Lemonade, Inc. Data Breach Notice (Oregon Attorney General)
If you received a notice from Lemonade, Inc., here’s what the filing says was exposed, and what to do about it.
Lemonade, Inc. notified Oregon residents of a data breach in a filing reported to the Oregon Department of Justice on April 11, 2025. The filing puts the incident itself on April 01, 2023.
The April 1, 2023 breach at Lemonade, Inc. means that personal information belonging to 190,000 people sat exposed for 741 days before the company filed its notice with Oregon on April 11, 2025. That interval—more than two years—is the single most striking fact in the record.
Two years passed between the incident and the filing
Lemonade reported the incident date as April 1, 2023 and made its regulatory filing on April 11, 2025. The 741-day gap is now public. Notification timelines vary by state and depend on when an investigation concludes, so the record does not label the delay as a failure. It simply states both dates and the scale: 190,000 people whose personal information was involved.
What the filing actually lists as exposed
The Oregon Attorney General’s record names only one category: personal information. No passwords, no financial account numbers, no Social Security numbers, and no government identifiers appear in the disclosed list. That absence is meaningful. Because no passwords were exposed, this incident does not put your Lemonade account login at direct risk.
The exposed personal information still carries long-term value. Names combined with addresses, policy details, or other contact data can be used for targeted identity theft attempts, fraudulent loan applications, or convincing customer-service impersonations. These records do not expire the way a credit card does.
What this means for you right now
If you received a letter from Lemonade notifying you that your information was included, the personal data listed in that letter is now in unknown hands. The filing does not state whether the data was copied or simply accessed, so treat the worst case as possible. The people whose records were included face an elevated risk of fraud that will last for years.
Absence of a letter usually means your information was not part of the 190,000 affected records. Letters are sent to the last known address on file at the time of the incident in April 2023. If you have moved since then, contact Lemonade directly to confirm whether you were in the affected group. The company is required to notify individuals whose personal information was involved.
The permanent nature of personal information exposure
Unlike a password or credit card, the core elements of personal information cannot be cancelled or reissued on demand. Once it leaves a company’s control, it remains usable for fraud indefinitely. The two-year gap before notification simply gave any parties who accessed the data more time to put that information to use or to sell it.
This is why the scale—190,000 people—matters. Each record represents a permanent addition to the pool of identity data available to criminals. Lemonade’s filing does not disclose the exact initial access vector or confirm whether data was exfiltrated, so those details remain unknown.
Why the lack of credential exposure changes your priorities
Because the record contains no password data, you do not need to change your Lemonade password for this incident. That is genuine good news. Your effort is better spent on the downstream risks created by the exposed personal information: monitoring for new accounts opened in your name, watching for unexpected insurance or loan inquiries, and maintaining strong fraud alerts on your credit files.
The filing lists personal information only. It does not mention medical data, driver’s license numbers, or financial account details. Those categories are absent from the record, which limits—but does not eliminate—the possible harms.
How to check whether you are affected
The most reliable indicator remains the letter. Lemonade must notify affected Oregon residents directly, usually by mail. If you have not received one, your information was likely not included. Anyone who changed addresses after April 1, 2023 should reach out to Lemonade’s support to verify their status. The filing itself cannot tell an individual reader whether their specific record was touched; only the company’s notification can.
The 190,000 figure is exact as stated in the Oregon filing. It covers the number of people whose personal information was involved in the April 2023 incident. No further breakdown is provided.
Long-term monitoring is now part of your routine
Personal information exposed in 2023 remains valuable in 2025 and will stay valuable for the foreseeable future. Criminal markets treat such data as a durable asset. The two-year notification delay does not change what you control today: vigilance over new credit applications, regular review of insurance statements, and prompt response to any unexpected contact that claims to be from Lemonade.
The record establishes what was exposed, how many people were affected, and when the company filed notice. It does not establish how the incident occurred or whether any specific individual’s data left the environment. Those uncertainties are part of the official filing.
Report details & sourcing
Related breaches
Punch & Associates Investment Management, Inc. Data Breach Notice (Vermont Attorney General)
Punch & Associates Investment Management, Inc. notified Vermont residents of a data breach in a fili…
Livara Health Medical Group Data Breach Notice (California Attorney General)
Livara Health Medical Group notified California residents of a data breach in a filing reported to t…
Pan American Group LLC Data Breach Notice (California Attorney General)
Pan American Group LLC notified California residents of a data breach in a filing reported to the Ca…