HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICMediumContained
LEMONADE, INC.
bd_f35592cfa8a8894d · schema v1 · pii pii-v1
Full breach record for LEMONADE, INC. →Lemonade, Inc. notified Delaware AG of a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed bad actors to input personal info (name, DOB, address) and receive a victim's driver's license number. The exposure period was April 2023 to April 8, 2025. Lemonade mitigated the vulnerability and offered 12 months of credit monitoring. No evidence of misuse was found.
This filing is one of 10 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (9) · sorted by filing gap
- bd_9c31feadbbc4c6d6California State AGfiled 2025-06-12(1d gap)Verified
- bd_d0fb196ee08df9c1Texas State AGfiled 2025-06-17(4d gap)Verified
- bd_5083a89f0a03f74eCalifornia State AGfiled 2025-04-11(63d gap)Verified
- bd_509afcd072ce27cdOregon State AGfiled 2025-04-11(63d gap)Candidate
Show 5 more filings ↓Show fewer ↑up to 64d gap
- bd_a20792f866647d69South Carolina State AGfiled 2025-04-11(63d gap)Verified
- bd_c499fb305e941f00Iowa State AGfiled 2025-04-11(63d gap)Verified
- bd_d8eba2a22408f594Texas State AGfiled 2025-04-11(63d gap)Verified
- bd_16c248d2b9cddae7Indiana State AGfiled 2025-04-10(64d gap)Verified
- bd_5dcd5abd140186b2Delaware State AGfiled 2025-04-10(64d gap)Verified
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2025/06/Lemonade-Inc.-Individual-Notice-Version-1-Wave-2.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 13, 2025
- Raw hash
- eda6b4feea8af17148be63cdbf9ea40cf60bfe1888abb8c4d08ae3e42555884b
Reporting entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Victim entity
- Name
- LEMONADE, INC.norm: lemonade
- Domain
- lemonade.com
Incident
- Discovered
- Apr 8, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 9 weeks(66 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.