For millions of Americans, the steady drumbeat of data breach notifications has become a grimly familiar part of modern life. In a digital era where personal information is routinely entrusted to health providers, financial institutions, and retirement plan administrators, the threat of cyber intrusions looms ever larger. Recent incidents in Lake County, Illinois, serve as a stark reminder that no sector is immune—while the broader national numbers paint an even more troubling picture of the cybersecurity landscape in 2026.
Earlier this year, the Lake County Health Department sent out notifications to some of its patients, alerting them to a data breach that occurred back in May. According to the agency’s official statement, the incident stemmed from a printing error that caused some billing statements to contain incorrect patient information. Officials were quick to assure the public that “no financial account information or Social Security Administration numbers were involved, and no information has been misused.” For those who rely on the Health Department and Community Health Center, that news offered a measure of relief—at least compared to the horror stories of more severe breaches that have become all too common.
Still, as reported by Forbes, the scale of data breaches in 2026 is staggering. Within just the first six months of the year, an estimated 471.2 million data breach victim notices were sent out to Americans, according to the Identity Theft Resource Center’s 2026 Data Breach Report. That figure already eclipses the total number of notices for all of 2025, which stood at 297.5 million. Financial services remain the most frequently targeted sector, but health care, professional services, and manufacturing have all suffered significant breaches as well.
The largest single incident so far this year occurred in May, when the education platform Canvas was compromised. Forbes estimates that about 275 million victim notices—representing 58% of the year’s total to date—were sent out, primarily to college students and staff. As the number of affected individuals grows, so too does the sense of resignation among consumers, many of whom now keep drawers full of “security incident” notices and offers for free credit monitoring from the likes of Experian, TransUnion, and Equifax. Yet, as one observer wryly noted, “Which doesn’t help us if our private data is swirling digitally somewhere in the cloud, waiting to be used by bad actors and cyber-grifters years down the road.”
Lake County’s Health Department, in fact, is no stranger to such incidents. In September 2024, the agency experienced a previous breach when an unauthorized third party gained access to an employee’s email account. While officials found no evidence of unauthorized data transfer, the information potentially exposed included names, addresses, dates of birth, medications, phone numbers, email addresses, diagnoses, and even driver’s license numbers. That same year, the Illinois Secretary of State’s Office warned about 50,000 drivers that their personal data may have been exposed in a breach that originated in Lake County—a scammer had infiltrated a county government email account and sent phishing attempts to state employees. Although authorities claimed that Social Security numbers and driver’s license numbers were likely not compromised, the lingering uncertainty is enough to keep residents on edge.
Under Illinois state law, agencies and businesses that experience a data breach are required to notify both the Illinois Attorney General’s Office and the affected residents. These notifications must include details about the nature of the breach, the types of information compromised, and the timeframe of the incident—if known at the time. Yet, for many victims, these warning letters often arrive months after the fact, leaving them to wonder whether their privacy has already been violated and their information sold off to the highest bidder.
So what exactly happens to this trove of stolen data? According to industry experts, cybercriminals can use personal information—such as Social Security numbers, driver’s license numbers, financial account data, medical records, health insurance IDs, biometric data, and login credentials—to take over existing accounts, open new lines of credit, or orchestrate elaborate identity theft schemes. The ancient warning of “buyer beware” has never seemed more relevant as consumers navigate the ever-expanding digital frontier.
Beyond health care and government agencies, retirement plans have emerged as a particularly attractive target for cybercriminals. The U.S. Department of Labor (DOL) has made protecting retirement plans from cybersecurity risks a top priority, but as PLANSPONSOR reports, attention must also be paid to managing and mitigating breaches when they do occur. Brea Dantin, a retirement plan adviser at Shepherd Financial, underscores the importance of swift action: “If I’m the participant, I want to notify the provider and plan sponsor, that way … everyone is on high alert.”
Dantin explains that participants themselves are the “first line of defense” against cyber breaches, with some insurers requiring secure account setup and strong passwords before extending cybersecurity protection guarantees. Yet, even the most diligent account holders can miss subtle signs of intrusion. The real danger, Dantin warns, is that stolen personally identifiable information—such as Social Security numbers, birth dates, and home addresses—can unlock the door to further breaches across other financial accounts.
Determining who is responsible for making participants whole after a breach is, as Dantin puts it, “like the wild, wild west.” Some recordkeepers will accept responsibility and restore lost assets, but not all do. Lisa Matthews, vice president of fraud and risk at IRALogix, advises plan sponsors to scrutinize their contracts with recordkeepers, ensuring they include provisions for data breaches and clarify what the recordkeeper’s insurance covers. “Plan sponsors will often want to have it include a voluntary customer protection restoration guarantee, which can be important to negotiate at the beginning of the hiring process,” Matthews says.
Kevin Walsh, principal at Groom Law Group, notes that the Department of Labor’s Employee Benefits Security Administration has issued “Cybersecurity Program Best Practices,” first in 2021 and updated in 2024, offering detailed guidance for plan sponsors. These best practices recommend a series of steps when a breach occurs: informing law enforcement, notifying insurers, investigating the incident, alerting affected participants without unreasonable delay, providing them with information to prevent further injury, and fixing the underlying vulnerabilities. Honoring contractual and legal notification obligations is also emphasized, as is preventing recurrence.
Walsh further explains that the Employee Retirement Income Security Act (ERISA) is not a strict liability statute but rather a “prudence statute.” In other words, plan sponsors are expected to act prudently—especially when hiring service providers—but are not automatically liable for every cybersecurity incident. “If we’re going to have a voluntary [retirement] system, we can’t put employers in the business of insuring against all cybersecurity vulnerabilities,” Walsh says. Still, the industry is “always hoping to find a way to make the participant whole.”
As data breaches continue to proliferate and evolve, the challenge for individuals, institutions, and regulators alike is to stay one step ahead of the cybercriminals. While new best practices and technologies may offer some hope, the only certainty is that the struggle to protect personal information in the digital age is far from over.