Poppins Payroll
Incident posture
Linked entities
- Victim
- Poppins Payroll
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Poppins Payroll detected unauthorized access after a vulnerability in the Metabase software it uses was exploited, leading to potential exposure of personal information for household employers and employees. The company reported the incident to the California and Vermont Attorneys General and noted that 333 Vermont residents were affected, while the full nationwide scope remains unconfirmed. Data that may have been accessed includes names, Social Security numbers, dates of birth, addresses, phone numbers, wage and tax information, and financial account details. The company has offered affected individuals two years of credit monitoring and identity protection services.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On September 3, 2026, Poppins Payroll detected unauthorized access to one of its systems after an external actor exploited a known vulnerability in the Metabase analytics platform that the company used for internal reporting. The intrusion occurred on the same day it was discovered, according to the company's internal logs. Upon detection, Poppins Payroll immediately worked to remediate the vulnerability and engaged an external cybersecurity firm to conduct a forensic investigation. The firm's analysis concluded that the breach may have allowed the attacker to view or acquire personal data stored in the affected system. The company reported that it addressed the security flaw and took steps to prevent further unauthorized entry.
The information that may have been accessed varied depending on what each individual had previously supplied to Poppins Payroll for payroll and tax processing. Potential data elements included full name, Social Security number, date of birth, residential address, telephone number, wage and compensation details, tax return information, direct deposit and other financial account numbers, and credit or debit card information. Poppins Payroll serves household employers and the household employees they pay through its platform, so both groups could be affected. A filing with the Vermont Attorney General's office identified 333 Vermont residents whose information was potentially compromised, while the total number of affected individuals nationwide has not been publicly disclosed. The company also notified the California Attorney General beginning September 29, 2026, as part of its state breach reporting obligations.
Starting September 29, 2026, Poppins Payroll sent breach notification letters to individuals whose data may have been exposed and simultaneously notified the California and Vermont Attorneys General of the incident. As part of its response, the company offered affected persons 24 months of credit monitoring and identity protection services through Experian IdentityWorks. Edelson Lechtzin LLP, a national class action law firm, announced an investigation into possible claims arising from the breach and began offering free case evaluations to those who received a notice or suspected exposure. The firm stated that any successful litigation could seek compensation for losses related to the incident and encourage improved data safeguards at Poppins Payroll. As of the date of the public statements, the full nationwide scope of the breach and the identity of the attacker remained unconfirmed.
Sources
Sources available to members: 1 source.