sözaltı news Politics
Politics
EN AZ
Why Poppins Payroll Data Breach Is Particularly Concerning

Why Poppins Payroll Data Breach Is Particularly Concerning

newsweek.com 05.10.2026 23:05 4 views
Poppins Payroll's data breach could leave people's information at risk of being stolen and used for years.

Poppins Payroll, a household employee payroll company, informed customers last week of a serious data breach that may have exposed a lot of their personal information to cyber criminals, and lawyers are now looking into a potential class-action lawsuit. Poppins is a popular payroll company used by parents to pay their nanny on the books and more than 65,000 families have used the service since it started in 2016. It's unclear exactly how many people were potentially impacted by the data breach, but it has the potential to impact tens of thousands of customers.

In a letter to customers, the company informed them that their Social Security numbers, birth dates and financial account numbers may have been compromised. The letters were sent on September 29, a few weeks after the breach was detected by the company. Zachary Lewis, chief information security officer and data protection officer at the University of St.

Louis Health Sciences & Pharmacy school, told Newsweek it's always "serious" when someone's Social Security number is exposed, but many Americans likely already had theirs compromised in previous breaches. On September 3, the company detected that a third party had gained unauthorized access to customers' information through a security vulnerability in Metabase, a software vendor the company uses. Metabase gives companies a means of analyzing and visualizing data.

Brad LaPorte, a cybersecurity analyst, told Newsweek that the amount of information that was potentially compromised is particularly concerning because a payroll company holds "everything a criminal needs to become you." In the letter, Poppins told customers that the company didn't have evidence their information was used to commit financial fraud or identity theft. However, information isn't always immediately used once it's stolen and Poppins offered customers two years of credit monitoring and identity protection. "An absence of immediate fraud does not mean the information will never be used.

We've seen instances of threat actors sitting on this information for years before it gets used," Lewis said. Along with the enhanced credit monitoring, Lewis told impacted customers to consider a credit freeze with Equifax, Experian and TransUnion, the three major credit bureaus. It makes it harder for someone to open a credit account in their name and can be lifted if the person wants to apply for credit.

While some users on Reddit suggested closing the bank account connected to Poppins and opening a new one, Lewis said that may be unnecessary. Instead, he said people should contact their bank's fraud department to determine whether replacing the account or adding other protections is appropriate. Since it's possible that federal tax information was exposed, Lewis encouraged people to get an IRS Identity Protection Pin because it helps prevent someone from filing a federal income tax return using someone else's Social Security number.

Extract — continue reading at the source.

Read full story