I don't like #ITRC for such purposes because they only used data from incidents involving SSN and were focused on identity theft. They never included incidents with only PHI or sensitive personal data if it wasn't likely to lead to ID theft. I prefer #DBIR, but keep in mind it's a bit narrower than what you might want as it only includes confirmed breaches.
Did you check the FTC Sentinel reports to see what they can give you?
On May 2, the Interstate Technology Regulatory Council (ITRC) will be holding a roundtable on data quality for environmental data. The panelists will be discussing best practices and taking audience questions. Register at https://itrcweb.org/events/event-description?CalendarEventKey=53388505-3688-47db-bac4-0186e59c625f&CommunityKey=0c358b0a-a5b9-4fd7-a832-11888551a153&Home=%2fevents%2fcalendar
Related documents are at https://edm-1.itrcweb.org/environmental-data-quality-home/
The second roundtable in the Environmental Data Management Best Practices series by the Interstate Technology and Regulatory Council (ITRC) will be held on April 6, and will address the topic of exchanging environmental data.
More information, and registration for the roundtable, is available at https://www.clu-in.org/conf/itrc/EDM-2/