Poppins Payroll Data Breach Class Action Lawsuit Investigation
Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Poppins Payroll data breach, which reportedly affected thousands of individuals and may have exposed Social Security numbers, financial account codes, and credit and debit account information.
JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Poppins Payroll, please submit your information to be considered:
You may also open the form here: Poppins Payroll Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.
Poppins Payroll Data Breach: Key Facts
| Company: | Poppins Payroll |
|---|---|
| Location: | Boulder, Colorado |
| Incident Type: | Data Breach |
| Number Affected: | THOUSANDS |
| Data Involved: | Social Security numbers, financial account codes, and credit and debit account information |
| Date Began: | September 3, 2026 |
| Date Discovered: | September 3, 2026 |
| Date Ended: | UNCONFIRMED |
| Notice Date: | September 29, 2026 |
| Credit Monitoring: | 24 months of Experian IdentityWorks |
| Status: | Class Action Lawsuit Investigation |
What happened in the Poppins Payroll data breach?
Poppins Payroll disclosed a data breach involving unauthorized access to a company system on September 3, 2026. According to its notification, an outside party exploited a vulnerability in Metabase software. The company detected the access that day and determined that personal information may have been accessed or acquired. Its consumer notification letter is dated September 29, 2026. California Attorney General Submitted Breach Notification Sample
The Vermont Attorney General's disclosure lists Social Security numbers and financial information among the affected data categories. The registry uses the categories “Financial Account Codes” and “Credit and Debit Account Info.” The publicly available California sample letter redacts the recipient’s specific affected information, so individual notification letters remain the best source for determining what information was involved for each person. Vermont Attorney General Security Breach Notices
Poppins Payroll states that it addressed the vulnerability, retained an outside security firm, and strengthened system access controls and other safeguards. According to the company, security experts confirmed that the identified vulnerability no longer presented a current threat. As of its notification letter, Poppins reported no evidence of resulting financial fraud or identity theft and offered affected individuals two years of free credit monitoring and identity protection.
California’s registry records the breach report on September 29, 2026, and Vermont’s registry records it on September 30, 2026. Vermont identifies 333 affected residents; that figure represents Vermont residents alone. 8095 individuals were reportedly affected in Massachusetts. A nationwide total could not be confirmed from the official records reviewed as of October 1, 2026. Massachusetts Attorney General Security Breach Notices
How did the Poppins Payroll data breach occur?
An unauthorized party exploited a security vulnerability in Metabase, software used by Poppins Payroll, to access a company system. Poppins subsequently investigated the incident with an outside security firm. The public disclosures reviewed do not identify a specific vulnerability number or provide a detailed technical account of the exploit. AcidPeak
When did the Poppins Payroll data breach occur?
The disclosed breach date is September 3, 2026. Poppins Payroll also detected the unauthorized access that day. California’s official registry lists September 3 as the incident date and September 29, 2026, as the report date. California Attorney General Submitted Breach Notification Sample
How many people were affected by the Poppins Payroll data breach?
Thousands of individuals were affected by the Poppins Payroll data breach. The Poppins Payroll data breach affected at least 8,428 people, including 8,095 Massachusetts residents and 333 Vermont residents. California also published a breach notification, but the company’s nationwide affected population has not been publicly confirmed. California Attorney General Submitted Breach Notification Sample
What information was exposed in the Poppins Payroll data breach?
- Breached data reportedly may include, but is not necessarily limited to:
- Social Security numbers
- financial account codes
- credit and debit account information
Has Poppins Payroll offered free credit monitoring and/or identity theft protection services?
Yes. Poppins Payroll offered 24 months of Experian IdentityWorks at no cost, including credit monitoring, dark web monitoring, identity restoration assistance, and up to $1 million in identity theft insurance, subject to policy terms. Recipients should follow their letter’s enrollment instructions and deadline; those details are redacted in the public sample. California Attorney General Submitted Breach Notification Sample
Poppins Payroll Data Breach Timeline
| Date | Event |
|---|---|
| September 3, 2026 | Unauthorized access occurred through a Metabase vulnerability, and Poppins Payroll detected it the same day. |
| After detection; exact dates undisclosed | Poppins addressed the vulnerability, engaged an outside security firm, and added security protections. |
| September 29, 2026 | Poppins dated its consumer notification letter. California’s registry records the report on this date. |
| September 30, 2026 | Vermont recorded the breach report, identifying 333 affected Vermont residents. |
Who is Poppins Payroll?
Poppins Payroll Company, LLC is a privately held household-payroll firm based in Boulder, Colorado. Founded in 2016, it calculates pay, withholds and remits household employment taxes, and prepares year-end forms such as the Form W-2 and Schedule H for families who employ nannies, housekeepers, senior caregivers, and similar household workers. The service is offered in all 50 states. The company states that more than 65,000 families have used it since 2016. Spectrum Equity lists a growth investment with a partnership year of 2024. Mail associated with the firm is directed to P.O. Box 44, Boulder, Colorado 80306. Poppins Payroll Website
What should you do if you received a Poppins Payroll data breach letter?
Keep the notification, review the information identified as affected, and enroll in the offered protection before the stated deadline. Monitor bank statements and credit reports, promptly report unauthorized transactions, and consider free credit freezes with Equifax, Experian, and TransUnion. If identity theft occurs, visit IdentityTheft.gov for recovery steps. Preserve records of suspicious activity, expenses, and time spent addressing the incident.
Poppins Payroll Data Breach Notice
The notice describes the Poppins Payroll data breach, including the type of information that may have been involved and the steps offered to affected individuals.
Open the Poppins Payroll Data Breach Notice in a New Tab
Sources & Additional Information About the Poppins Payroll Data Breach
-
- Poppins Payroll Website
- Massachusetts Attorney General Security Breach Notices
- Vermont Attorney General Security Breach Notices
- California Attorney General Submitted Breach Notification Sample
- AcidPeak
- my Social Security
- Medicare.gov: Reporting Medicare fraud & abuse
- FTC: Checking Your Credit Report
- FTC: Credit Freezes and Fraud Alerts
- AnnualCreditReport.com
- FTC Consumer Advice: Identity Theft
- IdentityTheft.gov
- IRS Identity Theft Guide for Individuals
- IRS Identity Theft Guide Central
- IRS: Get an identity protection PIN (IP PIN)
- U.S. Department of Health and Human Services Office of Inspector General: Medical Identity Theft
- IdentityTheft.gov: What To Do if Your Information Was Lost or Stolen, or Part of a Data Breach
Class Action FAQ
About This Data Breach Resource
This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Poppins Payroll data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.
This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.
This page is especially relevant for readers searching for information about the Poppins Payroll data breach, Poppins Payroll data breach notice, Poppins Payroll class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.
Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.
The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.
For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?
This website is not associated with nor authorized by Poppins Payroll or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.