Clustered 10 filings across 7 jurisdictions · filing window Apr 10, 2025 → Jun 17, 2025. View entity profile → Other incidents for this victim →
incident inc_a2c1df26a2d54d0f · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE IA IN OR SC TX
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
per-filing reported counts
State AGs report only their own residents; bars show per-filing counts.
Earliest sighting first · deep chronology in Litigation Timeline
10 filings across 7 jurisdictions · Apr 10, 2025 – Jun 17, 2025 · 3 milestones
Apr 1, 2023 → Apr 8, 2025
When the intrusion reportedly occurred, per the linked filings
Mar 14, 2025
Reported by OREGON AG, CALIFORNIA AG, TEXAS AG filings
Apr 8, 2025
Reported by DELAWARE AG, SOUTH CAROLINA AG, CALIFORNIA AG, TEXAS AG filings
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Lemonade Inc reported a data breach to the Indiana Attorney General. The breach occurred on 2023-04-01 and was reported on 2025-04-10. 1,861 Indiana residents were affected. 190,279 individuals affected in total.
Affected (this filing): 190,279
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor, who already possessed a name, DOB, and address, to retrieve a user's driver's license number via a third-party integration. The exposure occurred from approximately April 2023 through April 8, 2025. Lemonade mitigated the vulnerability and is offering 12 months of credit monitoring to affected individuals.
Lemonade, Inc. disclosed a vulnerability in its online car insurance application process that likely exposed driver's license numbers for identifiable individuals. The unauthorized exposures spanned from approximately April 2023 through September 2024. The company learned of the incident on March 14, 2025, and promptly eliminated the vulnerability. Affected individuals are being offered 12 months of complimentary identity protection and credit monitoring.
Lemonade, Inc. reported a data breach to the Oregon Attorney General. The breach was reported on 2025-04-11. The breach occurred during 4/1/2023 - 9/18/2024. The breach was discovered on 3/14/2025. 190,000 individuals were affected. Notice was sent on 4/10/2025.
Affected (this filing): 190,000
Lemonade, Inc. disclosed a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed a bad actor to obtain driver's license numbers of users who entered personal information into the system between April 2023 and April 8, 2025. The incident affected a small number of users across five states, including South Carolina. Lemonade mitigated the vulnerability and offered 12 months of complimentary credit monitoring and identity protection services to affected individuals.
Lemonade, Inc., a financial services sector entity reported a data breach to the Iowa Attorney General. The breach was reported on 2025-04-11.
Lemonade, Inc. based in New York, New York, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-03-14 and reported on 2025-04-11. 17,563 Texas residents were affected. 190,000 individuals affected in total. Types of information involved: Driver’s License number. Consumers were notified via U.S. Mail.
Affected (this filing): 17,563
Lemonade, Inc. disclosed a vulnerability in its online car insurance quote application ('Online Flow') discovered on April 8, 2025. The vulnerability, present since approximately April 2023, allowed bad actors who entered a name, date of birth, and address to potentially expose the corresponding driver's license number via a third-party integration. The incident affected a small number of users across five states. Lemonade mitigated the vulnerability and is offering 12 months of identity protection and credit monitoring to affected individuals.
Lemonade, Inc. notified Delaware AG of a security incident involving its car insurance quote application (Online Flow). A vulnerability allowed bad actors to input personal info (name, DOB, address) and receive a victim's driver's license number. The exposure period was April 2023 to April 8, 2025. Lemonade mitigated the vulnerability and offered 12 months of credit monitoring. No evidence of misuse was found.
Lemonade, Inc. based in New York, New York, a insurance services entity reported a data breach to the Texas Attorney General. The breach was discovered on 2025-04-08 and reported on 2025-06-17. 30 Texas residents were affected. 279 individuals affected in total. Types of information involved: Driver’s License number. Consumers were notified via U.S. Mail.
Affected (this filing): 30