Cybersecurity

Radaris.com Domain Seizure Marks a Watershed Moment in the Battle Over Data Broker Privacy Practices

The digital empire of consumer data broker Radaris.com has faced an unprecedented collapse following a court-ordered transfer of its flagship domain to Atlas Data Privacy Corp. This development, stemming from the company’s persistent failure to comply with New Jersey’s Daniel’s Law, represents a rare victory for privacy advocates against an industry long characterized by obfuscation, jurisdictional shell games, and aggressive litigation tactics. The transfer of radaris.com, alongside more than a dozen associated domains, serves as a tangible consequence for a business model built on the wholesale aggregation and sale of personal information, despite legal mandates requiring the removal of data belonging to law enforcement and government officials.

The Genesis of the Litigation

In February 2024, Atlas Data Privacy Corp initiated legal action against Radaris, alleging systematic violations of New Jersey’s Daniel’s Law. Named in honor of Daniel Anderl, the son of U.S. District Judge Esther Salas who was murdered in 2020, the statute provides a critical safeguard for judges, law enforcement personnel, and other government officials. It mandates the removal of their personal information from commercial databases and stipulates a penalty of $1,000 per violation for companies that fail to honor such requests.

For years, Radaris maintained a reputation for ignoring these removal requests, relying on a complex web of corporate entities to insulate its owners from liability. When Atlas began its legal offensive, the response from Radaris was characterized by procedural delays, the assertion of fraudulent ownership claims, and the tactical use of offshore corporate registrations.

A Chronology of Evasion and Institutional Shell Games

The tactics employed by the operators of Radaris reflect a well-documented "island-hopping" strategy designed to frustrate plaintiffs. Between 2017 and 2025, the organization consistently shifted its operational base to jurisdictions such as the Marshall Islands, the British Virgin Islands, and the Seychelles.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

In 2017, Radaris was the subject of a class-action lawsuit that resulted in a $7.5 million default judgment. When plaintiffs moved to collect, the court ordered the registry Verisign to transfer the radaris.com domain to the claimants. Radaris’s legal counsel, Val Gurvits of the Boston Law Group, successfully appealed the order by arguing that the court had failed to name the actual owner—a Cyprus-based firm called Bitseller Expert Limited. Following the dismissal of the transfer, the operation transitioned from Bitseller to Andtop Company, an entity established in the Marshall Islands in October 2020.

This cycle of creating and discarding legal entities effectively shielded the true architects of the operation—Russian-born brothers Igor and Dmitry Lubarsky—from direct accountability for nearly a decade. Even when confronted with evidence regarding their roles, the brothers’ legal representatives attempted to suppress investigative reporting, including threats of defamation litigation, by falsely claiming the company was owned by Ukrainian nationals living in Ukraine.

The Forensic Evidence of Unified Operations

Through the course of discovery, Atlas Data Privacy Corp successfully acquired more than 10,000 internal documents and emails, providing a granular view of the organization’s backend operations. This cache of evidence confirms that disparate entities, including Radaris America, Inc., Bitseller Expert Limited, and various others, functioned as a single, centralized operation managed from a Boston-area hub.

The technical and financial infrastructure of these companies was found to be unified. The entities shared bank accounts, payment processing systems, and common administrative mail domains such as "difive.com" and "scienteco.com." The documentation reveals a lucrative business model, with Radaris.com generating an estimated $42,000 in monthly revenue, while its sister site, Veripages.com, brought in approximately $45,000 through partnerships with major marketing and advertising firms like the Lifetime Value Company.

Further complicating the ethical landscape, internal records indicate that Radaris received roughly $25,000 per month through a partnership with Onerep, a service that ironically markets itself as a solution for individuals seeking to remove their data from the very sites that Radaris operates. This circular ecosystem—profiting from both the sale of data and the "cure" for its exposure—highlights the perverse incentives driving the modern data brokerage industry.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

Legal and Constitutional Challenges

The current status of the radaris.com domain, which now displays an Atlas-provided notice of the transfer, represents a significant, though potentially temporary, victory. Radaris’s legal defense, now led by Victor Worms, has filed a motion to vacate the default judgment. The defense argues that the court’s order is void because the domain name itself is not a legal entity capable of being sued, and that the seizure constitutes a forfeiture in violation of constitutional principles.

This battle is unfolding against the backdrop of a broader constitutional challenge to Daniel’s Law. Approximately 150 data broker firms currently facing litigation from Atlas have coordinated to challenge the statute on First Amendment grounds, arguing that it is overly broad. While the Third Circuit Court of Appeals has yet to issue a definitive ruling, the case is widely expected to reach the U.S. Supreme Court, setting the stage for a landmark decision on the tension between commercial data rights and personal privacy protections.

Broader Implications for Privacy Legislation

The legal struggle surrounding Radaris underscores the systemic inadequacy of current U.S. data protection laws. Privacy expert Justin Sherman, author of The Middlemen, emphasizes that the issue extends far beyond the practices of a single firm. The lack of comprehensive federal privacy legislation has left a regulatory vacuum, where the definition of "public" or "government" data is broad enough to exempt nearly every category of personal information—from property filings to professional licenses—from meaningful regulation.

The recent breach at IDScan.net, which exposed the driver’s license data of 153 million Americans, serves as a stark reminder of the dangers posed by the unchecked aggregation of personal records. Despite state-level attempts to implement age-verification laws, there remains no federal standard governing how these companies manage, share, or secure the sensitive biometric and identification data they collect.

The impact of the Radaris domain transfer extends to 14 other states that have passed legislation modeled after New Jersey’s Daniel’s Law. However, the legal environment remains volatile; in August 2025, a federal district court ruled West Virginia’s version of the law unconstitutionally broad. This legal inconsistency creates a fractured landscape for both consumers and businesses, fueling a climate of uncertainty.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

Conclusion

The dissolution of the Radaris domain empire is a testament to the efficacy of aggressive, resource-intensive litigation in the face of institutionalized corporate evasion. By tracing the financial and administrative threads linking dozens of shell companies back to a single source, Atlas Data Privacy Corp has provided a roadmap for future enforcement.

However, as long as the underlying economic incentives remain, and as long as federal law continues to exempt the vast majority of personal data from protection, the Radaris case may be less of a definitive resolution and more of a precursor to a longer, more complex constitutional battle. As the judiciary weighs the limits of state-level privacy statutes against the protections afforded to commercial data aggregators, the fundamental question remains: whether the current regulatory framework is capable of addressing the privacy risks inherent in a 21st-century digital economy, or if the burden of data protection will continue to fall on the shoulders of private litigants.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button