Lemonade $10.5 Million Settlement Over License Number Data Breach Approved
A federal district court in New York has approved a $10.5 million class action settlement by digital insurer Lemonade over its exposing license numbers of as many as 190,644 drivers to third parties through its online auto insurance quote platform.
The case consolidated complaints brought by three plaintiffs from New York, Connecticut and Arizona on behalf of themselves and others affected by the quoting platform’s data breach, even if they were not Lemonade customers and never even applied for insurance from Lemonade.
The quoting feature uses the name, date of birth, and address entered by the website visitor, combined with additional information Lemonade already has or can access from third-party data brokers, and then automatically “pre-fills” the driver’s license information.
The claimants maintained that Lemonade’s website essentially functioned as a driver’s license lookup tool, which scammers have used to access driver’s license numbers. The plaintiffs claimed Lemonade knowingly provides driver’s license numbers to any user who first enters a name and address and the insurer does not verify that a user is entitled to the information. In addition, Lemonade does not employ effective security measures to detect whether a website visitor is, in fact, a “bot” or automated process rather than an individual person, according to the suit.
Class Action: Drivers Sour on Lemonade for Exposing License Numbers
The complaints said the license plate exposure due to the security flaw went on for 17 months between April 2023 and September 2024. It took Lemonade almost two years to discover the flaw in March 2025 and then did not disclose the vulnerability letters to affected individuals until April 2025, two years after the breaches began.
The plaintiffs accused Lemonade of negligence in handling of individuals’ data and of violating the federal Driver’s Privacy Protection Act, New York business law, Connecticut Unfair Trade Practices Act, and Federal Trade Commission (FTC) data security guidelines.
Class Claims
Under the settlement approved by U.S. Magistrate Judge Katharine H. Parker in the Southern District of New York, class members will be able to submit claims for a documented loss payment up to $10,000 and/or a pro rata cash payment. Class members will also get three years identify theft protection and credit monitoring with three credit bureaus.
The approved class includes people who never applied for insurance with Lemonade and were not Lemonade customers because “unauthorized parties availed themselves of the personal information that Lemonade made publicly available through its quote platform on a wholesale basis,” according to the lawsuit.
Lemonade, beyond the settlement fund, has agreed to implement changes and security features to strengthen its protection of customer data.
The court approved an attorneys’ fee of one-third of the settlement fund ($3,500,000). The court had preliminarily approved the class action settlement and conditionally certified the class for in May, 2026.
Not Yet Profitable
In approving the settlement, Judge Parker noted that courts consider whether a defendant could handle a greater judgment than what is outlined in a proposed settlement, and if the court finds that it could not, it is more likely that the proposed settlement is reasonable and fair. The judge noted that Lemonade is a “new company that is not yet profitable” and that financial information provided to the court made it “clear an early settlement is reasonable because there is assurance of payment and elimination of any risk” that Lemonade’s ability to pay will not be an ongoing concern. “Thus, this factor weighs in favor of approving the settlement,” the judge concluded.
Lemonade, which was launched with homeowners and renters products 10 years ago, now also offers auto, pet and life insurance.
Judge Parker further noted that if this case did not settle, there would be further litigation that would involve extensive discovery, only increasing the cost and extending the timeline of an action that has already been ongoing for approximately a year.
Other Insurers
Lemonade is not the first or only insurer to face scrutiny of its quoting platform.
In 2025, New York State secured more than $19 million in penalties from eight auto insurance providers for inadequate cybersecurity controls that allowed hackers to steal New Yorkers’ personal information including driver’s license numbers from their online auto insurance quoting applications. The penalized firms included Farmers Insurance Exchange, Hagerty Insurance Agency, Hartford Fire Insurance Co., Infinity Insurance Co., Liberty Mutual Insurance Co., Metromile Insurance Co., Midvale Indemnity Co., and State Automobile Mutual Insurance Co.
New York Attorney General Letitia James also secured $975,000 in penalties from auto insurer Root, $5.1 million from GEICO and Travelers, as well as $500,000 from Noblr, for also failing to prevent data breaches of New Yorkers’ data.
In 2024, Lemonade reached a $5 million settlement in a case accusing it of illegally sharing life insurance applicants’ personal and health-related information to third parties including TikTok, Facebook and Snapchat.