Poppins Payroll Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Poppins Payroll
Active investigation Data breach · Financial Notices mailed Sep 29, 2026

Received a September 2026 breach notice from Poppins Payroll?

Dapeer Law, P.A. is investigating a potential class action against Poppins Payroll Company, a Boulder, Colorado household payroll and tax services provider, on behalf of families, nannies, caregivers, and other individuals whose personal information may have been exposed in the September 2026 cyber incident.

Submit your claim → See what to do No fee unless we recover for you
Breach window
Sep 3, 2026
Unauthorized system access via Metabase vulnerability
Notification delay
About 4 weeks
Discovered Sep 3, 2026, notices Sep 29, 2026
Credit monitoring
24 months
Through Experian IdentityWorks (three-bureau)
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Poppins Payroll dated September 2026.
  • Your letter offered enrollment in 24 months of free Experian IdentityWorks credit monitoring, including $1 million in identity theft insurance.
  • You had personal or financial information held by Poppins Payroll in its capacity as a household payroll and tax services provider, for example as a family that employs household staff or as a nanny, caregiver, or other household employee paid through Poppins.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility →
Background

What happened

On September 3, 2026, Poppins Payroll Company detected unauthorized access to one of its systems. According to the notice letter filed with the California Attorney General, an unauthorized third party used a security vulnerability in Metabase, a software vendor used by Poppins Payroll, to access a Poppins system. The company states that it detected and stopped the access the same day and retained a third-party security firm to investigate the scope of the incident.

Poppins Payroll began mailing notice letters on September 29, 2026, about four weeks after the incident was discovered. The company is offering 24 months of complimentary Experian IdentityWorks membership, which includes daily three-bureau credit monitoring, dark web monitoring, identity restoration support, and up to $1 million in identity theft insurance. The public version of the notice refers to personal information but does not itemize the specific data elements involved, and the total number of people affected has not been disclosed. Exactly what information was accessed and whether the vendor vulnerability should have been patched or mitigated sooner are among the issues being evaluated.

Household payroll providers typically maintain sensitive records for both employers and their household employees, which can include names, addresses, Social Security numbers, tax identification details, wage information, and bank account details used for direct deposit and tax payments. If information of this kind was accessed, affected individuals could face an elevated risk of identity theft, tax-related fraud, and financial fraud. Recipients should read their own letter carefully for any details about their specific information.

Metabase vulnerability Third-party software Household payroll Colorado California AG filing
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard your Poppins Payroll breach notice. Your letter contains your Experian IdentityWorks activation code and enrollment deadline, and is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free 24-month credit monitoring

Enroll in the Experian IdentityWorks membership offered in your letter before the activation deadline stated in the letter, using the unique code provided. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because payroll records can include tax and direct deposit information, also watch for unexpected IRS correspondence, and review your bank statements for unfamiliar transactions.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We'll review your Poppins Payroll notice, explain your options, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim →
Timeline

Breach timeline

Sep 3, 2026 Passed
Unauthorized access to a Poppins Payroll system through a Metabase vulnerability
Sep 3, 2026 Passed
Unauthorized access detected and stopped, third-party security firm retained
Sep 29, 2026 Passed
Notice letters mailed, notice filed with California Attorney General
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Poppins Payroll to implement stronger data-security practices going forward, including improved oversight of third-party software vendors, timely patching of known vulnerabilities, and ongoing security testing.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Poppins Payroll. What should I do? +

Keep your Poppins Payroll notice letter, enroll in the free 24-month Experian IdentityWorks membership before the deadline stated in your letter, place a free fraud alert or security freeze with the three nationwide credit bureaus, review your bank statements and watch for unexpected IRS notices, document any time or money you spend responding to the breach, and consider speaking with a data breach attorney about your legal options.

Am I eligible to join a class action against Poppins Payroll? +

If you received a data breach notice from Poppins Payroll dated September 29, 2026, you are likely a candidate for a free case evaluation. Eligibility for any future legal action will also depend on your state of residence, the categories of your data that were involved, and any documented losses or out-of-pocket expenses, including time spent responding to identity-theft concerns.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The public version of the Poppins Payroll notice refers to personal information but does not itemize the specific data elements involved. Because household payroll providers can hold Social Security numbers, tax details, wage records, and bank account information for both employers and employees, review your own letter carefully for any details about what was involved for you.

Did Poppins Payroll offer free credit monitoring? +

Yes. Poppins Payroll is offering 24 months of complimentary Experian IdentityWorks membership, which includes daily three-bureau credit monitoring, dark web monitoring, identity restoration support, and up to $1 million in identity theft insurance. You must enroll before the deadline stated in your letter using the activation code it contains. Enrolling does not waive your right to pursue legal claims.

How many people were affected by the Poppins Payroll breach? +

Poppins Payroll has not publicly disclosed the total number of people affected. The notice confirms that Rhode Island residents were among those impacted but does not give a total. This page will be updated as more information becomes available.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

A copy of the Poppins Payroll notice letter is available through the California Attorney General's data breach website, linked in the Sources & References section below. If you received a letter but no longer have it, Dapeer Law can help you obtain a copy as part of a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Poppins Payroll Company, Experian IdentityWorks, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on September 29, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Next
Next

City of McMinnville Data Breach Lawsuit Investigation