A court took 15 Radaris domains under Daniel's Law. Radaris.net was still serving profiles 21 days later
Two New Jersey default judgments moved radaris.com and 14 sister domains to Atlas Data Privacy. The Radaris brand kept publishing US profiles on radaris.net, a domain a 2017 federal order also seized before it was handed back.
By Parminder Kumar Sharma · · 21 min read

Fifteen domains moved. The brand kept publishing
On 17 September 2026 we requested each of the 15 domain names listed in two New Jersey default judgments against the Radaris people-search group. All 15 returned the same page: a notice from Atlas Data Privacy Corporation saying the domain has been transferred to it by court order. In the same session, from the same London connection, radaris.net returned a working Radaris people-search site. It served a US profile page for a common name, linked to a sitemap dated up to 17 September, and its terms of service state that "Radaris is operated by Dilangi, Inc, Majuro, Marshall Islands."
That is 21 days after the New Jersey court entered judgment against radaris.com on 27 August. It is also not the first time radaris.net has been named in a court order. In June 2017 a federal judge in California ordered radaris.com, radaris.net and five other domains transferred to class plaintiffs. Ten and a half months later the same judge granted relief to two companies that had not been named in the case, and the domains went back.
This briefing sets out who sued and under what law, exactly what the two judgments are reported to say, what the 2017 case teaches about domain seizure as a remedy, what was still running when we checked, and what a UK organisation protecting executives or staff from doxxing can realistically do. The key question is whether a court turning domain control into the enforcement mechanism is powerful or shallow. On this record the honest answer is both, and the diagram below shows why.
Who sued, and under what law
The plaintiffs. Atlas Data Privacy Corporation and five individual plaintiffs filed Atlas Data Privacy Corporation, et al. v. Radaris.com, et al. on 8 February 2024 in the Superior Court of New Jersey, Law Division, Middlesex County, docket MID-L-000847-24. That is the caption and docket number Atlas prints on every seized domain. According to the same notice, an amended complaint was filed on 27 May 2025 in which Atlas asserted claims assigned to it by approximately 21,760 law enforcement officers, prosecutors and other covered persons. KrebsOnSecurity describes Atlas as having re-filed in June 2025 with many more Radaris-linked defendants; we use the date Atlas itself gives.
Atlas is a company, not a public body. The New Jersey Supreme Court describes it as offering an online service that covered persons use to send non-disclosure notices to data brokers, which Atlas then pursues as assignee of their claims.
The law. The claims are brought under Daniel's Law, N.J.S.A. 56:8-166.1, enacted in November 2020 after the July 2020 shooting of Daniel Anderl, son of US District Judge Esther Salas, at the family home. As amended, and as quoted in full by the New Jersey Supreme Court on 12 August 2026, the statute works like this:
- An authorised person sends written notice asking a person, business or association to stop disclosing the home address or unpublished home telephone number of a covered person.
- The recipient must stop disclosing it, on the internet or otherwise, not later than 10 business days after receiving the notice.
- A recipient that does not is liable to the covered person or the covered person's assignee, who may sue in the Superior Court.
- The court "shall award" actual damages but not less than liquidated damages of $1,000 for each violation, punitive damages on proof of willful or reckless disregard of the law, reasonable fees and costs, and any other preliminary and equitable relief it considers appropriate.
The definition of covered person quoted by the court is the 2022 wording: active, formerly active or retired judicial officers, law enforcement officers and prosecutors, plus immediate family members in the same household. We did not review later amendments to that definition.
Where the law stands. On 12 August 2026 the New Jersey Supreme Court, answering a question certified by the US Court of Appeals for the Third Circuit in Atlas v. We Inform (a group of 40 appeals, not the Radaris case), held unanimously that Daniel's Law contains no mental state requirement for actual damages liability. It was explicit that this did not decide the constitutional challenge: whether the law is constitutional "is for the Third Circuit to determine." KrebsOnSecurity reported on 16 September that the Third Circuit had not yet ruled, and we found no ruling. Separately, on 20 August 2025 a federal district court held West Virginia's version of Daniel's Law facially unconstitutional under the First Amendment, according to a summary by Troutman Pepper Locke, a firm whose lawyers act for data broker appellants in the New Jersey litigation.
