The consumer data broker Radaris.com has been stripped of its domains after a protracted legal battle, signaling a significant victory for privacy advocates and law enforcement officials in New Jersey. The company, notorious for its persistent refusal to remove personal information from its vast people-search network, was found to have violated Daniel’s Law, a state statute designed to protect sensitive information of public officials and their families. In a decisive ruling, a judge ordered the transfer of radaris.com and over a dozen related data broker domains to the plaintiffs, Atlas Data Privacy Corp., citing Radaris’s repeated obstruction and evasion tactics.

The legal showdown began in February 2024 when Atlas Data Privacy Corp. initiated a lawsuit against Radaris. Atlas has been actively pursuing data brokers accused of contravening Daniel’s Law, which mandates the complete removal of personal data for specified individuals and carries substantial fines for non-compliance. This law, born from a personal tragedy, provides a crucial safeguard for those in public service. The timing of the lawsuit was particularly noteworthy, as it followed a detailed investigation by KrebsOnSecurity into the Radaris co-founders, Russian-born brothers Igor and Dmitry Lubarsky, who operate a sprawling web of people-search and dating services. Their attorneys, including Val Gurvits of the Boston Law Group, initially threatened defamation lawsuits and disavowed ownership, claiming the true operators were Ukrainians. However, subsequent reporting by KrebsOnSecurity revealed the Lubarsky brothers’ use of a fictitious CEO, "Gary Norden," and their extensive network of shell companies, further complicating their defense.
Radaris’s legal strategy, as described by Matt Adkisson, president and CEO of Atlas, involved a deliberate pattern of delay and obfuscation. The company allegedly engaged in "island-hopping," constantly shifting its legal domicile to jurisdictions like the Marshall Islands, the British Virgin Islands, and Seychelles, while altering privacy policies and introducing new corporate entities. This tactic aimed to confuse plaintiffs and courts about who the actual responsible parties were. Adkisson recounted instances where newly created entities, claimed by Radaris to be managing the company, were found not to exist. This pattern of evasion is reminiscent of a prior class action lawsuit in 2017 where Radaris temporarily lost a $7.5 million default judgment. Although the domain transfer was halted by an appeal based on the argument that the true owner, Cyprus-based Bitseller Expert Limited, was not properly named, Radaris subsequently changed its operator to Andtop Company, a Marshall Islands entity formed in 2020, preventing the plaintiffs from refiling their case at that time.

Raj Parikh, a partner at PEM Law representing Atlas, noted that Radaris had historically relied on "attrition," wearing down opposing counsel through procedural complexities and making financial recovery difficult due to the foreign nature of the entities. However, recognizing the significant threat Radaris posed to New Jersey law enforcement, Atlas committed the necessary resources to pursue the case to its conclusion. The court ultimately found that the defendants had ample opportunity to defend themselves but failed to do so, leading to the default judgment and the order to transfer the domains. Despite efforts by Radaris’s new counsel, Victor Worms, to vacate the judgment on the grounds that Radaris.com is not a legal entity, the court’s decision stands, with 14 domains already transferred to Atlas. Radaris.com now displays a notice from Atlas detailing the court-ordered transfer and linking to further reporting.
Crucially, Atlas has obtained over 10,000 emails and documents that corroborate KrebsOnSecurity’s findings. These documents reportedly confirm that entities such as Radaris America, Inc., Bitseller Expert Limited, and Digital Orbit Corp., among others, are centrally administered by a small group of individuals from common mailboxes, share financial infrastructure, and operate from a single virtual office address. The emails also reveal the financial operations of the Radaris network, with Radaris.com generating approximately $42,000 monthly and Veripages.com earning around $45,000 through partnerships with firms like Lifetime Value Company. Further financial insights show the Radaris group earning up to $25,000 monthly from a partnership with Onerep, a company ironically offering to remove personal data from people-search sites, whose founder has also been linked to operating numerous such sites.

While the domain transfer represents a significant victory, the broader implications for data privacy remain complex. Radaris and its affiliated companies still face potential fines for Daniel’s Law violations. However, the constitutionality of Daniel’s Law itself is under attack from numerous data broker firms being sued by Atlas. Many of these cases have been moved to federal court, challenging the law as an overreach and a violation of the First Amendment. The Third Circuit Court of Appeals has yet to rule, and the case is widely anticipated to reach the U.S. Supreme Court. This legal challenge mirrors similar efforts across at least 14 other states that have adopted laws similar to Daniel’s Law, though some, like West Virginia’s, have already been struck down as unconstitutional.
Privacy expert Justin Sherman highlights the persistent lobbying efforts by powerful industries, including big tech, social media, and cryptocurrency firms, against comprehensive federal data privacy legislation. He argues that the current landscape, where public records are often exempt from privacy protections, allows people-search companies to thrive. Sherman points to the recent breach at IDScan.net, which exposed the driver’s license information of over 153 million Americans, as a stark example of the dangers posed by lax data protection laws. He emphasizes that despite numerous "wake-up calls," the lack of robust federal privacy legislation is not due to a lack of awareness but rather a deliberate resistance from industry stakeholders. The public’s expectation that everyone should be covered by privacy laws, not just specific groups like law enforcement, underscores the growing demand for stronger protections in the digital age.

