Welcome to The Optery Dispatch — a newsletter delivering the latest insights on threat intelligence and proactive cybersecurity strategy. In Issue #16, published August 25, 2026, we cover:
- The ITRC reports 471.2 million victim notices in H1 2026, surpassing the full-year 2025 total as phishing, smishing, and BEC remain the leading disclosed attack category.
- Google details how UNC6671 targets employees on personal mobile phones to circumvent corporate security controls and compromise cloud environments.
- Zscaler findings and Optery survey data show why personal data removal must extend beyond executives to other high-risk roles across the workforce.
ITRC 2026 H1 DBR: Cyberattacks Drive Record Breach Pace as Social Engineering Remains the #1 Reported Attack Vector
Victim notices exceeded the full-year 2025 total in six months, as phishing, smishing, and BEC continue to be the leading reported source of compromise
The Identity Theft Resource Center recorded 1,803 data compromises and an estimated 471.2 million victim notices in the first half of 2026, already exceeding the 297.5 million notices issued during all of 2025. At the current pace, 2026 could reach approximately 3,600 compromises and set a new annual record.
Cyberattacks accounted for 1,256 compromises, or 69.7% of the total, but generated 92.3% of all victim notices. Phishing, smishing, and business email compromise, grouped as a single category, remained the leading disclosed cyberattack vector.
The ITRC continues to highlight a worsening breach-transparency problem. Only 425 of the 1,803 notices, or 24%, disclosed how the compromise occurred, the lowest rate the ITRC has recorded. Among cyberattacks, 972 of 1,256 were classified as “Not Specified,” leaving the attack vector unknown in more than three out of four cases. The ITRC notes that “this opacity prevents consumers, businesses and policymakers from understanding their true risk exposure or taking meaningful preventive action.”
Financial services experienced the most compromises, followed by healthcare, professional services, and manufacturing. Technology generated the greatest number of victim notices.
The report concludes with recommendations for consumers and businesses, including credit freezes, passkeys, multifactor authentication, least-privilege access, zero-trust architecture, continuous vendor monitoring, automated patching, network segmentation, incident-response exercises, and employee training.
Personal data removal provides another layer of mitigation. Data brokers and people-search sites expose the names, roles, relationships, phone numbers, email addresses, and other details attackers use to launch phishing, smishing, and BEC attacks. Cybersecurity leaders ranked data brokers as the #1 source of attacker intelligence for social engineering in Optery’s 2026 Enterprise Social Engineering Survey Report.
Additionally, the H1 report cites ITRC’s 2025 Annual Data Breach Report, which found that 53.7% of breach victims experienced increased phishing attempts after a breach. Following a breach, personal data removal helps prevent attackers from enriching stolen records with data broker information to build more complete target profiles for phishing, impersonation, credential theft, account takeover, and other follow-on attacks.
Read the full report: ITRC H1 2026 Data Breach Report – ITRC
UNC6671 Targets Employees’ Personal Phones in Enterprise Vishing Campaign
UNC6671 reaches employees outside corporate channels to gain access to enterprise cloud environments
Google Threat Intelligence Group (GTIG) reported on August 6 that UNC6671, a financially motivated threat cluster, is continuing to compromise organizations through targeted voice-phishing attacks that lead to cloud data theft and extortion. The activity has been associated with several extortion brands, including BlackFile, Redact, Pink, Helix, and Falcon.
Attackers call targeted employees on their personal mobile phones while posing as corporate IT help-desk personnel. In some recent cases, they have spoofed the organization’s legitimate help-desk number. Claiming that an urgent security migration requires the employee to enable FIDO2 passkeys or update their multifactor authentication enrollment, the caller directs the employee to a company-specific lookalike site. Adversary-in-the-middle infrastructure then intercepts credentials and authentication tokens, allowing the attackers to access Microsoft 365, Okta, and connected cloud services.
Once inside, UNC6671 uses automated scripts to exfiltrate data. The attackers have also used compromised email accounts to reset passwords for applications outside the organization’s single sign-on environment and deleted password-reset confirmations, security notifications, company-wide alerts, and other messages that could reveal their activity.
Google observed the group narrow its targeting in July to private-equity firms, law firms, and financial-rating agencies, apparently seeking sensitive corporate and client information that could provide greater extortion leverage. Between January 7 and May 12, Google reviewed 18 BlackFile Bitcoin wallets that received approximately $10.69 million. Initial ransom demands typically ranged from $1 million to more than $3 million.
Google recommends phishing-resistant MFA, stronger session controls, managed-device requirements, restrictions on where authentication can originate, and closer monitoring of identity and SaaS activity. GTIG did not identify how the attackers obtained employees’ personal mobile numbers. However, data broker removal closes off a readily available source of this targeting data and should be considered an essential mitigation.
Zscaler: Ransomware Attackers Target “Business Privilege” Across the Workforce
Managers and employees in finance, sales, operations, HR, and marketing are among the roles attackers value most
Managers and employees in finance, sales, operations, HR, and marketing are among the roles attackers value most
Over a one-month period, Zscaler ThreatLabz identified 351 victims across 334 organizations linked to a single ransomware campaign. It found that 62% held manager-level titles or higher, while roughly 75% worked in accounting and finance, sales, operations, HR, or marketing.
Zscaler describes the value these employees possess as “business privilege”: access and authority created by employees’ roles and relationships. The findings indicate attackers are pursuing people who can help them reach systems, sensitive data, financial processes, and other employees, whether or not they sit in the executive suite.
Zscaler also notes that attackers combine information from compromised systems with publicly available data to map reporting lines and identify the employees most likely to influence an organization’s response.
Optery’s 2026 survey of 400+ cybersecurity leaders found a similarly broad target set. Among respondents, IT and IAM personnel were identified most often (80.5%), followed by HR (44.7%), finance (43.9%), executives (42.3%), help desk personnel (33.0%), engineers (22.8%), contractors (17.8%), and sales personnel (9.3%).
Optery’s survey respondents also ranked data broker and people-search sites as the No. 1 source of attacker intelligence used in social engineering.
Executives remain an important target set, but they ranked fourth in Optery’s survey. Executive-only data broker removal does not reflect the breadth of roles attackers are focusing on. Personal data removal has to follow the risk across other high-risk roles and the broader workforce.
The vast majority of organizations are already moving in that direction. Among Optery’s survey respondents, 82.2% said their organizations plan to expand personal data removal coverage within the next 12 months, while another 6.9% said expansion is under consideration.
Read more:
- Ransomware Victims Research | ThreatLabz
- Ransomware gangs skip the CEO, head straight for the 40-something IT manager
- The Data Behind the Deception: Optery 2026 Enterprise Social Engineering Survey Report – Optery
Thanks for reading! Want us to write about something specific? Submit a topic or idea.
If you’re looking to reduce your organization’s exposed PII and dramatically lower the volume of phishing, voice and messaging scams, credential theft attempts, and other PII-based threats your team has to defend against, Optery can help. We find and remove dozens more exposed profiles per person on average than competing services, and we prove it with before-and-after screenshots.
Get started here: Optery for Business
Subscribe to receive future editions of The Optery Dispatch







