects the most current identity theft statistics available as of September 2026, sourced from the primary reports that journalists, security teams, and IT buyers actually rely on.
Key identity theft statistics at a glance
$27.3 billion was lost to identity fraud in 2025, affecting 18 million victims (Javelin, 2026).
$38 billion in combined identity fraud and scam losses hit 36 million Americans in 2025 (Javelin, 2026).
New account fraud victims rose 31% to 5.4 million, and account takeover victims rose 18% to 6 million (Javelin, 2026).
$15.9 billion in fraud losses were reported to the FTC in 2025 across 3 million reports (FTC, 2026).
Imposter scams were the top reported fraud for the ninth straight year, with more than 1 million reports and $3.5 billion lost (FTC, 2026).
$20.9 billion in losses and 1,008,597 complaints reached the FBI's IC3 in 2025; Americans over 60 alone lost $7.7 billion, up 59% (FBI, 2026).
471.2 million breach victim notices were issued in the first half of 2026, already surpassing all of 2025 (ITRC, 2026).
27.2% of identity compromises now begin with unauthorized access to a victim's device, up 78% year over year (ITRC, 2026).
Only 9% of identity theft victims who suffered any financial impact reported resolving their case (ITRC, 2026).
The global average cost of a data breach reached $4.99 million, a 12% jump and a record high (IBM, 2026).
48% of breaches now involve a third party, and 31% start with a software vulnerability (Verizon DBIR, 2026).
How common is identity theft in 2026?
The short answer: roughly one in seven American adults experienced some form of identity fraud or scam last year. Javelin's 2026 study, based on a survey of 5,010 U.S. adults conducted in late 2025, puts the number of traditional identity fraud victims at 18 million and scam victims at about 19 million, with overlap between the two groups bringing the combined total to 36 million.
The headline losses stabilized rather than fell. Identity fraud losses came in at $27.3 billion in 2025 versus $27.2 billion in 2024. Scam losses dropped sharply, down 45% to just under $11 billion, and the average scam loss per victim fell 33% from $868 to $579. Javelin titled its 2026 report "The Illusion of Progress" for a reason: the money moved from scams into structural identity fraud, where victim counts are climbing.
Account takeover losses topped $15 billion, down 4%, but victims rose 18% to 6 million.
New account fraud losses grew 13% to $7 billion, and victims grew 31% from 4.2 million to 5.4 million.
Victims spent an average of 10.4 hours resolving identity fraud in 2025, up from 9.5 hours in 2023. Account takeover cases took 17 hours; new account fraud cases took 17.8 hours.
Federal reporting data tells a consistent story. FTC Consumer Sentinel data presented to Congress in March 2026 shows fraud reports rose from 2.6 million in 2024 to 3 million in 2025, with reported losses climbing from $12 billion to $15.9 billion. A separate FTC data release in June 2026 rounds total 2025 fraud losses to $16 billion, the highest ever recorded and about 25% above 2024.
Identity theft losses by fraud type
Imposter scams remain the single largest category of consumer fraud, and they are increasingly the front door to identity theft. Nearly one in three fraud reports filed with the FTC in 2025 involved someone impersonating a business, government agency, or trusted contact. Consumers reported losing $3.5 billion to imposters, nearly three times the 2020 figure. Business impersonators accounted for about $1 billion of that, and government impersonators about $920 million, up from $789 million in 2024.
Investment scams caused the heaviest financial damage in both federal datasets. The FTC recorded $7.9 billion in investment fraud losses in 2025. The FBI's IC3 counted $8.6 billion in investment losses, followed by $3.0 billion for business email compromise and $2.1 billion for tech and customer support scams.
Cryptocurrency is now the dominant rail. IC3 tracked 181,565 crypto-related complaints in 2025 (up 21%) with $11.4 billion in losses (up 22%). Crypto investment scams alone drew 61,559 complaints and $7.2 billion in losses.
