Poppins Payroll, a household payroll and tax service based in Boulder, Colorado, disclosed a data breach that exposed sensitive personal and financial information.
Founded in 2016, Poppins Payroll focuses exclusively on household payroll rather than general business payroll. It provides services for individuals who employ workers in their homes, including nannies, babysitters, housekeepers, gardeners, personal assistants and senior caregivers.
On Sept. 3, 2026, Poppins Payroll detected that an unauthorized third party had gained access to one of its systems. The intruder exploited a security vulnerability in Metabase, a software vendor used by the company, to reach a Poppins Payroll system. The breach was both discovered and carried out on the same day.
An investigation into the incident determined that personal information may have been accessed or acquired by the unauthorized third party on Sept. 3, 2026.
The types of information exposed included Social Security numbers, financial account codes and credit and debit account information.
The company disclosed the incident to the attorneys general offices of California and Vermont starting on Sept. 29, 2026. According to the respective state filing, 333 Vermont residents were identified as affected by the incident.
Poppins Payroll’s response to the breach
Poppins Payroll is offering affected individuals 24 months of complimentary credit monitoring and identity protection services through Experian IdentityWorks. Affected individual received a unique activation code and an enrollment deadline in their notification letter.
Poppins Payroll also established a dedicated call center for questions about the incident. The call center’s contact information was included in the notification letters sent to affected individuals.
The company’s mailing address for correspondence related to the breach is PO Box 44, Boulder, CO 80306-0044.
