LEMONADE, INC.
ent_21f7d76e09764ac21d94b4b2
Disclosures
17
State AG · 11 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
190,279
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- LEMONADE, INC.
- Normalized
- lemonade— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 5493009BKR06OXXU6853
- SEC EDGAR CIK
- 0001691421
- Domain
- lemonade.com
Disclosure history (17)newest first
- Rhode Island State AGas victim2025-06-17
Lemonade, Inc. filed a supplemental breach notification with the Rhode Island Attorney General regarding a vulnerability in its car insurance quoting system. The vulnerability exposed driver's license numbers in browser source code from approximately April 2023 through April 8, 2025. Approximately 2,313 Rhode Island residents were affected. Lemonade shut down the affected flow, fixed the vulnerability, and notified residents, offering 12 months of credit monitoring.
- Texas State AGas victim2025-06-17
Lemonade, Inc. based in New York, New York, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-08 and reported on 2025-06-17. 30 Texas residents were affected. 279 individuals affected in total. Types of information involved: Driver’s License number. Consumers were notified via U.S. Mail.
- Nebraska State AGas victim2025-06-13
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed unauthorized access to driver's license numbers for users in five states, including Nebraska, between April 2023 and April 8, 2025. Lemonade discovered and mitigated the vulnerability on April 8, 2025, and is offering 12 months of credit monitoring to affected individuals. No evidence of misuse was found.
- Delaware State AGas victim2025-06-13
Lemonade, Inc. notified Delaware AG of a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed bad actors to input personal info (name, DOB, address) and receive a victim's driver's license number. The exposure period was April 2023 to April 8, 2025. Lemonade mitigated the vulnerability and offered 12 months of credit monitoring. No evidence of misuse was found.
- California State AGas victim2025-06-12
Lemonade, Inc. disclosed a vulnerability in its online car insurance quote application ('Online Flow') discovered on April 8, 2025. The vulnerability, present since approximately April 2023, allowed bad actors who entered a name, date of birth, and address to potentially expose the corresponding driver's license number via a third-party integration. The incident affected a small number of users across five states. Lemonade mitigated the vulnerability and is offering 12 months of identity protection and credit monitoring to affected individuals.
- Rhode Island State AGas victim2025-04-14
Lemonade, Inc. notified the Rhode Island Attorney General of a data breach affecting approximately 2,300 state residents. Between April 2023 and September 2024, bad actors exploited a vulnerability in Lemonade's car insurance online application flow to access driver's license numbers. Lemonade eliminated the vulnerability, notified affected individuals, and offered 12 months of credit monitoring.
- Massachusetts State AGas victim2025-04-12
Lemonade, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2025-04-12. 32,801 Massachusetts residents were affected.
- California State AGas victim2025-04-11
Lemonade, Inc. disclosed a vulnerability in its online car insurance application process that likely exposed driver's license numbers for identifiable individuals. The unauthorized exposures spanned from approximately April 2023 through September 2024. The company learned of the incident on March 14, 2025, and promptly eliminated the vulnerability. Affected individuals are being offered 12 months of complimentary identity protection and credit monitoring.
- Oregon State AGas victim2025-04-11
Lemonade, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-04-11. The breach occurred during 4/1/2023 - 9/18/2024. The breach was discovered on 3/14/2025. 190,000 individuals were affected. Notice was sent on 4/10/2025.
- South Carolina State AGas victim2025-04-11
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor to obtain driver's license numbers of users who entered personal information into the system between April 2023 and April 8, 2025. The incident affected a small number of users across five states, including South Carolina. Lemonade mitigated the vulnerability and offered 12 months of complimentary credit monitoring and identity protection services to affected individuals.
- Iowa State AGas victim2025-04-11
Lemonade, Inc. notified Iowa AG of unauthorized access to driver's license numbers for ~750 Iowa residents. Bad actors used stolen credentials to exploit a vulnerability in the car insurance quote flow (April 2023–Sept 2024). Lemonade patched the vulnerability, contained the incident, and offered 12 months of credit monitoring.
- Texas State AGas victim2025-04-11
Lemonade, Inc. based in New York, New York, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-03-14 and reported on 2025-04-11. 17,563 Texas residents were affected. 190,000 individuals affected in total. Types of information involved: Driver’s License number. Consumers were notified via U.S. Mail.
- Indiana State AGas victim2025-04-10
Lemonade Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-04-01 and was reported on 2025-04-10. 1,861 Indiana residents were affected. 190,279 individuals affected in total.
- Delaware State AGas victim2025-04-10
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor, who already possessed a name, DOB, and address, to retrieve a user's driver's license number via a third-party integration. The exposure occurred from approximately April 2023 through April 8, 2025. Lemonade mitigated the vulnerability and is offering 12 months of credit monitoring to affected individuals.
- Nebraska State AGas victim2025-04-10
Lemonade, Inc. disclosed a security incident involving its online insurance application flow (www.lemonade.com/car). A vulnerability in the Online Flow allowed unauthorized access to driver's license numbers for identifiable individuals. The exposure period spanned from approximately April 2023 through September 2024. Lemonade discovered the vulnerability on March 14, 2025, eliminated it, and is providing 12 months of complimentary credit monitoring and identity protection services to affected individuals. No evidence of misuse was found.
- Illinois State AGas victim2025-04-01
LEMONADE, INC. filed a data-breach notice with the Illinois Attorney General in April 2025 (case 25-04-082). The register records the breach as discovered on March 14, 2025. Personal information types reported: drivers license. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Indiana State AGas victim2022-10-28
Lemonade Insurance Company reported a data breach to the Indiana Attorney General. The breach occurred on 2022-09-28 and was reported on 2022-10-28. 2 Indiana residents were affected. 200 individuals affected in total.