So the statute behind the Radaris seizures is in force, has just been read as requiring no mental state for actual damages, and faces a live constitutional appeal. A judgment built on it is only as durable as the statute and the default procedure behind it.
The two New Jersey judgments against the Radaris defendants: what is on the record and what is not. Source: Atlas notices served on the seized domains, which quote the judgments; KrebsOnSecurity for the defence position. We could not obtain the judgments themselves.
| Item | Stated | Not stated |
|---|---|---|
| Court | Superior Court of New Jersey, Law Division, Middlesex County, MID-L-000847-24 | The judge who signed each judgment |
| Type | Final judgment by default, entered 12 June 2026 and 27 August 2026 | Any contested ruling on the merits |
| Defendants | Radaris, LLC and Radaris America, Inc. (June); 15 domain names named as defendants | Any individual defendant |
| Finding | Plaintiffs established Daniel's Law violations as set out in the amended complaint | How many covered persons' details were published |
| Remedy | Seizure of each domain; permanent injunction reaching affiliated domains and persons in concert | Any damages figure |
| Status | Defence counsel says a motion to vacate is filed and appeals will follow | A hearing date or ruling on that motion |
What the court ordered, and what actually moved
There are two judgments, not one. The notice on centeda.com says that on 12 June 2026 the court entered a final judgment by default against Radaris, LLC, Radaris America, Inc. and twelve domain-name defendants: centeda.com, clubset.com, comfibook.com, dataveria.com, difive.com, hudwayglass.com, kwold.com, newenglandfacts.com, pub360.com, rain-street.org, verecor.com and veriforia.com. The notice on radaris.com says that on 27 August 2026 the court entered a final judgment by default against radaris.com, rehold.com and trustoria.com. KrebsOnSecurity dates the court's finding to 26 August; the notice gives 27 August as the date of entry. We use the notice.
Both notices quote the same two remedies. The court "awarded the seizure of this domain" and granted a permanent injunction restraining the defendants and those acting in concert with them from disclosing covered persons' protected information through the named domains "as well as any subdomains, affiliated domains or sites within the possession, custody or control of Defendants." That last phrase matters later.
KrebsOnSecurity counts 14 domains transferred so far. The two judgments list 15, and all 15 served the Atlas notice when we checked. We cannot reconcile the difference from the public record; it may reflect timing.
What the registry records show. Verisign's WHOIS, which is the authoritative record for .com, shows radaris.com, rehold.com and trustoria.com last updated on 10 September 2026, 14 days after the August judgment, and now held at registrar NameCheap on Cloudflare name servers. Nine of the eleven .com domains in the June judgment show a last update of 24 July 2026, 42 days after that judgment; centeda.com and comfibook.com show later updates. A WHOIS "updated" date records the most recent change to a domain, not necessarily the transfer, so these intervals are an inference about timing rather than proof of it. They are consistent with the notices: the domains changed hands, and the new holder repointed them.
The 15 domains named in the two judgments, registry last-updated dates and what each returned on 17 September 2026. Sources: Atlas notices; Verisign WHOIS (.com) and Public Interest Registry WHOIS (.org); our HTTP checks.
| Domain | Judgment | Registry last updated | Seen 17 Sep |
|---|---|---|---|
| radaris.com | 27 Aug 2026 | 10 Sep 2026 | Atlas notice |
| rehold.com | 27 Aug 2026 | 10 Sep 2026 | Atlas notice |
| trustoria.com | 27 Aug 2026 | 10 Sep 2026 | Atlas notice |
| centeda.com | 12 Jun 2026 | 31 Aug 2026 | Atlas notice |
| clubset.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| comfibook.com | 12 Jun 2026 | 3 Sep 2026 | Atlas notice |
| dataveria.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| difive.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| hudwayglass.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| kwold.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| newenglandfacts.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| pub360.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| rain-street.org | 12 Jun 2026 | 12 Aug 2026 | Atlas notice |
| verecor.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
| veriforia.com | 12 Jun 2026 | 24 Jul 2026 | Atlas notice |
Radaris's response. We found no public statement from Radaris. KrebsOnSecurity reports that Val Gurvits of Boston Law Group, who has represented Radaris before, declined to comment and referred questions to another lawyer, Victor Worms. Mr Worms told KrebsOnSecurity the judgment was entered against radaris.com, which is not a legal entity, that a motion to vacate has been made because "a non-entity has no legal capacity to sue or be sued", and that appeals will follow because the transfer amounts to a forfeiture in violation of constitutional principles. Neither a vacatur ruling nor an appeal had been reported when we checked.
