What Happened in the Wikoff Color Corporation Data Breach?
Wikoff Color Corporation, a maker of inks and coatings based in Fort Mill, South Carolina, has disclosed a data security incident tied to a phone-based scam. An employee received a fraudulent phone call, commonly known as a vishing attempt, that tricked them into granting an outsider access to internal systems. This access allowed the attacker to view and take certain company files.
According to filings, the intrusion took place between June 26, 2026 and July 6, 2026. Unlike many breaches that rely on malware or a technical exploit, this incident depended on manipulating a person rather than breaking through a firewall. The attacker impersonated a trusted contact to convince the employee to hand over access.
Wikoff discovered the incident and began an internal review shortly afterward. The breach discovery date was reported as July 2026. As a result, the company brought in outside cybersecurity specialists to investigate, secure its network, and determine exactly what data had been reached.
Wikoff also alerted law enforcement about the intrusion. In addition, the company notified the New Hampshire Attorney General’s office, since at least one New Hampshire resident was confirmed to be affected. The notification date for this breach was July 2026, and Wikoff began sending letters to affected individuals around that same time.
Because vishing exploits human trust rather than software flaws, it has become a growing threat across many industries. Manufacturing companies, in particular, may not always have the same depth of security training found in banking or healthcare. This incident illustrates how a single phone call can lead to a serious exposure of sensitive personal records.
Who was affected?
The people affected by this breach are described as clients of Wikoff Color Corporation. At least one individual, a resident of New Hampshire, has been confirmed as impacted through the notification filed with that state’s Attorney General.
However, the exact number of people affected nationwide has not been publicly disclosed. Wikoff has stated that its review of the incident was still ongoing at the time it sent notice letters. Because of this, the company said it would supplement its disclosure if further details came to light.
It remains unclear whether employees, in addition to clients, were affected by the exposure. Similarly, there is no public information yet indicating whether minors are among the impacted individuals. Anyone who receives a written notice from Wikoff should treat it as confirmation that their data was involved.
What Information Was Potentially Exposed?
The investigation found that the unauthorized party accessed files containing highly sensitive identifying information. This is the type of data combination that regulators and security experts consider especially dangerous when exposed together.
- Full name
- Date of birth
- Social Security number
This combination of data points is often enough on its own to pass identity verification at a bank, credit bureau, or government agency. As a result, criminals can use it to open new financial accounts or take out loans in a victim’s name.
Beyond new account fraud, this type of data can also be used to file a fraudulent tax return or claim government benefits under someone else’s identity. Because a Social Security number cannot easily be changed, the risk from this kind of exposure can persist for years. Ongoing vigilance is essential for anyone confirmed to be affected.
What is the company doing?
Once Wikoff learned of the intrusion, it moved to contain the situation. The company hired outside cybersecurity experts to investigate the scope of the attack and to help lock down its systems going forward. It also reported the incident to law enforcement for further investigation.
In response to the breach, Wikoff is offering 24 months of free credit monitoring to individuals confirmed to be affected. In addition, the company says it is reviewing its internal security policies and procedures. This review is meant to reduce the chance that a similar vishing scheme could succeed again in the future.
Because the investigation into the full scope of the incident was still active at the time notices went out, Wikoff has committed to sending updated information if more details emerge. This means additional individuals could still be notified later. Affected individuals should keep any letters they receive for their records.
What Should Affected Individuals Do?
Enroll in Credit Monitoring
Anyone who receives a notice from Wikoff should sign up for the free 24-month credit monitoring service being offered. This service can help flag suspicious new activity on your credit file quickly.
Because monitoring only tracks activity after enrollment, it is important to sign up as soon as the offer becomes available. Waiting too long could mean missing early warning signs of fraud. Review the notification letter carefully for enrollment instructions and deadlines.
Place a Fraud Alert or Credit Freeze
Given that a Social Security number was exposed, affected individuals should strongly consider placing a fraud alert or a full credit freeze with all three major credit bureaus. A freeze makes it much harder for a criminal to open new accounts using your information.
To place a freeze, you must contact Equifax, Experian, and TransUnion separately. This step is free by law, and it can be lifted temporarily whenever you need to apply for credit yourself. Because this breach involved a highly sensitive data combination, a freeze offers stronger protection than a fraud alert alone.
Watch for Tax and Government Benefit Fraud
Since Social Security numbers were involved, affected individuals should watch for signs of tax-related identity theft. This includes any unexpected notice from the IRS about a tax return you did not file.
You can also request an Identity Protection PIN from the IRS as an added layer of defense. This PIN prevents someone else from filing a tax return using your Social Security number. In addition, watch for any unfamiliar notices related to unemployment or other government benefits.
Stay Alert for Phishing Attempts
Because this breach originated from a phone-based social engineering scam, affected individuals should be especially cautious of unexpected calls, texts, or emails. Scammers sometimes use breach news to run follow-up scams pretending to help with the very incident that exposed your data.
Never give out personal information to an unsolicited caller, even if they claim to represent a bank, government agency, or the breached company itself. Instead, hang up and contact the organization directly using a verified phone number. This simple habit can prevent a second wave of fraud following the original breach.
Monitor Financial Accounts Closely
In addition to credit monitoring, affected individuals should regularly review their bank and credit card statements. Look for any charges or withdrawals you do not recognize, even small ones, since criminals sometimes test stolen data with tiny transactions first.
If you notice anything suspicious, report it to your financial institution immediately. You should also consider reporting suspected identity theft to the Federal Trade Commission and your state Attorney General’s office. Keeping detailed records of any fraud you discover can also help if you later decide to pursue legal action.
