A data breach at Poppins Payroll Company involved Social Security numbers, financial account information, and credit or debit card information. At least 333 Vermont residents are affected, and the company has not said how many people were affected nationwide.
Poppins Payroll Company is a Boulder, Colorado company that runs payroll and household tax filing for families who employ nannies, caregivers, and other household workers. On September 30, 2026, the Vermont Attorney General’s Office posted a security breach notice from Poppins Payroll. According to that filing, the breach affected 333 Vermont residents.
The Vermont listing states that the information involved included Social Security numbers, financial account information, and credit or debit card information. As of this writing, Poppins Payroll has not publicly explained how the breach happened, when it started, or when the company discovered it.
Why a Payroll Company Breach Carries Extra Risk
A payroll company holds the exact records needed to pay a worker and file taxes. That usually means Social Security numbers and bank account details. When those two items leak together, criminals have what they need to open new accounts, file fake tax returns, or try to move money.
Poppins Payroll serves two groups: the families who hire household help, and the nannies and caregivers who get paid through the platform. The Vermont filing does not say whether the affected people are employers, workers, or both. Anyone who has used Poppins Payroll in either role may want to watch closely for a notice letter.
How Many People Were Affected by the Poppins Payroll Breach?
Poppins Payroll has not disclosed the total number of people affected. The Vermont filing counts 333 Vermont residents. That figure covers only one small state, so the national total may be higher. This post will be updated if Poppins Payroll or another state attorney general releases a larger count.
What Information Was Exposed?
Based on the Vermont Attorney General filing, the compromised information includes:
- Social Security numbers
- Financial account information
- Credit or debit card information
The filing does not list other data types. People who receive a letter should read it closely, since individual letters sometimes list more detail.
What Is Poppins Payroll Offering Affected Individuals?
Poppins Payroll has not publicly posted details of any credit monitoring or identity protection offer. Affected individuals should check their notice letter for any enrollment code, deadline, or support phone number.
What Poppins Payroll Customers and Workers Can Do Now
Exposed Social Security numbers and bank details can be used long after a breach ends. Affected individuals can take these steps:
- Place a free credit freeze with Equifax, Experian, and TransUnion.
- Request an IRS Identity Protection PIN to help block fake tax returns filed with a stolen Social Security number.
- Review bank and card statements for charges or transfers you do not recognize.
- Ask the bank about replacing any card or account number listed in your letter.
- Watch for emails, texts, or calls that mention Poppins Payroll and ask for passwords or payment.
Do You Have Legal Options?
Payroll companies collect Social Security numbers and bank information because they must. With that data comes a legal duty to protect it. When that duty is not met, affected individuals may have legal rights and remedies worth discussing with an attorney.
Emery | Reddy is investigating the Poppins Payroll data breach. There is No Fee Unless We Recover.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage payroll and financial data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
FAQ
How many people were affected by the Poppins Payroll data breach?
Poppins Payroll has not released a total. A filing with the Vermont Attorney General lists 333 Vermont residents. The total across all states is not known yet.
What information was exposed?
According to the Vermont filing, the breach involved:
- Social Security numbers
- Financial account information
- Credit or debit card information
I’m a nanny or caregiver paid through Poppins. Could my information be involved?
Possibly. Poppins Payroll processes pay for household workers as well as the families who employ them. The public filing does not say which group was affected. If you get a letter, keep it and read which information it lists for you.
When did the breach happen?
Poppins Payroll has not publicly shared when the breach started or when it was found. The Vermont notice was posted on September 30, 2026.
What should I do if I received a notification letter?
- Keep the letter and the envelope.
- Freeze your credit with all three credit bureaus.
- Get an IRS Identity Protection PIN.
- Check your bank and card accounts often.
- Enroll in any monitoring the letter offers, if it offers any.
How can I protect myself from scams that mention the breach?
Criminals often send fake follow-up messages after a breach makes the news. They may use the company’s name to seem real. Do not click links or give out information in a message you did not expect. Contact the company using a phone number or website you already know is real.
Do I have a legal claim?
Companies that collect your Social Security number and bank information have a duty to protect it and to tell you promptly when it is exposed. If Poppins Payroll fell short, you may have rights. Contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.