柠檬水公司因未加密传输驾照号码通知约19万名用户
Lemonade Inc.通知约19万名用户,因技术故障导致其驾照号码在未加密情况下传输给第三方数据提供商。问题发生在2023年4月至2024年3月期间。公司已修复漏洞,并称此事件不影响运营或财务结果。 2025-4-18 11:12:0 Author: www.cybersecuritydive.com(查看原文) 阅读量:6 收藏

Lemonade Inc. has begun sending notification letters to about 190,000 people after their driver’s license numbers were transmitted unencrypted, according to regulatory filings by the company. 

The company said a technical issue in its online application process for car insurance led to the exposure of data in an application programming interface call to a third-party data provider, according to an April 9 filing with the Securities and Exchange Commission

As part of the online application process, certain information is sent between a server and a user’s browser, according to the filing. This includes data used to generate an insurance quote.  

Lemonade said it learned of the issue on March 14 and said the exposures likely lasted from April 2023 through March 2024, according to a notice filed with the California Attorney General’s office. 

The technical issue allowed the data to be sent out without the normal means of protection used by Lemonade and the driver’s license numbers were left without encryption. The company said has since taken measures to resolve the vulnerability.

Lemonade said none of its operations were compromised and customer data was not targeted. The company said it does not consider the incident to be “material” to operations or financial results.   

The company said it will notify regulators based on its legal obligations. 

A spokesperson for the company was not immediately available. 

Lemonade offers various policies, including renters, homeowners, pets, auto and life insurance in the U.S. and parts of Europe. It has more than 2.4 million customers.


文章来源: https://www.cybersecuritydive.com/news/lemonade-drivers-license-exposed/745762/
如有侵权请联系:admin#unsafe.sh