Application Security

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

Lemonade says the incident is not material and that its operations were not compromised, nor was its customer data targeted.

Lemonade says the incident is not material and that its operations were not compromised, nor was its customer data targeted.

Insurance firm Lemonade is notifying roughly 190,000 individuals that their driver’s license numbers were likely exposed due to a technical glitch.

Copies of the notification letter that were submitted to regulators in several states show that the incident involved an online application that enables individuals to obtain car insurance quotes and purchase policies.

According to the company, a vulnerability in the car insurance quote flow resulted in the exposure of certain driver’s license numbers for identifiable individuals. The vulnerability has been addressed, Lemonade says.

Between April 2023 and September 2024, the platform transmitted the information unencrypted, which the company says allowed driver’s license numbers to be accessed without authorization.

“We have no evidence to suggest that your driver’s license number has been misused but we are providing this notice as a precaution to inform potentially affected individuals and share some steps you can take to help protect yourself,” the company’s notification letter reads.

The insurer is providing the impacted individuals with 12 months of free credit monitoring and identity protection services.

Advertisement. Scroll to continue reading.

Lemonade has notified the Securities and Exchange Commission that approximately 190,000 people were impacted by the mishap.

“Based on the company’s current knowledge of the facts and circumstances related to the incident, the company’s operations were not compromised, nor was Lemonade customer data targeted, and the company has determined that the incident is not material,” Lemonade told the SEC.

Founded in 2015, Lemonade describes itself as “a full-stack insurance carrier” that provides renters, homeowners, car, pet, and life insurance products in the US and Europe. The insurer is best known for relying on AI to activate policies and process claims.

Related: 2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

Related: Conduent Says Names, Social Security Numbers Stolen in Cyberattack

Related: Hertz Discloses Data Breach Linked to Cleo Hack

Related: State Bar of Texas Says Personal Information Stolen in Ransomware Attack

Related Content

Artificial Intelligence

Dozens of such keys can be extracted from apps’ decompiled code to gain access to all Gemini endpoints.

Network Security

Akamai warns that Layer 7 DDoS, API abuse and AI-powered attacks are merging into coordinated, multi-vector campaigns that are harder to detect and defend...

Application Security

New research shows attackers increasingly abusing APIs at machine speed as AI-driven systems widen exposure and amplify impact.

Application Security

API cybersecurity will be a ping pong ball, battered between the rackets of AI-assisted attackers and AI-assisted defenders.

Cybersecurity Funding

The Italian startup will use the investment to build proprietary AI models, accelerate global expansion, and hire new talent.

Artificial Intelligence

An attacker can inject indirect prompts to trick the model into harvesting user data and sending it to the attacker’s account.

Application Security

APIs are easy to develop, simple to implement, and frequently attacked. They are  prime and lucrative targets for cybercriminals. 

Application Security

Willfully ignoring important security issues to make our lives easier is, unfortunately, something that does happen in the security field. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version