Skip to content
CYBERSECURITY & DATA PRIVACY

Court-Ordered Transfer of Radaris.com Marks a Major Shift in the Battle Over Data Broker Accountability

The consumer data broker Radaris.com has long maintained a reputation for ignoring requests to remove personal information from its vast network of online people-search services. That operational model recently caught up with the company in a high-stakes lawsuit alleging that Radaris violated a New Jersey privacy law providing for hefty fines against data brokers that publish the personal information of state law enforcement officials. Facing repeated stonewalling and procedural prevarication by attorneys representing Radaris, the presiding judge ordered that radaris.com and more than a dozen other data broker domains be transferred directly to the plaintiffs.

The legal showdown began in February 2024, when Radaris was sued by Atlas Data Privacy Corp, a company that has been actively pursuing data brokers alleged to be violating a New Jersey statute known as Daniel’s Law. Named in honor of a family tragedy involving a federal judge, the statute allows state law enforcement officials, government personnel, judges, and their family members to have their personal information completely removed from commercial data brokers and people-search services. Furthermore, the legislation provides for statutory fines of $1,000 per violation against companies that ignore removal requests.

Less than a month after Atlas filed its lawsuit, investigative reporting shed light on the co-founders of Radaris: Igor and Dmitry Lubarsky, Russian-born brothers residing in Massachusetts who operate a sprawling network of people-search companies, along with various Russian-language dating services and affiliate marketing programs. Attorneys representing the Lubarsky brothers subsequently threatened to file a defamation lawsuit unless the reporting was retracted and a formal apology issued. Their legal counsel asserted that the reporting was inaccurate and that the true owners of the enterprise were instead Ukrainians living in Ukraine.

Despite the legal threats, subsequent investigations detailed how the Lubarsky brothers built and operated Radaris and other data broker entities using a fictitious CEO’s identity. Radaris’s attorney at the time—a lawyer with the Boston Law Group named Val Gurvits—admitted in subsequent proceedings that his clients had invented the pseudonym "Gary Norden" and that Radaris had issued multiple press releases over the years quoting the fake executive while seeking capital from potential investors.

Attorneys for Radaris waited until the absolute last minute to appear in court and contest what appeared to be an inevitable default judgment in favor of the plaintiffs, subsequently arguing that Atlas had failed to properly serve the true owners and operators of Radaris and several associated sister companies.

In response, Atlas refiled the lawsuit in June 2025, dramatically expanding the scope of the litigation to include a larger group of Radaris-affiliated data brokers accused of violating Daniel’s Law. Matt Adkisson, president and CEO of Atlas, stated that Radaris relied on a familiar defense playbook: delaying proceedings until the final possible moment while playing an intricate shell game regarding the company’s true country of origin and the individuals listed as its beneficial owners.

According to Adkisson, this phase of the litigation involved a constant shifting of corporate structures, privacy policies, and shell entities incorporated in offshore jurisdictions such as the Marshall Islands, the British Virgin Islands, and the Seychelles. Behind the scenes, defense attorneys repeatedly argued that specific corporate entities merely operated the domains and were the proper parties to sue, only for those entities to be quietly discarded and replaced by new ones as judgments loomed, while the lawyers simultaneously claimed that the underlying parent companies holding the actual domain assets bore no responsibility.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

When defendants updated their terms of service to assert that Radaris was suddenly managed by an entity in the Marshall Islands, Atlas hired a local investigator who quickly discovered that the newly cited management company did not even exist. This tactic mirrored previous litigation, including a 2017 class action lawsuit that Radaris temporarily lost because it failed to contest the claims in court. When those plaintiffs attempted to collect on a $7.5 million default judgment, the court ordered the domain registry Verisign to transfer the radaris.com domain name to the plaintiffs.

Although Mr. Gurvits successfully appealed that 2017 verdict by arguing that the lawsuit had failed to name the actual domain owner—a Cyprus-registered company called Bitseller Expert Limited—the operator of Radaris subsequently shifted to Andtop Company, an entity formed in the Marshall Islands in October 2020. The plaintiffs in that earlier matter never refiled their complaint, allowing the enterprise to continue its operations largely unimpeded.

Raj Parikh, a partner at PEM Law in New Jersey who manages the Daniel’s Law litigation for Atlas, noted that this strategy of attrition had served the defendants well for a decade. Plaintiffs’ attorneys would routinely tire of the procedural obstacles and abandon their efforts, a strategy that would likely have succeeded again given the inherent difficulties of recovering financial judgments from foreign actors. However, recognizing the direct security threat posed by the website to law enforcement officers and public officials in New Jersey, the legal team committed the necessary time and resources to see the litigation through to its conclusion.

On August 26, the judge in the New Jersey case ruled that the defendants had been afforded multiple opportunities to appear and defend against the claims but had repeatedly failed to do so. Mr. Gurvits declined to comment on the ruling, indicating that the matter had been reassigned to another attorney, Victor Worms. In response to inquiries, Mr. Worms asserted that the New Jersey court transferred Radaris.com to Atlas as part of a default judgment against Radaris.com, which he argued is not a legal entity with the capacity to be sued.

