HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
LEMONADE, INC.
bd_a20792f866647d69 · schema v1 · pii pii-v1
Full breach record for LEMONADE, INC. →Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor to obtain driver's license numbers of users who entered personal information into the system between April 2023 and April 8, 2025. The incident affected a small number of users across five states, including South Carolina. Lemonade mitigated the vulnerability and offered 12 months of complimentary credit monitoring and identity protection services to affected individuals.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_5083a89f0a03f74eCalifornia State AGfiled 2025-04-11Verified
- bd_509afcd072ce27cdOregon State AGfiled 2025-04-11Candidate
- bd_c499fb305e941f00Iowa State AGfiled 2025-04-11Verified
- bd_d8eba2a22408f594Texas State AGfiled 2025-04-11Verified
Show 5 more filings ↓Show fewer ↑up to 67d gap
- bd_16c248d2b9cddae7Indiana State AGfiled 2025-04-10(1d gap)Verified
- bd_5dcd5abd140186b2Delaware State AGfiled 2025-04-10(1d gap)Verified
- bd_9c31feadbbc4c6d6California State AGfiled 2025-06-12(62d gap)Verified
- bd_f35592cfa8a8894dDelaware State AGfiled 2025-06-13(63d gap)Verified
- bd_d0fb196ee08df9c1Texas State AGfiled 2025-06-17(67d gap)Verified
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Individual%20Notice%20(Version%201)%20Wave%202.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 11, 2025
- Raw hash
- 5096ebdadccc7fb385ec25cb507453b4a85500e57c2b2ab36b7a3bc683cf800e
Reporting entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Victim entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Incident
- Discovered
- Apr 8, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 3 days(3 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.