Executive Summary
A New Jersey court has ordered the transfer of radaris.com and 13 other domains from the data broker Radaris to Atlas Data Privacy Corp following a lawsuit under New Jersey’s Daniel’s Law. This law allows law enforcement officers, judges, prosecutors, and their families to demand the removal of their personal information from data brokers, with a $1,000 penalty per violation. Radaris failed to comply with removal requests and did not mount a substantive legal defense, resulting in a default judgment and the unprecedented seizure of its primary domains. The operators of Radaris, identified as Igor and , used a network of shell companies and frequent changes in corporate structure to evade accountability. The court’s action is a significant precedent in privacy enforcement, demonstrating that domain infrastructure can be leveraged when financial penalties are unenforceable. While the affected domains no longer sell personal dossiers, at least 25 other people-search sites remain operational under the same management. The broader data broker industry is now facing similar lawsuits and legislative scrutiny in multiple states. No technical compromise or malware was involved in this incident; the enforcement was entirely legal and procedural.
Technical Information
The incident involving Radaris is characterized by legal and procedural enforcement rather than technical exploitation. Atlas Data Privacy Corp initiated legal action under Daniel’s Law (N.J.S.A. 56:8-166.1), which mandates that data brokers remove personal information of covered individuals upon request. Radaris failed to comply and did not appear in court, resulting in a default judgment and the court-ordered transfer of 14 domains, including radaris.com, to Atlas.
Radaris operated a network of at least 25 people-search and data broker sites, as well as Russian-language dating services. The company’s operators used a series of shell companies registered in offshore jurisdictions such as the Marshall Islands, British Virgin Islands, Seychelles, and Cyprus to obscure ownership and delay legal proceedings. This tactic, referred to as “island-hopping,” involved frequent changes to privacy policies and corporate entities, making it difficult for plaintiffs to enforce judgments or collect damages.
The court’s decision to transfer domain infrastructure, rather than pursue financial penalties, reflects the challenges of enforcing judgments against offshore entities. Previous legal actions, such as the 2014 Fair Credit Reporting Act class action (Huebner v. Radaris), resulted in uncollectible default judgments due to the use of shell companies. The domain transfer mechanism bypasses these obstacles by leveraging the control of U.S.-based domain registries.
Radaris’s business model involved compiling and selling detailed dossiers containing current and past addresses, phone numbers, relatives, and known email addresses of millions of Americans. The company earned approximately $42,000 per month from radaris.com and $45,000 per month from veripages.com through partnerships with other data brokers and removal services, such as Onerep and the Lifetime Value Company.
The technical mapping of Radaris’s evasion tactics aligns with several MITRE ATT&CK techniques, including:
- T1583.001 - Acquire Infrastructure: Domains: Registration and operation of multiple domains under various shell companies.
- T1584.001 - Compromise Infrastructure: Domains: Use of rapid domain ownership changes and shell companies to evade enforcement.
- T1585.001 - Establish Accounts: Social Media Accounts: Creation of fictitious personas (e.g., a persona using the name “”) and use of multiple email addresses to mask true ownership.
- T1589.002 - Gather Victim Identity Information: Email Addresses: Compilation and sale of reports containing personal and contact information.
- T1591.002 - Gather Victim Org Information: Business Relationships: Internal communications revealing business relationships with other data brokers and removal services.
No malware, technical exploitation, or external cyber threat actors were identified in this incident. All actions were legal and procedural, with high-confidence attribution to the company operators based on documentary evidence, legal admissions, and investigative reporting.
The primary victims were New Jersey law enforcement officers, judges, prosecutors, and their families, but the general public remains exposed through the broader network of people-search sites. The enforcement action against Radaris is part of a larger trend, with Atlas suing approximately 150 other data brokers and at least 14 states passing similar privacy laws.
The case highlights the limitations of current privacy laws, which often exclude ordinary citizens, and underscores the need for comprehensive federal privacy legislation. The domain seizure sets a precedent for using infrastructure as leverage in privacy enforcement and signals increased legal risk for data brokers employing evasive corporate structures.