Worms stated that the defense has filed a motion to vacate the default judgment on the grounds that it is void, and indicated an intention to pursue all appropriate appeals, contending that the forced transfer of the domain amounts to an unconstitutional forfeiture.

While radaris.com still appears prominently in search engine results for U.S. residents, the domain no longer functions as a commercial storefront selling detailed dossiers on millions of Americans. Its homepage now features a prominent notice from Atlas detailing the court-ordered domain transfer, alongside links to prior investigative reporting on the enterprise.

Email Confirmations

During the course of the litigation, Atlas reportedly obtained more than 10,000 internal emails and corporate documents that substantiate previous findings regarding the ownership and administrative structure of Radaris and its network of subsidiary companies.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

According to Atlas, the documentary evidence demonstrates that numerous nominal legal entities—including Radaris America, Inc., Bitseller Expert Limited, Digital Orbit Corp, Core Solutions Group Inc, Lucky Solutions Inc, Virtura Corp, Veripages Inc., Nuform Solutions Inc., Growth Data Advisors Inc., and Property Experts, Inc.—are all administered by the same core group of individuals using shared mailboxes, unified banking and payment processing channels, and a single virtual office address.

A summary compiled by Atlas indicates that these records establish that radaris.com and at least twenty-five other people-search websites operate as a single unified enterprise managed by a small group based in the Boston area. The administrative, financial, and technical infrastructure of these sites has historically relied on specific mail domains and their corporate successors. Furthermore, internal records indicate that Radaris.com generates approximately $42,000 per month, while sister site Veripages.com pulls in roughly $45,000 monthly through partnerships with marketing firms such as the Lifetime Value Company, whose brands include PeopleLooker, PeopleSmart, NumberGuru, and the vehicle history platform Bumper.

Additional disclosures from Atlas suggest that the Radaris family of websites has generated up to $25,000 monthly through partnerships with Onerep, a data privacy firm that assists individuals in removing their personal information from people-search directories. Previous investigations revealed that Onerep’s founder had historically launched and operated dozens of people-search sites while simultaneously offering removal services, creating an industry ecosystem where companies profit from both the exposure and the removal of consumer data.

To date, the New Jersey court has transferred 14 domain names belonging to the Radaris network to Atlas. While radaris.com now redirects entirely to the court-mandated transfer notice, the broader legal battle surrounding the statutes governing data brokers remains ongoing.

The Road Ahead

Although the Radaris network faces potential statutory fines of $1,000 per violation under Daniel’s Law, the broader enforcement of the statute is currently stalled by constitutional challenges brought by roughly 150 other consumer data broker firms facing similar lawsuits from Atlas.

The data broker industry has successfully transferred at least 70 of the Atlas lawsuits to federal court, arguing that the New Jersey statute is overly broad and infringes upon First Amendment protections. While the U.S. Court of Appeals for the Third Circuit has yet to render a decision on the constitutional challenge, legal observers anticipate that the case will ultimately be appealed to the U.S. Supreme Court.

Meanwhile, at least 14 other states have enacted privacy legislation modeled after New Jersey’s Daniel’s Law, with several additional states considering comparable measures. However, the legal durability of these statutes remains uncertain; a federal district court ruled West Virginia’s version of Daniel’s Law facially unconstitutional under the First Amendment.

Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security

Justin Sherman, a privacy expert and author of the forthcoming book The Middlemen, which examines the data broker industry’s role in modern surveillance, noted that federal lawmakers have long faced intense lobbying from technology companies opposed to comprehensive federal privacy standards.

Sherman pointed out that opposition now spans multiple powerful sectors, including social media platforms, big tech firms, cryptocurrency enterprises, and artificial intelligence proponents who argue that restricting data collection and scraping will undermine economic competitiveness.

According to Sherman, people-search companies will continue to operate profitably unless Congress enacts meaningful federal consumer privacy and data protection legislation tailored to the digital age. Most state-level privacy measures continue to exempt records classified as public or government documents, including voting registries, property filings, marriage certificates, motor vehicle records, criminal histories, court files, death records, professional licenses, and bankruptcy filings.

While numerous states have implemented age-verification mandates requiring residents to submit identification to access adult online content, no federal statute regulates how the third-party entities scanning those driver’s licenses may store, share, or utilize the collected data. Analysts note that the absence of such statutory safeguards mirrors vulnerabilities exposed in major data breaches, such as the recent incident involving IDScan.net, which compromised the driver’s license records of more than 153 million Americans.

As legal and legislative battles continue across multiple jurisdictions, privacy advocates emphasize that piecemeal state statutes like Daniel’s Law highlight a much broader, systemic failure to secure basic personal data at the federal level.

Leave a Reply

Your email address will not be published. Required fields are marked *