← Blog

Poppins Payroll Breach: Metabase Flaw Hits Household SSNs

Share on X

Boulder-based Poppins Payroll — household payroll for nannies and caregivers — disclosed that on September 3, 2026 an intruder exploited a vulnerability in Metabase to reach a company system the same day. Exposed data may include SSNs, financial account codes, and credit/debit information. California and Vermont AG notices began ~September 29; Vermont’s filing identifies 333 residents (used as best available regulator floor; nationwide total may be higher).

Canonical: https://breachhistory.com/poppins-payroll/poppins-payroll2026.

What happened

Per Claim Depot’s summary of state filings and company notice language: discovery and intrusion on Sep 3 via Metabase; 24 months Experian IdentityWorks offered. Household employers and their workers both sit in scope when a payroll SaaS is hit.

Action items

  1. Enroll in Experian using letter codes.
  2. Freeze credit for household employers and employees if SSNs exposed.
  3. Watch tax-season and nanny-payroll phishing.
  4. Rotate any reused portal passwords.

Sources

Open questions and verification posture

Week-one reporting rarely includes full malware forensics. Separate victim/regulator facts from actor marketing. Missing headcounts stay zero in the catalog until a filing appears. That discipline keeps BreachHistory usable when headlines inflate.

Phishing to expect

Lookalike domains, fake incident-response WhatsApp accounts, and urgency around fake enrollment deadlines. Call numbers printed on official letters only. Do not install remote-support tools from cold callers. Do not pay crypto to strangers.

Neighboring incidents

Cross-read related BreachHistory finance, education, healthcare, and ransomware-claim posts for pattern recognition — shared vendor risk and delayed consumer mailings recur through 2026. Use comparisons for briefings, not to copy unverified counts across rows.

Security-team checklist

  1. Inventory non-core systems holding identifiers.
  2. Phishing-resistant MFA on those systems.
  3. Log/alert bulk exports.
  4. Pre-draft counsel-approved notices.
  5. Tabletop a 72-hour extortion email with legal and PR.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.

Readers should treat primary notices and reputable press as the source of truth, bookmark the canonical BreachHistory URL for updates, freeze credit when SSNs or national IDs are in scope, and ignore cryptocurrency “deletion” scams. Security teams should inventory non-core tools that still hold identity data, enforce phishing-resistant MFA, alert on bulk exports, and pre-draft customer notices. Journalists must label unverified leak-site claims clearly and avoid Breachsense. Household members should be briefed so secondary phishing aimed at relatives fails. When regulators revise censuses, return to the canonical link rather than viral screenshots.