The narrow "identity theft" category that IC3 tracks separately looks small by comparison: 31,675 complaints and $185.8 million in losses. But the personal data breach category, which feeds identity theft downstream, drew 67,456 complaints and $1.3 billion in losses. Phishing and spoofing was the most reported crime type overall at 191,561 complaints.
Who is most affected by identity theft
Older Americans absorb a disproportionate share of the damage. IC3 received 201,266 complaints from people over 60 in 2025, a 37% increase, with losses of $7.7 billion, a 59% increase. The average loss for a victim over 60 was $38,500, and 12,444 older victims lost more than $100,000 each. Crypto-related losses for that age group reached $4.4 billion.
Children are targeted differently. The Identity Theft Resource Center's 2026 Trends in Identity Report, based on 9,253 cases from 6,188 people who contacted the ITRC between April 2025 and March 2026, found that fraudulent employment accounted for 40% of all misuse cases involving minors, making it the most common identity crime against children.
Working-age adults are seeing a different shift. For the first time, hacked devices overtook scams as the leading cause of identity compromise among working-age adults. Unauthorized device access rose from 15.3% to 27.2% of all identity compromises, a 78% increase, while scams involving shared personal information dropped from 43.1% to 36.1%.
Geography matters too. The ITRC found that 49% of Colorado residents who contacted the center reported multi-layered incidents, and Illinois residents reported fraudulent employment at nearly three times the national average.
What happens after identity theft: resolution and impact
Identity theft has become a layered crime. More than one in four ITRC contacts (25.6%) were dealing with two or more identity incidents at the same time, up from 23.5% the prior year.
Resolution is rare once money is involved. Among victims with no measurable financial impact, 53% reported resolving their case. Among victims with any financial impact, that figure drops to 9%. Among victims who experienced three or more financial impacts, zero reported resolution.
The human cost extends beyond money. Just under 10% of ITRC respondents (9.7%) reported suicidal ideation as a result of their identity crime.
When criminals attempt to misuse stolen identities, they mostly open new accounts. Of attempted misuse cases, 62.1% involved new account applications and 37.9% involved account takeovers. Credit cards were the target in 41% of attempts, followed by checking accounts (17.7%) and personal loans (8.5%). Attempted misuse caught by financial institutions rose 26.8%, one of the few positive signals in the data.
Consumer behavior compounds the problem. Javelin found that 55% of consumers who did not respond to a fraud alert believed the alert itself was a scam, and 30% of scam victims admitted to giving banking details to the scammer.
Data breaches: the supply side of identity theft
Every stolen identity starts with stolen data, and 2026 is on pace to be the worst year on record for breach exposure. The ITRC's H1 2026 Data Breach Report tracked 1,803 data compromises in the first six months of 2026, including 1,029 in the second quarter alone. Those events generated 471.2 million victim notices, already exceeding the 297.5 million notices issued during all of 2025. A single breach of the Instructure Canvas education platform accounted for 275 million notices, or 58% of the half-year total.
At the current pace, 2026 will finish near 3,600 compromises, ahead of the 3,321 recorded in 2025. Financial services was the most frequently breached sector (387 compromises), followed by healthcare (281). Manufacturing saw 74 million victim notices in six months, up from 1.97 million in all of 2025.
Two structural trends stand out for identity theft risk:
Supply chain attacks concentrate exposure. Thirty-eight supply chain events affected 206 organizations and produced 280.6 million victim notices in H1 2026.
Transparency is collapsing. Only 24% of breach notices in H1 2026 included details about the attack vector, the lowest rate the ITRC has ever recorded. Victims are being told their data was exposed without being told how.
Insider incidents are spiking. The ITRC logged 21 malicious insider events in the first half of 2026, compared with 3 in all of 2025.
