Poppins Payroll Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Poppins Payroll data breach, which reportedly affected thousands of individuals and may have exposed Social Security numbers, financial account codes, and credit and debit account information.


JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Poppins Payroll, please submit your information to be considered:

You may also open the form here: Poppins Payroll Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

Poppins Payroll Data Breach: Key Facts

Company: Poppins Payroll
Location: Boulder, Colorado
Incident Type: Data Breach
Number Affected: THOUSANDS
Data Involved: Social Security numbers, financial account codes, and credit and debit account information
Date Began: September 3, 2026
Date Discovered: September 3, 2026
Date Ended: UNCONFIRMED
Notice Date: September 29, 2026
Credit Monitoring: 24 months of Experian IdentityWorks
Status: Class Action Lawsuit Investigation


What happened in the Poppins Payroll data breach?

Poppins Payroll disclosed a data breach involving unauthorized access to a company system on September 3, 2026. According to its notification, an outside party exploited a vulnerability in Metabase software. The company detected the access that day and determined that personal information may have been accessed or acquired. Its consumer notification letter is dated September 29, 2026. California Attorney General Submitted Breach Notification Sample

The Vermont Attorney General's disclosure lists Social Security numbers and financial information among the affected data categories. The registry uses the categories “Financial Account Codes” and “Credit and Debit Account Info.” The publicly available California sample letter redacts the recipient’s specific affected information, so individual notification letters remain the best source for determining what information was involved for each person. Vermont Attorney General Security Breach Notices

Poppins Payroll states that it addressed the vulnerability, retained an outside security firm, and strengthened system access controls and other safeguards. According to the company, security experts confirmed that the identified vulnerability no longer presented a current threat. As of its notification letter, Poppins reported no evidence of resulting financial fraud or identity theft and offered affected individuals two years of free credit monitoring and identity protection.

California’s registry records the breach report on September 29, 2026, and Vermont’s registry records it on September 30, 2026. Vermont identifies 333 affected residents; that figure represents Vermont residents alone. 8095 individuals were reportedly affected in Massachusetts. A nationwide total could not be confirmed from the official records reviewed as of October 1, 2026. Massachusetts Attorney General Security Breach Notices


How did the Poppins Payroll data breach occur?

An unauthorized party exploited a security vulnerability in Metabase, software used by Poppins Payroll, to access a company system. Poppins subsequently investigated the incident with an outside security firm. The public disclosures reviewed do not identify a specific vulnerability number or provide a detailed technical account of the exploit. AcidPeak


When did the Poppins Payroll data breach occur?

The disclosed breach date is September 3, 2026. Poppins Payroll also detected the unauthorized access that day. California’s official registry lists September 3 as the incident date and September 29, 2026, as the report date. California Attorney General Submitted Breach Notification Sample


How many people were affected by the Poppins Payroll data breach?

Thousands of individuals were affected by the Poppins Payroll data breach. The Poppins Payroll data breach affected at least 8,428 people, including 8,095 Massachusetts residents and 333 Vermont residents. California also published a breach notification, but the company’s nationwide affected population has not been publicly confirmed. California Attorney General Submitted Breach Notification Sample


What information was exposed in the Poppins Payroll data breach?


Has Poppins Payroll offered free credit monitoring and/or identity theft protection services?

Yes. Poppins Payroll offered 24 months of Experian IdentityWorks at no cost, including credit monitoring, dark web monitoring, identity restoration assistance, and up to $1 million in identity theft insurance, subject to policy terms. Recipients should follow their letter’s enrollment instructions and deadline; those details are redacted in the public sample. California Attorney General Submitted Breach Notification Sample


Poppins Payroll Data Breach Timeline

Date Event
September 3, 2026 Unauthorized access occurred through a Metabase vulnerability, and Poppins Payroll detected it the same day.
After detection; exact dates undisclosed Poppins addressed the vulnerability, engaged an outside security firm, and added security protections.
September 29, 2026 Poppins dated its consumer notification letter. California’s registry records the report on this date.
September 30, 2026 Vermont recorded the breach report, identifying 333 affected Vermont residents.

Who is Poppins Payroll?

Poppins Payroll Company, LLC is a privately held household-payroll firm based in Boulder, Colorado. Founded in 2016, it calculates pay, withholds and remits household employment taxes, and prepares year-end forms such as the Form W-2 and Schedule H for families who employ nannies, housekeepers, senior caregivers, and similar household workers. The service is offered in all 50 states. The company states that more than 65,000 families have used it since 2016. Spectrum Equity lists a growth investment with a partnership year of 2024. Mail associated with the firm is directed to P.O. Box 44, Boulder, Colorado 80306. Poppins Payroll Website


What should you do if you received a Poppins Payroll data breach letter?

Keep the notification, review the information identified as affected, and enroll in the offered protection before the stated deadline. Monitor bank statements and credit reports, promptly report unauthorized transactions, and consider free credit freezes with Equifax, Experian, and TransUnion. If identity theft occurs, visit IdentityTheft.gov for recovery steps. Preserve records of suspicious activity, expenses, and time spent addressing the incident.


Poppins Payroll Data Breach Notice

The notice describes the Poppins Payroll data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the Poppins Payroll Data Breach Notice in a New Tab


Sources & Additional Information About the Poppins Payroll Data Breach


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


Infographic summarizing the Poppins Payroll data breach, including the number of affected individuals, the categories of information involved, and the publicly confirmed reporting timeline.
Poppins Payroll data breach infographic summarizing the number of people affected, the types of information involved, and the publicly confirmed timeline. Information current as of September 30, 2026.


About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Poppins Payroll data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the Poppins Payroll data breach, Poppins Payroll data breach notice, Poppins Payroll class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by Poppins Payroll or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.