AccidentalMisconfigurationCustomer Data InvolvedDelayed DiscoveryIDENTITY_GOVERNMENTMediumContained
LEMONADE, INC.
bd_9c31feadbbc4c6d6 · schema v1 · pii pii-v1
Full breach record for LEMONADE, INC. →Lemonade, Inc. disclosed a vulnerability in its online car insurance quote application ('Online Flow') discovered on April 8, 2025. The vulnerability, present since approximately April 2023, allowed bad actors who entered a name, date of birth, and address to potentially expose the corresponding driver's license number via a third-party integration. The incident affected a small number of users across five states. Lemonade mitigated the vulnerability and is offering 12 months of identity protection and credit monitoring to affected individuals.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_f35592cfa8a8894dDelaware State AGfiled 2025-06-13(1d gap)Verified
- bd_d0fb196ee08df9c1Texas State AGfiled 2025-06-17(5d gap)Verified
- bd_5083a89f0a03f74eCalifornia State AGfiled 2025-04-11(62d gap)Verified
- bd_509afcd072ce27cdOregon State AGfiled 2025-04-11(62d gap)Candidate
Show 5 more filings ↓Show fewer ↑up to 63d gap
- bd_a20792f866647d69South Carolina State AGfiled 2025-04-11(62d gap)Verified
- bd_c499fb305e941f00Iowa State AGfiled 2025-04-11(62d gap)Verified
- bd_d8eba2a22408f594Texas State AGfiled 2025-04-11(62d gap)Verified
- bd_16c248d2b9cddae7Indiana State AGfiled 2025-04-10(63d gap)Verified
- bd_5dcd5abd140186b2Delaware State AGfiled 2025-04-10(63d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-603991
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 12, 2025
- Raw hash
- d76645cad2281d356dc9c2a8bde8cbae0424e689fb201c507aef97000016f72b
Reporting entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Victim entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Incident
- Discovered
- Apr 8, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENT
- Attack vector
- Misconfiguration
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- Filed breach notification with California Attorney General
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(65 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.