The cost side is rising in parallel. IBM's 2026 Cost of a Data Breach Report puts the global average breach cost at $4.99 million, a 12% increase and a record high. AI-driven attacks, led by deepfake impersonations and AI-enabled malware, increased 56%. An AI model inversion attack now costs an average of $6 million. Organizations making extensive use of AI and automation in security saved an average of $1.93 million per breach compared with those using none.
How attackers get in
The Verizon 2026 Data Breach Investigations Report, which analyzed more than 22,000 confirmed breaches, documented a shift in initial access. Vulnerability exploitation now starts 31% of breaches, overtaking stolen credentials as the top entry point for the first time in the report's history. Credential abuse dropped to 13% as an initial access vector but still appears in 39% of breaches somewhere in the attack chain, typically for lateral movement and privilege escalation.
Other findings from the 2026 DBIR that matter for identity theft:
Ransomware was present in 48% of breaches, up from 44%, the highest figure in DBIR history. The median ransom paid fell to $139,875 from $150,000.
Breaches involving a third party jumped 60% to 48% of all breaches.
The human element was present in 62% of breaches.
Social engineering on mobile devices achieved click rates 40% higher than traditional email phishing.
Employee use of unapproved AI tools rose from 15% to 45% in a single year, and shadow AI is now the third most common source of non-malicious data leakage.
Emerging trends and what's new in 2026
For journalists and IT leaders tracking this beat, these are the developments that separate the 2026 picture from prior years:
Device compromise overtook scams. The ITRC's finding that hacked devices are now the leading cause of identity compromise among working-age adults marks a change in how identities get stolen. The attack moves from persuading a person to compromising an endpoint, which shifts defense from awareness training toward endpoint security and patching.
Breach volume is decoupling from breach count. Fewer, larger, supply-chain-driven events now dominate exposure. One education platform breach produced more victim notices in 2026 than every breach combined in 2025.
AI is on both sides of the ledger. IBM measured a 56% increase in AI-driven attacks while also finding $1.93 million in savings for defenders using AI extensively. Verizon found generative AI bolstering 15% of attack techniques.
Older adults are the fastest-growing loss category. A 59% one-year increase in losses for Americans over 60 dwarfs the overall 26% increase in IC3-reported losses.
Victims are running out of resolution paths. A 9% resolution rate for anyone who lost money, and 0% for those with three or more financial impacts, suggests recovery infrastructure has not kept pace with attack volume.
Fraud is stabilizing at a high plateau, not falling. Identity fraud losses of $27.3 billion were flat year over year even as scam losses dropped 45%, meaning criminals shifted tactics rather than retreating.
How managed IT services can help
Most identity theft begins with a breach at an organization, not a mistake by an individual, and the 2026 data shows those breaches increasingly originate through unpatched vulnerabilities, third-party vendors, and compromised endpoints. Managed security service providers close those gaps with continuous patching, endpoint detection, vendor risk monitoring, and incident response that most mid-market companies cannot staff internally. Looking for a managed security service provider that can help your organization reduce breach risk and protect customer identity data? manageditservices.ai connects businesses with vetted MSSPs and cybersecurity consultants across the United States. Find a provider near you to compare options.
Related Articles
- Third-Party Data Breach Statistics for 2026Third-party data breaches now account for nearly half of all confirmed breaches worldwide. According to the 2026 Verizon Data Breach Investigations Report, 48% of breaches involved a third-party…
- Small Business Ransomware Statistics for 2026Ransomware has become the defining cyber threat for small businesses. According to the Verizon 2026 Data Breach Investigations Report, ransomware now appears in 48% of all breaches analyzed, up from…
- Small Business Cybersecurity Statistics for 2026Small businesses face an unprecedented wave of cyber threats in 2026. According to the Hiscox Cyber Readiness Report 2026, 56% of U.S.
- Shadow IT Statistics for 2026: What the Latest Data RevealsShadow IT, the use of technology, software, and cloud services without IT department approval, continues to grow as one of the most persistent security and compliance challenges facing…
Hadley McIntosh
Updated Sep 28, 2026 · 10 min read