DisclosureLens
HackingFinancial ServicesFinanceStolen CredentialsData ExfiltratedCustomer Data InvolvedGovernment IDIdentity (basic)HighContained

LEMONADE, INC.

bd_a20792f866647d69 · schema v1 · pii pii-v1

Severity

High

Discovered

Apr 8, 2025

Filed

Apr 11, 2025

To disclose

3 days

Affected

1,950state residents only

Linked

16 filings

Confidence

65%
Full breach record for LEMONADE, INC.2 incidents on file

Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor to obtain driver's license numbers of users who entered personal information into the system between April 2023 and April 8, 2025. The incident affected a small number of users across five states, including South Carolina. Lemonade mitigated the vulnerability and offered 12 months of complimentary credit monitoring and identity protection services to affected individuals.

South Carolina clock SC CRA notice due3 days discovery → filing
unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.

Incident timeline

undetected · 738 days
discovery → filing · 3 days

Apr 1, 2023

Begins

Apr 8, 2025

Discovered

Apr 11, 2025

Filed

vs. sector median

8 wks faster

This filing is one of 16 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (10) · sorted by filing gap

Show 6 more filingsup to 67d gap

Showing first 10 of 15 linked disclosures.

Filing propagation · 11 filings · 9 states

View merged incident ↗
California State AGApr 11 · first
Oregon State AGApr 11 · first
Iowa State AGApr 11 · first
South Carolina State AGApr 11 · first · this page

Pattern: first filing Apr 11 (CA), last Jun 17 (TX) — a 67-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Cascade drawn from the first 10 linked disclosures of 15 — the full spread may be wider.

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.