HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
LEMONADE, INC.
bd_5dcd5abd140186b2 · schema v1 · pii pii-v1
Full breach record for LEMONADE, INC. →Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor, who already possessed a name, DOB, and address, to retrieve a user's driver's license number via a third-party integration. The exposure occurred from approximately April 2023 through April 8, 2025. Lemonade mitigated the vulnerability and is offering 12 months of credit monitoring to affected individuals.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_16c248d2b9cddae7Indiana State AGfiled 2025-04-10Verified
- bd_5083a89f0a03f74eCalifornia State AGfiled 2025-04-11(1d gap)Verified
- bd_509afcd072ce27cdOregon State AGfiled 2025-04-11(1d gap)Candidate
- bd_a20792f866647d69South Carolina State AGfiled 2025-04-11(1d gap)Verified
Show 5 more filings ↓Show fewer ↑up to 68d gap
- bd_c499fb305e941f00Iowa State AGfiled 2025-04-11(1d gap)Verified
- bd_d8eba2a22408f594Texas State AGfiled 2025-04-11(1d gap)Verified
- bd_9c31feadbbc4c6d6California State AGfiled 2025-06-12(63d gap)Verified
- bd_f35592cfa8a8894dDelaware State AGfiled 2025-06-13(64d gap)Verified
- bd_d0fb196ee08df9c1Texas State AGfiled 2025-06-17(68d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/06/Lemonade-Inc.-Individual-Notice-Version-1-Wave-2.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 10, 2025
- Raw hash
- b8371ced1afd57800fab6a87ebaa3756bfd3f2e32c1c338ee2a40630067f573c
Reporting entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Victim entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Incident
- Discovered
- Apr 8, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 2 days(2 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.