2026-09-18 · Source: Insurance Journal
Summary in 3 Points • Lemonade settles for $10.5 million over data breach affecting 190,644 drivers' license numbers • Settlement includes up to $10,000 loss payment and three years of identity theft protection • Lemonade to enhance data security measures following breach settlement approval --- A federal district court in New York has approved a $10.5 million class action **settlement** involving digital insurer Lemonade, following a data breach that exposed the driver's license numbers of up to 190,644 individuals. The breach occurred through Lemonade's online auto insurance quote platform, which inadvertently allowed unauthorised access to sensitive information. The settlement, approved by U.S. Magistrate Judge Katharine H. Parker, provides class members with the option to claim up to $10,000 for documented losses, alongside three years of identity theft protection and credit monitoring. The breach, which went undetected for nearly two years, led to accusations against Lemonade of negligence and violations of several data protection laws. For the **London Insurance Market**, this settlement highlights the critical importance of robust **cybersecurity** measures, especially for digital insurers operating within the auto insurance sector. Lemonade's breach and subsequent settlement underscore the potential financial and reputational risks associated with inadequate data protection, a concern that resonates with London Market participants who underwrite cyber and data breach policies. The incident serves as a reminder of the regulatory scrutiny and potential penalties insurers face, akin to the $19 million in penalties imposed on several insurers by New York State for similar breaches. This case emphasises the need for London insurers to ensure their quoting platforms and data handling practices are fortified against such vulnerabilities. **Underwriters** and **brokers** within the London Market should consider the implications of this settlement when assessing the **risk** profiles of digital insurers and their cybersecurity practices. The Lemonade case illustrates the necessity for comprehensive **risk assessments** and the inclusion of stringent data protection clauses in policy wordings. Additionally, risk managers should advise clients on the importance of maintaining up-to-date cybersecurity measures to mitigate the risk of data breaches and potential legal actions. This case also highlights the value of offering identity theft protection as part of a comprehensive response strategy following a data breach.