[US] Implications of Poppins Payroll data breach

[US] Implications of Poppins Payroll data breach
06 Oct 2026

In the US, the household employee payroll company Poppins Payroll informed customers of a serious data breach. The cyberattack, which happened in early September, may have exposed their personal information to cybercriminals, Newsweek reports.

Lawyers are now exploring a potential class-action lawsuit.

Parents reportedly use Poppins Payroll to pay household nannies on the books. More than 65,000 families have used the service since it launched in 2016. 

It is not yet known how many people were impacted by the data breach. However, it could potentially have impacted tens of thousands of customers.

In a letter to those customers, Poppins stated that their Social Security numbers, birth dates and financial account numbers might have been compromised. The letters were sent on September 29, weeks after the company detected the breach.

Speaking to Newsweek, Zachary Lewis - chief information security officer and data protection officer at the University of St. Louis Health Sciences & Pharmacy School - said it's always "serious" when someone's Social Security number is exposed, but many Americans likely already had theirs compromised in previous breaches.

On September 3, Poppins Payroll detected that a third party had gained unauthorised access to customers' information through a security vulnerability in Metabase, a software vendor the company uses. Metabase reportedly offers companies a means of analysing and visualising data.

Brad LaPorte - a cybersecurity analyst - told Newsweek that the amount of information that was potentially compromised is particularly concerning, as a payroll company holds "everything a criminal needs to become you."

In the letter, Poppins told customers it had no evidence that their information was used to commit financial fraud or identity theft. But information isn't always used immediately after it's stolen. 

Poppins reportedly offered customers two years of credit monitoring and identity protection.

Mr Lewis said, "An absence of immediate fraud does not mean the information will never be used. We've seen instances of threat actors sitting on this information for years before it gets used." 



Source: Newsweek

(Quotes via original reporting)

 

In the US, the household employee payroll company Poppins Payroll informed customers of a serious data breach. The cyberattack, which happened in early September, may have exposed their personal information to cybercriminals, Newsweek reports.

Lawyers are now exploring a potential class-action lawsuit.

Parents reportedly use Poppins Payroll to pay household nannies on the books. More than 65,000 families have used the service since it launched in 2016. 

It is not yet known how many people were impacted by the data breach. However, it could potentially have impacted tens of thousands of customers.

In a letter to those customers, Poppins stated that their Social Security numbers, birth dates and financial account numbers might have been compromised. The letters were sent on September 29, weeks after the company detected the breach.

Speaking to Newsweek, Zachary Lewis - chief information security officer and data protection officer at the University of St. Louis Health Sciences & Pharmacy School - said it's always "serious" when someone's Social Security number is exposed, but many Americans likely already had theirs compromised in previous breaches.

On September 3, Poppins Payroll detected that a third party had gained unauthorised access to customers' information through a security vulnerability in Metabase, a software vendor the company uses. Metabase reportedly offers companies a means of analysing and visualising data.

Brad LaPorte - a cybersecurity analyst - told Newsweek that the amount of information that was potentially compromised is particularly concerning, as a payroll company holds "everything a criminal needs to become you."

In the letter, Poppins told customers it had no evidence that their information was used to commit financial fraud or identity theft. But information isn't always used immediately after it's stolen. 

Poppins reportedly offered customers two years of credit monitoring and identity protection.

Mr Lewis said, "An absence of immediate fraud does not mean the information will never be used. We've seen instances of threat actors sitting on this information for years before it gets used." 



Source: Newsweek

(Quotes via original reporting)

 

Leave a Reply

All blog comments are checked prior to publishing