Cybersecurity

Radaris faces historic domain seizure following legal battles over data privacy and Daniel’s Law compliance

The consumer data broker Radaris.com has effectively been dismantled in a landmark legal maneuver after years of ignoring requests to remove sensitive personal information from its extensive network of people-search platforms. Following a protracted legal battle, a New Jersey judge ordered the transfer of Radaris.com and more than a dozen associated data broker domains to Atlas Data Privacy Corp. This move comes as a direct consequence of Radaris’s refusal to comply with Daniel’s Law, a critical New Jersey statute designed to shield state law enforcement officials, judges, and their families from the risks associated with the public exposure of their private data.

The seizure represents a rare and significant victory for privacy advocates who have long struggled to hold shadowy data brokerage firms accountable. For years, Radaris operated under a veil of corporate ambiguity, relying on a complex web of shell companies and international jurisdictions to evade service of process and regulatory oversight. The transfer of the domains to the plaintiffs—a consequence of a default judgment—serves as a stark reminder of the escalating tensions between digital privacy rights and the unchecked commercialization of personal information.

A Chronology of Evasion and Litigation

The conflict between Atlas Data Privacy Corp and the operators of Radaris began in earnest in February 2024. Atlas, a firm specifically tasked with enforcing Daniel’s Law, targeted Radaris for its failure to honor removal requests. Under the statute, data brokers are liable for fines of up to $1,000 per violation if they continue to publish the private data of protected individuals after being notified.

Radaris’s defense strategy throughout the proceedings was characterized by what legal experts describe as "procedural attrition." By frequently shifting the nominal owners of their digital assets—often to entities in the Marshall Islands, the British Virgin Islands, or the Seychelles—the company successfully delayed accountability for years. This "island-hopping" phase was intended to exhaust the resources of plaintiffs and complicate the serving of legal documents.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

The pattern of behavior traces back even further. In 2017, Radaris was involved in a class-action lawsuit that resulted in a $7.5 million default judgment. At that time, the company avoided paying by claiming that the lawsuit had targeted the wrong corporate entity. By the time the plaintiffs attempted to collect, the operator of the domain had been shifted from a Cyprus-based firm, Bitseller Expert Limited, to the Marshall Islands-based Andtop Company. The plaintiffs eventually abandoned that effort, reinforcing the efficacy of the firm’s obfuscation tactics.

However, the 2024 litigation took a different trajectory. Atlas, bolstered by the discovery of thousands of internal emails and financial documents, was able to pierce the corporate veil. These documents revealed that despite the frequent name changes, the administrative, financial, and technical operations were all funneled through a single Boston-area cluster of individuals: brothers Igor and Dmitry Lubarsky.

The Anatomy of a Data Broker Empire

The investigation into the Lubarsky brothers revealed a sophisticated, albeit deceptive, business model. The brothers, who reside in Massachusetts, managed a dizzying array of platforms beyond Radaris, including Russian-language dating services and various affiliate marketing programs. Perhaps most egregiously, the company employed a fictitious CEO, "Gary Norden," to provide a veneer of corporate legitimacy. Attorney Val Gurvits, representing the Lubarskys, eventually admitted that the CEO was a fabrication, used in press releases to solicit investor interest.

According to data compiled by Atlas, this collective of companies generated substantial revenue. Radaris.com alone was estimated to pull in approximately $42,000 per month, with sister site Veripages.com generating upwards of $45,000. These figures were bolstered by partnerships with major marketing entities such as the Lifetime Value Company, which operates brands like PeopleLooker and Bumper. Furthermore, internal records indicated that the Radaris network received as much as $25,000 monthly from Onerep, a service that claims to help consumers remove their data from the very sites that Radaris and its affiliates populate.

This circular economy of data—where firms profit from both the publication of sensitive information and the "service" of removing it—has drawn sharp criticism from privacy researchers. The documents obtained by Atlas proved that these seemingly independent websites were, in reality, a singular operation managed from a unified set of mailboxes and payment processing accounts.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

Official Responses and Legal Maneuvering

The legal team representing Radaris has continued to contest the recent court orders. Following the transfer of the domains, attorney Victor Worms, now representing the interests associated with the Radaris network, argued that the judgment was void. "We have made a motion to vacate that default judgment on the grounds that it is void since a non-entity has no legal capacity to sue or be sued," Worms stated, suggesting that because "Radaris.com" is a domain name rather than a legal person or corporation, the court lacked the jurisdiction to seize it.

Worms further indicated that his clients intend to pursue appeals, framing the domain transfer as a violation of constitutional due process rights. Despite these objections, the impact on the firm’s operations has been immediate. The Radaris.com homepage no longer provides access to personal dossiers; instead, it hosts a formal notice regarding the domain transfer and links to investigative reporting on the company’s past practices.

Broader Implications and the State of Privacy Law

The Radaris case highlights a critical vulnerability in the American legal system regarding the regulation of data brokers. While New Jersey’s Daniel’s Law has set a high bar, it is currently facing a massive constitutional challenge. Approximately 150 data broker firms, including the Radaris family, have sought to move pending litigation to federal court, arguing that the law is overly broad and infringes upon First Amendment rights regarding the dissemination of "public" information.

The constitutional validity of such laws remains in flux. In August 2025, a federal district court ruled that West Virginia’s version of Daniel’s Law was facially unconstitutional. As these cases wind their way toward the U.S. Supreme Court, the legal landscape for data privacy remains fragmented.

Privacy expert Justin Sherman, author of the forthcoming book The Middlemen, emphasizes that the fundamental issue is the lack of a comprehensive federal privacy framework. "The average person can look at Daniel’s Law and have a perfectly normal reaction, which is that everyone should be covered, not just police and judges," Sherman noted. He argues that current state-level efforts, while well-intentioned, are hampered by massive exemptions for "public" records.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

Because data brokers categorize information like voting registries, property filings, marriage certificates, and motor vehicle records as public, they argue that their activities are protected by law. This creates a scenario where the digital footprint of an average American is essentially a commodity that can be scraped, packaged, and sold without consent, regardless of the security risks involved.

Conclusion: A Wake-Up Call for Congress

The recent events surrounding Radaris demonstrate that while aggressive litigation can occasionally neutralize bad actors, it is an inefficient and inconsistent substitute for robust federal regulation. The exposure of the IDScan.net breach, which saw 153 million driver’s license records sold on the dark web, underscores the urgent need for legislation that governs how companies collect, store, and share identification data.

As it stands, the "shell game" played by firms like Radaris is facilitated by the absence of federal transparency requirements for the data brokerage industry. Until Congress enacts legislation that restricts the automated harvesting of personal data—rather than merely creating a patchwork of state-level opt-out requirements—the surveillance-by-default business model will likely persist. The transfer of Radaris.com to Atlas is a significant milestone in privacy litigation, but it remains a single battle in a much larger, ongoing war over the digital sovereignty of the American public. The case serves as both a warning to data brokers and a signal to lawmakers that the status quo is increasingly untenable in an era of ubiquitous digital surveillance.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button