AccidentalMisconfigurationCustomer Data InvolvedIDENTITY_GOVERNMENTMediumContained
LEMONADE, INC.
bd_5083a89f0a03f74e · schema v1 · pii pii-v1
Full breach record for LEMONADE, INC. →Lemonade, Inc. disclosed a vulnerability in its online car insurance application process that likely exposed driver's license numbers for identifiable individuals. The unauthorized exposures spanned from approximately April 2023 through September 2024. The company learned of the incident on March 14, 2025, and promptly eliminated the vulnerability. Affected individuals are being offered 12 months of complimentary identity protection and credit monitoring.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_509afcd072ce27cdOregon State AGfiled 2025-04-11Candidate
- bd_a20792f866647d69South Carolina State AGfiled 2025-04-11Verified
- bd_c499fb305e941f00Iowa State AGfiled 2025-04-11Verified
- bd_d8eba2a22408f594Texas State AGfiled 2025-04-11Verified
Show 5 more filings ↓Show fewer ↑up to 67d gap
- bd_16c248d2b9cddae7Indiana State AGfiled 2025-04-10(1d gap)Verified
- bd_5dcd5abd140186b2Delaware State AGfiled 2025-04-10(1d gap)Verified
- bd_9c31feadbbc4c6d6California State AGfiled 2025-06-12(62d gap)Verified
- bd_f35592cfa8a8894dDelaware State AGfiled 2025-06-13(63d gap)Verified
- bd_d0fb196ee08df9c1Texas State AGfiled 2025-06-17(67d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-601295
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- a633a1c9c309e8358b61ab05a68b6fd8f5d11a1ce916253338ceef57d35e7dce
Reporting entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Victim entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Incident
- Discovered
- Mar 14, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENT
- Attack vector
- Misconfiguration
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.