Affected Versions & Timeline
The affected domains include radaris.com, rehold.com, trustoria.com, and 11 other related domains operated by the Radaris network. The timeline of key events is as follows:
- February 8, 2026: Atlas Data Privacy Corp files suit against Radaris under Daniel’s Law.
- May 27, 2026: Complaint is amended to include additional domains and entities.
- August 26, 2026: New Jersey court enters default judgment and orders the transfer of 14 domains, including radaris.com, to Atlas.
- August 27, 2026: Domain transfer is executed; radaris.com displays a notice of court-ordered transfer.
- September 16-17, 2026: Public reporting confirms the domain transfer and details the legal and procedural history.
The court’s order bars the defendants and all persons in concert with them from publishing covered persons’ data through any subdomains, affiliated domains, or sites they control. The broader network of at least 25 people-search sites operated by the same group remains active, but only the 14 domains specified in the judgment are directly affected.
Threat Activity
The threat activity in this case is characterized by legal and procedural evasion rather than technical compromise. Radaris engaged in a pattern of corporate obfuscation, using shell companies and frequent changes in ownership and jurisdiction to delay or evade legal action. The company’s operators created fictitious personas and used multiple email addresses to mask their involvement across a network of related domains.
The primary threat to individuals was the unauthorized publication and sale of personal information, including addresses, phone numbers, relatives, and email addresses. This exposure increases the risk of identity theft, doxxing, and other privacy harms, particularly for law enforcement officers, judges, and their families.
The enforcement action against Radaris demonstrates the effectiveness of domain seizure as a remedy when financial penalties are unenforceable. It also highlights the ongoing risk posed by data brokers to both public officials and the general public, as well as the limitations of current privacy laws.
Mitigation & Workarounds
Critical recommendations for organizations and individuals concerned about data broker exposure include:
For covered individuals under Daniel’s Law (New Jersey law enforcement, judges, prosecutors, and their families), submit removal requests to data brokers and monitor compliance. Assign claims to a third party, such as Atlas Data Privacy Corp, for collective enforcement where possible.
For the general public, regularly search for your information on people-search sites and use available opt-out mechanisms. Be aware that data may reappear due to public record updates or data sharing among brokers. Use email aliases when interacting with data brokers to avoid providing fresh identifiers.
For organizations, monitor the legal landscape for changes in state and federal privacy laws affecting data brokers. Evaluate the use of paid data removal services, but vet providers for coverage and transparency.
For compliance and legal teams, recognize that domain infrastructure can be targeted in privacy enforcement actions. Review your organization’s exposure to data broker practices and ensure compliance with applicable laws.
Indicators of Compromise
The following table lists domains associated with the Radaris network and related entities, as identified in public reporting. These indicators are point-in-time and should be validated before enforcement.
Type | Indicator | Reported (date) | Source
|
Domain | radaris[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | rehold[.]com | 2026-09-17 | https://www.gblock.app/articles/radaris-daniels-law-domains-atlas-court-2026 |
Domain | trustoria[.]com | 2026-09-17 | https://www.gblock.app/articles/radaris-daniels-law-domains-atlas-court-2026 |
Domain | veripages[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | difive[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | centerex[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | scienteco[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | eprofit[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | realmo[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | pub360[.]com | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
Domain | idscan[.]net | 2026-09-16 | https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ |
References
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ https://www.yahoo.com/news/us/articles/data-broker-radaris-loses-website-160633707.html https://www.gblock.app/articles/radaris-daniels-law-domains-atlas-court-2026
About Rescana
Rescana provides a Third-Party Risk Management (TPRM) platform that enables organizations to continuously monitor, assess, and manage the risks posed by vendors, including data brokers and other third parties. Our platform supports the identification of exposed domains, infrastructure, and data broker relationships, helping organizations respond to evolving privacy and regulatory risks. For more information or to discuss your organization’s risk exposure, contact us at info@rescana.com.



