Metabase and Poppins Payroll: Poppins Payroll Data Breach Impacts Hundreds: Financial Info Exposed

Metabase and Poppins Payroll: Poppins Payroll Data Breach Impacts Hundreds: Financial Info Exposed

Poppins Payroll Data Breach Exposes Sensitive Personal and Financial Information

Poppins Payroll, a Boulder, Colorado-based payroll and tax service specializing in household employment, disclosed a data breach that compromised sensitive personal and financial data. The company, founded in 2016, serves individuals employing domestic workers such as nannies, housekeepers, and caregivers.

On September 3, 2026, Poppins Payroll detected an unauthorized intrusion into one of its systems. The attacker exploited a vulnerability in Metabase, a third-party software vendor used by the company, gaining access to sensitive data on the same day. The exposed information included Social Security numbers, financial account details, and credit/debit card information.

The breach was reported to the attorneys general offices of California and Vermont on September 29, 2026, with 333 Vermont residents confirmed as affected. In response, Poppins Payroll offered impacted individuals 24 months of complimentary credit monitoring and identity protection through Experian IdentityWorks, along with a dedicated call center for inquiries. Notification letters included activation codes and enrollment deadlines for affected parties.

Source: https://www.claimdepot.com/data-breach/poppins-payroll-2026

Poppins Payroll cybersecurity rating report: https://www.rankiteo.com/company/poppins-payroll

Metabase cybersecurity rating report: https://www.rankiteo.com/company/metabase

"id": "POPMET1790807516",
"linkid": "poppins-payroll, metabase",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '333 Vermont residents '
                                              'confirmed, others unknown',
                        'industry': 'Payroll and Tax Services',
                        'location': 'Boulder, Colorado, USA',
                        'name': 'Poppins Payroll',
                        'type': 'Company'}],
 'attack_vector': 'Third-party software vulnerability',
 'customer_advisories': 'Notification letters with credit monitoring '
                        'enrollment details',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Social Security numbers',
                                              'Financial account details',
                                              'Credit/debit card information']},
 'date_detected': '2026-09-03',
 'date_publicly_disclosed': '2026-09-29',
 'description': 'Poppins Payroll, a Boulder, Colorado-based payroll and tax '
                'service specializing in household employment, disclosed a '
                'data breach that compromised sensitive personal and financial '
                'data. The attacker exploited a vulnerability in Metabase, a '
                'third-party software vendor, gaining access to sensitive data '
                'including Social Security numbers, financial account details, '
                'and credit/debit card information.',
 'impact': {'data_compromised': 'Social Security numbers, financial account '
                                'details, credit/debit card information',
            'identity_theft_risk': 'High',
            'payment_information_risk': 'High'},
 'post_incident_analysis': {'root_causes': 'Third-party software (Metabase) '
                                           'vulnerability'},
 'references': [{'source': 'Company disclosure'}],
 'regulatory_compliance': {'regulatory_notifications': ['California and '
                                                        'Vermont attorneys '
                                                        'general offices']},
 'response': {'communication_strategy': 'Notification letters to affected '
                                        'individuals with activation codes and '
                                        'enrollment deadlines',
              'third_party_assistance': 'Experian IdentityWorks (credit '
                                        'monitoring and identity protection)'},
 'title': 'Poppins Payroll Data Breach Exposes Sensitive Personal and '
          'Financial Information',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Metabase vulnerability'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.