Executive Summary
This report analyzes the legal and regulatory enforcement action against Radaris.com and its affiliated domains, which resulted in the seizure of multiple data broker websites for violations of New Jersey’s Daniel’s Law. The incident did not involve a cyberattack or technical breach, but rather the ongoing publication and sale of protected personal information of law enforcement officers, judicial officials, and their families. The case sets a significant precedent for privacy law enforcement against data brokers, with sector-wide implications for compliance and operational risk. All findings and conclusions in this report are based on primary sources, including court records and investigative reporting from KrebsOnSecurity and the official Radaris.com court order notice.
Technical Information
The enforcement action against Radaris.com was not the result of a technical compromise, malware infection, or unauthorized network intrusion. Instead, the incident stemmed from the company’s persistent publication and sale of sensitive personal information, including home addresses and unpublished telephone numbers of law enforcement officers, prosecutors, judges, and their families—individuals protected under New Jersey’s Daniel’s Law. Despite repeated removal requests and legal notifications, Radaris.com and its affiliated domains continued to make this information available, prompting legal action.
Technical analysis of the incident reveals that the primary “attack vector” was the willful non-compliance with privacy law, rather than any form of cyber exploitation. The operational tactics employed by Radaris included the use of shell companies in multiple jurisdictions (such as the Marshall Islands, British Virgin Islands, Seychelles, and Cyprus), the creation of fictitious CEO identities, and frequent changes to privacy policies and legal entities to delay or evade legal accountability. These tactics are well-documented in over 10,000 emails and legal documents obtained during litigation, confirming centralized control by a small group based in Boston.
No malware, hacking tools, or technical indicators of compromise (IOCs) were identified in any primary source. The only “tools” referenced were legal and operational in nature, designed to obscure ownership and frustrate enforcement efforts. The MITRE ATT&CK framework can be used to map these evasion tactics to specific techniques, including defense evasion (T1070.004, T1036, T1588.002, T1583.001) and operational security (T1098, T1584.001).
The exposure of protected personal information posed direct threats to the safety and privacy of law enforcement and judicial officials, leading to the court-ordered seizure of at least 13 domains, including Radaris.com, Rehold.com, and Trustoria.com. The company now faces potential fines of $1,000 per violation, and the case has triggered similar lawsuits against over 150 data brokers in at least 14 other states.
All claims in this section are supported by primary source documentation, including the final judgment by default from the Superior Court of New Jersey (Docket No. MID-L-000847-24) and investigative reporting by KrebsOnSecurity.
Affected Versions & Timeline
The enforcement action targeted the operational versions of Radaris.com, Rehold.com, Trustoria.com, and at least 13 other affiliated domains as of August 27, 2026. The timeline of verified events is as follows: On February 8, 2024, Atlas Data Privacy Corp and five individual plaintiffs filed a lawsuit in New Jersey Superior Court. In March 2024, KrebsOnSecurity published an investigative report on Radaris’ business practices. On May 27, 2025, an amended complaint expanded the claims to include approximately 21,760 “covered persons” under Daniel’s Law. In June 2025, the lawsuit was re-filed to include additional data brokers. On August 26, 2026, the court found the defendants failed to appear, resulting in a default judgment. On August 27, 2026, the court entered final judgment by default, ordering domain seizure and permanent injunctive relief. On September 16, 2026, KrebsOnSecurity published a comprehensive report on the outcome and implications.
Threat Activity
There is no evidence of technical threat activity such as unauthorized access, exploitation, or malware deployment. The threat originated from the ongoing publication and sale of protected personal information, despite legal requirements and removal requests. The operational tactics used by Radaris and its operators included the use of shell companies, fictitious identities, and jurisdictional obfuscation to evade legal accountability. These tactics are confirmed by extensive documentary evidence and court findings.
The exposure of home addresses and unpublished phone numbers of law enforcement officers, prosecutors, judges, and their families posed direct threats to their safety and privacy. The case has broader implications for the data broker industry, with similar privacy laws and lawsuits emerging in multiple states.
Mitigation & Workarounds
The following recommendations are prioritized by severity:
Critical: Organizations handling sensitive personal information of law enforcement, judicial officials, or other protected persons must immediately review compliance with all applicable privacy laws, including Daniel’s Law and similar statutes in other states. Failure to comply can result in domain seizure, permanent injunctions, and significant financial penalties.
High: Data brokers and organizations aggregating personal data should implement robust data removal and opt-out processes, ensuring timely and verifiable responses to removal requests from covered individuals.
Medium: Legal, compliance, and IT teams should regularly audit data collection, storage, and publication practices to ensure ongoing alignment with evolving privacy regulations and court orders.
Low: Organizations should monitor legal developments in the data broker sector and participate in industry forums to stay informed about emerging risks and enforcement trends.
Indicators of Compromise
The following indicators are provided as a point-in-time reference and should be validated before enforcement. These indicators are based on primary source content and reflect domains seized as part of the court order.
Type | Indicator | Reported (date) | Source
|
Domain | radaris[.]com | 2026-08-27 | http://radaris.com/ |
Domain | rehold[.]com | 2026-08-27 | http://radaris.com/ |
Domain | trustoria[.]com | 2026-08-27 | http://radaris.com/ |
URL | hxxp://radaris[.]com/ | 2026-08-27 | http://radaris.com/ |
References
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/
About Rescana
Rescana provides a third-party risk management (TPRM) platform that enables organizations to continuously monitor, assess, and manage the privacy and security posture of their vendors and data partners. Our platform supports compliance with evolving privacy regulations and helps organizations identify and mitigate risks associated with data brokers and other third parties.
We are happy to answer questions at info@rescana.com.



