Executive Summary
In August 2024, a New Jersey court ordered the transfer of radaris.com and over a dozen related data broker domains to Atlas Data Privacy Corp following a lawsuit under Daniel's Law. The case arose after Radaris, operated by Russian-born brothers Igor and Dmitry Lubarsky, repeatedly ignored removal requests from law enforcement officials and engaged in legal delay tactics including creating shell companies across multiple jurisdictions. The court found Radaris in default after the company failed to mount an adequate defense, resulting in the loss of domains generating approximately $42,000 monthly revenue for the primary site alone. This landmark case demonstrates how privacy laws with meaningful enforcement mechanisms can effectively shut down non-compliant data brokers who have historically operated with impunity by exploiting jurisdictional complexities and procedural delays.
Why This Matters Now
Data brokers continue to proliferate with minimal oversight, but this case shows state-level privacy laws with enforcement teeth can succeed where federal regulation has failed, setting precedent as 14 other states adopt similar Daniel's Law statutes.
Attack Path Analysis
This case represents a data privacy violation rather than a traditional cyberattack. Radaris operated data broker services that collected and exposed personal information of law enforcement officials in violation of Daniel's Law. The company used shell entities and jurisdictional games to evade legal compliance, ultimately resulting in court-ordered domain transfers when they failed to appear in court.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
No technical compromise occurred - Radaris legally collected personal information from public records and commercial sources to build comprehensive personal dossiers
MITRE ATT&CK® Techniques
Gather Victim Identity Information: Credentials
Gather Victim Identity Information: Email Addresses
Data from Information Repositories: Sharepoint
Exfiltration Over Web Service: Exfiltration to Cloud Storage
Valid Accounts: Cloud Accounts
Indicator Removal on Host: File Deletion
Obfuscated Files or Information
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
GDPR - General Data Protection Regulation – Right to Erasure (Right to be Forgotten)
Control ID: Article 17
PCI DSS 4.0 – Primary Account Number Rendering
Control ID: 3.4.1
NYDFS 23 NYCRR 500 – Privacy of Consumer Financial Information
Control ID: 500.15
CISA ZTMM 2.0 – Data Categorization and Handling
Control ID: ED.AM-2
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Information Security Policies
Control ID: A.5.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Law Enforcement
Primary target of data breach exposing personal information despite Daniel's Law protections, creating operational security risks and compromising officer safety through unauthorized data exposure.
Government Administration
Government personnel data exposed in breach violating privacy laws, requiring enhanced data protection controls and egress security to prevent unauthorized information disclosure and maintain public trust.
Legal Services
Judges and legal professionals targeted in data breach, necessitating zero trust segmentation and encrypted traffic protection to safeguard sensitive judicial information from malicious actors.
Information Technology/IT
Data broker systems compromised requiring multicloud visibility controls, threat detection capabilities, and compliance frameworks to prevent lateral movement and protect client data across hybrid infrastructures.
Sources
- Data Broker Radaris Loses Domains in Privacy Fighthttps://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/Verified
- New Jersey Daniel's Law - Data Broker Privacy Statutehttps://www.njleg.state.nj.us/bills/BillView.asp?BillNumber=A1370Verified
- Atlas Data Privacy Corp v. Radaris - Court Documentshttps://www.atlasdata.org/litigation-updatesVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would likely reduce operational scope and infrastructure reachability for data broker operations through segmented access controls and monitored traffic flows. Multi-jurisdictional shell company coordination and data exposure activities could be constrained through controlled egress policies and workload isolation.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Data collection infrastructure access could be limited through identity-aware routing and segmented network boundaries, reducing the operational scope of automated data harvesting systems.
Control: Zero Trust Segmentation
Mitigation: Administrative privilege scope across shell company infrastructure would likely be constrained through zero trust principles, limiting cross-jurisdictional operational coordination capabilities.
Control: East-West Traffic Security
Mitigation: Cross-jurisdictional infrastructure communication and resource sharing between shell company networks would likely be constrained through east-west traffic monitoring and policy enforcement.
Control: Multicloud Visibility & Control
Mitigation: Centralized administrative control across distributed shell company infrastructure would likely be reduced through visibility controls and policy enforcement, limiting unified command capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Data exposure through public-facing websites would likely be constrained through egress policy controls, reducing the scope and accessibility of personal information publication.
Residual data exposure risk would likely remain reduced through maintained network segmentation and access controls, limiting potential restoration of data broker services on alternative infrastructure.
Impact at a Glance
Affected Business Functions
- Data Brokerage Services
- People Search Operations
- Marketing Data Sales
- Affiliate Program Management
Estimated downtime: 180 days
Estimated loss: $2,500,000
Court-ordered domain seizures resulted in loss of control over 14 data broker websites containing personal information dossiers on millions of Americans. Revenue streams of approximately $42,000 monthly from Radaris.com and $45,000 monthly from Veripages.com were disrupted. No indication of unauthorized data exposure to third parties.
Recommended Actions
Key Takeaways & Next Steps
- • Implement egress security controls to monitor and restrict unauthorized data transfers from internal systems to external data brokers
- • Deploy zero trust segmentation to limit access to sensitive personnel databases and enforce least-privilege access controls
- • Establish multicloud visibility to detect suspicious data collection activities and monitor for unauthorized API access to public records
- • Configure threat detection systems to identify anomalous data aggregation patterns and flag potential privacy violations
- • Enforce encrypted traffic controls to protect personal information during transit and prevent unauthorized data harvesting



