Identity theft news in 2026 was not one nationwide breach. It covered exposed account data, alleged tax fraud, victim-rights enforcement, and an incident where investigators found no sensitive-data loss. Students, school staff, client end users, and taxpayers were among those affected or potentially exposed. Identity theft means using another person's identifying information to impersonate them for fraud.
Table of Contents
- What the 2026 reports actually show
- Who was affected by the Canvas and Conduent incidents?
- When an intrusion does not expose identities
- How identities were allegedly misused—and what victims can obtain
- What should a confirmed victim do?
What the 2026 reports actually show
Identity theft remained a widespread consumer-security problem rather than a single news event. The FTC said more than one million people reported identity theft during 2025, according to its January 2026 consumer alert. The year's reports fall into three different categories: data exposure, confirmed or alleged misuse, and incidents where investigators found no sensitive personal data loss.
Readers should not treat those categories as interchangeable. A breach can create risk without proving that someone used the exposed information. Conversely, an identity-theft scheme may combine information obtained from several sources rather than one publicly identified breach.
Who was affected by the Canvas and Conduent incidents?
Instructure detected unauthorized Canvas activity on April 29, 2026. Potentially affected information included usernames, email addresses, course names, enrollment details, and messages belonging to schools, students, teachers, and staff. In its July 2026 incident update, Instructure said core learning data was not compromised. That category included course content, submissions, and credentials. Institutions still need to examine their incident-specific data packets because review of message data continued after the initial deliveries.
The reported exposure of usernames should therefore not be restated as a confirmed credential breach. The practical impact depends on the fields listed in each institution's packet, particularly any information found in messages. Conduent illustrates a separate problem involving service providers. Its April 2025 SEC disclosure said attackers had exfiltrated files during a January 13 intrusion. Those files concerned limited clients but contained personal information belonging to a significant number of their end users; the company had not yet determined the precise impact at the time of disclosure.
When an intrusion does not expose identities
The National Association of Insurance Commissioners reported a PeopleSoft intrusion in June 2026 in which data was exfiltrated. However, its investigation found no evidence that personally identifiable information, banking data, policyholder information, producer data, or employee data was accessed or released. That distinction limits what readers can conclude from a breach headline.
Data exfiltration confirms that information left a system, but it does not establish that identity-related records were among it. The NAIC finding also differs from an assurance that no intrusion occurred. The intrusion and exfiltration were acknowledged; the investigation's narrower conclusion concerned the categories of information accessed or released.
How identities were allegedly misused—and what victims can obtain
In April 2026, the Justice Department charged two men over an alleged stolen-identity tax-refund scheme. Prosecutors alleged that more than 300 false returns sought over $100 million using accountants' and taxpayers' names, addresses, and Social Security numbers. Charges are allegations, not findings of guilt.
The case nevertheless shows the difference between exposed data and claimed misuse: prosecutors alleged that identifying information was actively used to seek refunds. An August 2026 federal court order addressed another practical issue: access to records after identity theft. Under the Justice Department's announced Amazon order, Amazon must provide requested transaction records to verified identity-theft victims free within 30 days. The resolution followed allegations that Amazon had not supplied records promptly and included a $2.25 million civil penalty.
What should a confirmed victim do?
A confirmed victim should act on the affected accounts first. The CFPB's identity-theft response guidance recommends these steps: A security freeze is free and generally stops new credit accounts from being opened. It does not protect existing accounts, so victims must still review those accounts and respond to unauthorized activity.
Paid identity-monitoring services vary widely. They do not replace reviewing credit reports or acting when fraud appears. A freeze must be placed separately with Equifax, Experian, and TransUnion.
- Close compromised accounts.
- Contact the relevant banks or other financial institutions.
- File a report through IdentityTheft.gov.
- Place a fraud alert or security freeze.
