LEMONADE, INC.
ent_019e61a2d2278a7d309e512b41feb1d2
Disclosures
10
State AG · 7 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
190,279
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- LEMONADE, INC.
- Normalized
- lemonade— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493009BKR06OXXU6853
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (10)newest first
- ⭐Texas State AGas victim2025-06-17
Lemonade, Inc. based in New York, New York, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-08 and reported on 2025-06-17. 30 Texas residents were affected. 279 individuals affected in total. Types of information involved: Driver’s License number. Consumers were notified via U.S. Mail.
- 💎Delaware State AGas victim2025-06-13
Lemonade, Inc. notified Delaware AG of a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed bad actors to input personal info (name, DOB, address) and receive a victim's driver's license number. The exposure period was April 2023 to April 8, 2025. Lemonade mitigated the vulnerability and offered 12 months of credit monitoring. No evidence of misuse was found.
- 🐻California State AGas victim2025-06-12
Lemonade, Inc. disclosed a vulnerability in its online car insurance quote application ('Online Flow') discovered on April 8, 2025. The vulnerability, present since approximately April 2023, allowed bad actors who entered a name, date of birth, and address to potentially expose the corresponding driver's license number via a third-party integration. The incident affected a small number of users across five states. Lemonade mitigated the vulnerability and is offering 12 months of identity protection and credit monitoring to affected individuals.
- 🐻California State AGas victim2025-04-11
Lemonade, Inc. disclosed a vulnerability in its online car insurance application process that likely exposed driver's license numbers for identifiable individuals. The unauthorized exposures spanned from approximately April 2023 through September 2024. The company learned of the incident on March 14, 2025, and promptly eliminated the vulnerability. Affected individuals are being offered 12 months of complimentary identity protection and credit monitoring.
- 🦫Oregon State AGas victim2025-04-11
Lemonade, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-04-11. The breach occurred during 4/1/2023 - 9/18/2024. The breach was discovered on 3/14/2025. 190,000 individuals were affected. Notice was sent on 4/10/2025.
- 🌴South Carolina State AGas victim2025-04-11
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor to obtain driver's license numbers of users who entered personal information into the system between April 2023 and April 8, 2025. The incident affected a small number of users across five states, including South Carolina. Lemonade mitigated the vulnerability and offered 12 months of complimentary credit monitoring and identity protection services to affected individuals.
- 🌽Iowa State AGas victim2025-04-11
Lemonade, Inc., a financial services sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-04-11.
- ⭐Texas State AGas victim2025-04-11
Lemonade, Inc. based in New York, New York, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-03-14 and reported on 2025-04-11. 17,563 Texas residents were affected. 190,000 individuals affected in total. Types of information involved: Driver’s License number. Consumers were notified via U.S. Mail.
- 🏎️Indiana State AGas victim2025-04-10
Lemonade Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-04-01 and was reported on 2025-04-10. 1,861 Indiana residents were affected. 190,279 individuals affected in total.
- 💎Delaware State AGas victim2025-04-10
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor, who already possessed a name, DOB, and address, to retrieve a user's driver's license number via a third-party integration. The exposure occurred from approximately April 2023 through April 8, 2025. Lemonade mitigated the vulnerability and is offering 12 months of credit monitoring to affected individuals.