Poppins Payroll Data Breach Exposed Sensitive User Records
A security vulnerability in Metabase software allowed unauthorized access to sensitive financial and personal data.
Updated on Oct. 5, 2026 in Cybersecurity

Live Poll
Do you trust your payroll provider to keep your Social Security number and financial data secure?
Poppins Payroll detected unauthorized access to its systems on September 3, 2026, which resulted in the exposure of customer Social Security numbers, birth dates, and financial records. The company confirmed that a vulnerability in Metabase software facilitated the breach affecting its users across the United States.
Why it matters
The breach highlights the risks associated with third-party software vulnerabilities, particularly for services managing highly sensitive family financial data. It has prompted legal investigations into potential class-action litigation as impacted families assess the scope of the exposure.
The incident involved unauthorized access via a Metabase software vulnerability. The company waited 26 days between initial detection on September 3, 2026, and the issuance of notification letters on September 29, 2026.
The players
Poppins Payroll
A service provider that has managed payroll and financial records for more than 65,000 families since 2016.
Metabase
An open-source business intelligence software platform used to query and visualize data sets.
The details
The breach occurred when an unauthorized third party exploited a security vulnerability within Metabase—a business intelligence tool used for data visualization and analytics. This access allowed the actor to bypass security controls and reach sensitive personal files, including Social Security numbers and financial account information. While the company notified state regulators immediately upon identifying the intrusion, customers were not alerted until 26 days after the initial detection.
Timeline
2016: Poppins Payroll began operations serving families across the United States.
September 3, 2026: The company detected unauthorized third-party access to its systems.
September 29, 2026: Notification letters were sent to impacted customers.
The Tech Race
This event follows a pattern of security incidents involving known vulnerabilities in the Metabase software platform. It underscores the ongoing challenge of securing BI tools that serve as central nodes for sensitive customer data.
Impacted customers have been offered two years of credit monitoring services to mitigate the risks associated with the exposure of their personal identity markers. Affected individuals should monitor their financial statements closely for unauthorized activity resulting from the leaked account information.
The takeaway
The event highlights the necessity of maintaining rigorous patch management protocols for third-party BI software. Impacted users should monitor for updates from legal counsel regarding the announced class-action investigations.
Further reading
For broader analysis on protecting sensitive financial infrastructure, visit Cybersecurity.
Source note: This article includes information reported by Newsweek.
Live Poll
Do you trust your payroll provider to keep your Social Security number and financial data secure?








