CSIDB logo
Incident

Lemonade

Incident posture

Attack window
Apr 2023
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-26 05:58

Linked entities

Victim
Lemonade
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2023
Discovered
Mar 2025
Disclosed
Apr 2025
Resolved
Sep 2026

Summary

Lemonade’s online auto insurance quote tool exposed driver’s license numbers of up to 190,644 individuals to third parties through a security flaw that allowed any visitor to retrieve personal data without verification. The exposure persisted for over a year before being discovered, leading to a class action lawsuit alleging violations of privacy statutes and resulting in a $10.5 million settlement that provides claim payments, identity theft protection, and required security improvements. The court noted the insurer’s limited profitability as a factor supporting the settlement’s fairness, and the agreement includes attorney fees and mandatory changes to prevent future misuse.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Lemonade’s online auto insurance quote platform used the name, date of birth and address entered by a visitor, combined with data the company already possessed or could obtain from third‑party brokers, to automatically pre‑fill driver’s license information. The feature operated as a lookup tool that allowed anyone who entered a name and address to receive a driver’s license number without verification of entitlement, and Lemonade lacked effective controls to distinguish human visitors from bots. This vulnerability exposed the license numbers of as many as 190,644 drivers for a period of seventeen months, beginning in April 2023 and continuing through September 2024. Lemonade did not identify the flaw until March 2025, nearly two years after the exposure began, and did not send breach notification letters to affected individuals until April 2025. Three plaintiffs from New York, Connecticut and Arizona filed a consolidated class action on behalf of themselves and others who had never applied for or purchased insurance from Lemonade, alleging that the company’s practices violated the Driver’s Privacy Protection Act, state business laws, unfair trade practices statutes and Federal Trade Commission data security guidelines.

The federal district court in the Southern District of New York approved a $10.5 million class action settlement in September 2026, allocating one‑third of the fund, or $3.5 million, to attorneys’ fees. The settlement class includes anyone whose license number was made available through the quoting platform, regardless of whether they were Lemonade customers or had ever sought a quote. Class members may submit claims for documented losses up to $10,000 each and/or receive a pro rata cash payment from the remaining fund, and they are entitled to three years of identity theft protection and credit monitoring from the three major credit bureaus. Judge Katharine H. Parker noted that Lemonade, described as a new and not yet profitable company, faced limited ability to absorb a larger judgment, making the early settlement reasonable and fair; she also observed that continued litigation would increase costs and prolong a case already underway for about a year. The court had previously preliminarily approved the settlement and conditionally certified the class in May 2026. In addition to the monetary fund, Lemonade agreed to implement security enhancements and procedural changes to better protect personal data.

As part of the settlement’s impact, affected individuals can seek compensation for documented harms and receive ongoing credit monitoring, while Lemonade’s commitments aim to prevent similar exposures in the future. The case follows a 2024 $5 million settlement in which Lemonade resolved allegations of improperly sharing life insurance applicants’ personal and health‑related information with social media platforms. Separately, New York State imposed penalties exceeding $19 million on eight auto insurance providers in 2025 for inadequate cybersecurity controls that allowed theft of driver’s license numbers from online quoting applications, and the state attorney general secured additional fines from Root, GEICO, Travelers and Noblr for comparable data‑protection failures. These related actions underscore the broader regulatory scrutiny of quoting‑platform security practices across the insurance industry.

Sources

Sources available to members: 1 source.

CSIDB