Poppins Payroll breach exposes SSNs and financial data, prompting lawsuits and credit safeguards
Poppins Payroll revealed a breach that may have leaked customers' Social Security numbers, birth dates and bank details, sparking class-action investigations.
Poppins Payroll, a platform that helps families pay household employees, announced that a security breach may have compromised personal data of tens of thousands of users. The intrusion, discovered on September 3, involved unauthorized access via a flaw in Metabase, a data-visualisation tool the company employs. In letters sent on September 29, Poppins warned that Social Security numbers, birth dates and financial account numbers could have been exposed, though no fraud has yet been detected.
The firm is providing two years of credit-monitoring and identity-protection services and recommends credit freezes with the major bureaus and an IRS Identity Protection PIN. Cybersecurity experts highlighted the risk of the extensive data set for identity theft and warned of possible follow-up scams. Law firms such as Edelson Lechtzin LLP have opened investigations into a class-action lawsuit against Poppins.
Why it matters
The breach endangers sensitive personal data of many families, increasing identity-theft risk and prompting potential legal action.
In this story
