Executive Summary

In August 2024, a New Jersey court ordered the transfer of radaris.com and over a dozen related data broker domains to Atlas Data Privacy Corp following a lawsuit under Daniel's Law. The case arose after Radaris, operated by Russian-born brothers Igor and Dmitry Lubarsky, repeatedly ignored removal requests from law enforcement officials and engaged in legal delay tactics including creating shell companies across multiple jurisdictions. The court found Radaris in default after the company failed to mount an adequate defense, resulting in the loss of domains generating approximately $42,000 monthly revenue for the primary site alone. This landmark case demonstrates how privacy laws with meaningful enforcement mechanisms can effectively shut down non-compliant data brokers who have historically operated with impunity by exploiting jurisdictional complexities and procedural delays.

Why This Matters Now

Data brokers continue to proliferate with minimal oversight, but this case shows state-level privacy laws with enforcement teeth can succeed where federal regulation has failed, setting precedent as 14 other states adopt similar Daniel's Law statutes.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Daniel's Law is a New Jersey statute that allows law enforcement officials, judges, and their families to have their personal information completely removed from commercial data brokers, with $1,000 fines per violation for non-compliance.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely reduce operational scope and infrastructure reachability for data broker operations through segmented access controls and monitored traffic flows. Multi-jurisdictional shell company coordination and data exposure activities could be constrained through controlled egress policies and workload isolation.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Data collection infrastructure access could be limited through identity-aware routing and segmented network boundaries, reducing the operational scope of automated data harvesting systems.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Administrative privilege scope across shell company infrastructure would likely be constrained through zero trust principles, limiting cross-jurisdictional operational coordination capabilities.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Cross-jurisdictional infrastructure communication and resource sharing between shell company networks would likely be constrained through east-west traffic monitoring and policy enforcement.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized administrative control across distributed shell company infrastructure would likely be reduced through visibility controls and policy enforcement, limiting unified command capabilities.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exposure through public-facing websites would likely be constrained through egress policy controls, reducing the scope and accessibility of personal information publication.

Impact (Mitigations)

Residual data exposure risk would likely remain reduced through maintained network segmentation and access controls, limiting potential restoration of data broker services on alternative infrastructure.

Impact at a Glance

Affected Business Functions

  • Data Brokerage Services
  • People Search Operations
  • Marketing Data Sales
  • Affiliate Program Management
Operational Disruption

Estimated downtime: 180 days

Financial Impact

Estimated loss: $2,500,000

Data Exposure

Court-ordered domain seizures resulted in loss of control over 14 data broker websites containing personal information dossiers on millions of Americans. Revenue streams of approximately $42,000 monthly from Radaris.com and $45,000 monthly from Veripages.com were disrupted. No indication of unauthorized data exposure to third parties.

Recommended Actions

  • Implement egress security controls to monitor and restrict unauthorized data transfers from internal systems to external data brokers
  • Deploy zero trust segmentation to limit access to sensitive personnel databases and enforce least-privilege access controls
  • Establish multicloud visibility to detect suspicious data collection activities and monitor for unauthorized API access to public records
  • Configure threat detection systems to identify anomalous data aggregation patterns and flag potential privacy violations
  • Enforce encrypted traffic controls to protect personal information during transit and prevent unauthorized data harvesting

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image