Lemonade, Inc. Data Breach Notice (Oregon Attorney General): What Was Exposed & What To Do
Lemonade, Inc. disclosed a data breach on April 11, 2025 that exposed personal information of approximately 190,000 individuals. The incident itself occurred on April 1, 2023; anyone who received notice or believes their data may be involved should review the details and take recommended protective steps.
A data breach involving Lemonade, Inc. has left as many as 190,000 people facing the practical question of whether their personal information is now in the wrong hands. The company notified Oregon residents through a filing with the Oregon Department of Justice, giving those individuals a concrete reason to review their accounts, watch for misuse, and take basic protective steps.
Public detail remains limited to what appears in that regulatory notice. The incident itself is dated April 1, 2023, while the filing was reported on April 11, 2025. What is known is that personal information was involved; what is not known in full public view is the precise method of intrusion, the full technical scope, or every category of record that may have been touched.
Inside the incident
According to the breach notice filed with the Oregon Attorney General’s office and reported to the Oregon Department of Justice on April 11, 2025, Lemonade, Inc. informed Oregon residents of a data breach. The same filing places the underlying incident on April 1, 2023. The notice states that approximately 190,000 people were affected and that the exposed material is described as personal information.
No further technical narrative—such as how systems were accessed, how long unauthorized access lasted, whether data was exfiltrated in bulk, or whether encryption or other controls limited exposure—is set out in the facts available from the disclosure. Timing between the incident date and the later regulatory filing is likewise unexplained in the public summary. Readers should treat only the reported figures, dates, and the broad “personal information” label as established from the notice; everything else about the attack path remains undisclosed.
How a breach like this happens
Incidents that result in notices about personal information commonly begin with one of a small set of familiar weaknesses, though none of these should be assumed to be the cause in this specific case. Attackers often obtain initial access through stolen or guessed credentials, phishing that tricks an employee into revealing login details, unpatched software vulnerabilities, or misconfigured cloud storage and remote-access services. Once inside, they may move laterally, locate databases or document stores that hold customer or applicant records, and copy data for later use or sale.
In other cases, a third-party vendor with legitimate access becomes the entry point, or ransomware operators encrypt systems and also steal data to increase pressure. Organizations typically discover the problem through internal monitoring, law-enforcement tips, or external notifications, then investigate, contain the intrusion, and determine who must be notified under state breach laws. Because no threat group or precise technique is attributed in the Lemonade filing, any description of method for this event would be speculation; the pattern above is general background only.
Lemonade, Inc. and its sector
Lemonade, Inc. is known publicly as a technology-focused insurer that offers personal lines such as renters, homeowners, pet, and related coverage, often through app-based and online channels. Insurers in this sector routinely collect and retain information needed to quote policies, underwrite risk, process claims, and meet regulatory and anti-fraud requirements. That typically includes identifying details, contact data, property or asset information, payment-related records, and sometimes supporting documents or claim narratives.
A breach affecting an insurer is consequential because the relationship is long-running: policies renew, claims may span months or years, and the company may hold data on applicants who never became customers as well as on current and former policyholders. Even when only a subset of records is confirmed exposed, the sector’s concentration of identity-linked and financial-adjacent information raises the stakes for anyone whose file may have been involved. The Oregon notice does not itself allege fault or describe security posture; it simply records that a notifiable event occurred and that a large number of people were potentially affected.
The information in question
The breach notification names the exposed material as personal information. It does not, in the facts provided, itemize fields such as Social Security numbers, driver’s license numbers, bank account details, medical data, or specific claim documents. For an organization of this type, personal information in the ordinary course of business can include names, addresses, dates of birth, email addresses, phone numbers, policy identifiers, and other data used to administer insurance relationships—but those categories are not confirmed as part of this incident’s exposed set.
Exact contents therefore remain unconfirmed beyond the broad label in the notice. Affected individuals should not assume either the best or worst case; they should treat the possibility of identity-related misuse seriously while recognizing that public detail stops at “personal information” as stated in the filing.
What's at stake
For people whose data may have been involved, the concrete risks include targeted phishing that references a real insurer relationship, attempts to open new credit or accounts in their name, fraud against existing financial relationships, and long-term exposure if identifiers that do not change easily were among the records. Even limited personal information can be combined with data from other breaches to make social-engineering attacks more convincing. Monitoring and early detection matter more than panic.
For Lemonade, Inc., the stakes include regulatory follow-up, the cost of investigation and notification, potential civil claims, and erosion of customer trust in a business that depends on people sharing sensitive details to obtain coverage. The two-year gap between the stated incident date and the Oregon filing date, as reported, may also prompt questions from customers and regulators about discovery and notification timelines, though the public summary does not explain that interval.
What to do if you're exposed
If you have been a Lemonade customer, applicant, or otherwise received a breach notice, start with the basics: read any official letter carefully for what it says was involved and what free services, if any, the company is offering. Place a fraud alert or credit freeze with the major credit bureaus if you are concerned about new-account fraud; review credit reports and bank and insurance statements for unfamiliar activity; and be skeptical of unexpected calls, texts, or emails that claim to be from Lemonade or about a claim or refund. Change passwords on related accounts, enable multi-factor authentication where available, and keep records of any suspicious contacts.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, which can help you prioritize further monitoring. If you believe you are a victim of identity theft, report it to the Federal Trade Commission and consider filing a police report. Stay alert over time—misuse of personal information does not always appear immediately—and rely on official company or regulator communications rather than unsolicited offers of help.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Decisely Insurance Services Data Breach Notice (Oregon Attorney General)Apro, LLC d/b/a United Pacific Data Breach Notice (Oregon Attorney General)Apro, LLC d/ Data Breach Notice (Oregon Attorney General)CareOregon Data Breach Notice (Oregon Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.