Atlas's chief executive, Matt Adkisson, told KrebsOnSecurity that during the case Radaris's stated operators kept changing among entities in places such as the Marshall Islands, the British Virgin Islands and the Seychelles, which he called "their island-hopping phase." That is Atlas's account, from a party to the litigation. Read alongside the 2017 case below, it offers a plausible explanation for why Atlas sued the domain names themselves: the remedy attaches to the asset whichever company claims to run it that month. That explanation is our inference, not something Atlas or the court has stated.
It has been tried before: the 2017 order and the 2018 reversal
The federal docket in Huebner v. Radaris, LLC (N.D. Cal. 3:14-cv-04735) is a close rehearsal of this year's events, and it is fully public.
- 24 October 2014. Class action filed against Radaris, LLC, Radaris America, Inc. and a named individual under the Fair Credit Reporting Act and California law.
- 19 June 2017. Judge Vince Chhabria granted default judgment. The defendants had not appeared. The order found them to be a consumer reporting agency, held them jointly and severally liable for $7,500,000, and ordered registrars, registries, hosts and search engines to stop serving radaris.com, radaris.net, radaris.us, radaris.biz, radaris.info, radaris.org and trustoria.com, to transfer those domains to the plaintiffs, and to delete the databases behind them.
- After the judgment. According to the plaintiffs' later status report, the registrar for radaris.com and radaris.biz, EuroDNS, refused to comply. The plaintiffs went to the registries instead, Verisign for .com and Neustar for .biz, which changed the registrar of record so the domains could be moved to the plaintiffs.
- 1 March 2018. Two non-parties, Accuracy Consulting Ltd. and Bitseller Expert Limited, filed an emergency motion for relief from the judgment.
- 4 May 2018. The court granted it. The current record, it said, "does not permit a conclusion that Accuracy and Bitseller are acting in concert with the named defendants," and the plaintiffs could have named them at the outset.
- 7 June 2018. The plaintiffs reported that, following that order, they had transferred the domains to Accuracy, and that Amazon had indicated it would not comply with the order to delete the underlying databases.
- 12 June 2018. Case closed. KrebsOnSecurity reports the plaintiffs never re-filed.
From judgment to reversal took 319 days. The 2017 order was broader than anything the 2026 notices describe: it reached payment processors, advertisers, hosting providers and the databases themselves. It still did not hold, because the companies that claimed the domains had not been parties.
What was still running on 17 September
We checked the Radaris domains named in both court cases, the regional sites radaris.net itself links to, and sister sites named in KrebsOnSecurity's 2024 reporting. All checks were HTTP requests from a single UK connection on 17 September 2026. We did not search for any real individual, did not create accounts and did not attempt to pass bot challenges.
Radaris-branded and related sites that were not showing an Atlas notice on 17 September 2026. Sources: our HTTP checks; the sites' own terms and pages; Verisign WHOIS; KrebsOnSecurity for Atlas's claims.
| Site | What we observed | What it does not establish |
|---|---|---|
| radaris.net | HTTP 200. US people-search profile page for a common name. Sitemap links dated 12 to 17 Sep 2026. Terms name Dilangi, Inc, Marshall Islands. WHOIS last updated 8 Sep 2026. | Who controls it; whether it shows any covered person's data; whether the New Jersey injunction reaches it |
| radaris.co.uk | HTTP 200 with Radaris UK branding and the same Dilangi, Inc terms. Footer dated 2023. A test profile address returned HTTP 410. | Whether it holds UK residents' data at all |
| radaris.de, .es, .it, .ru, .eu, .asia, .in and radarisaustralia.com | All HTTP 200 with Radaris regional branding; all linked from the radaris.net regional sites page. | How much data each serves; who operates each |
| veripages.com | Live people search behind a bot check, footer dated 2026. Atlas says it is part of the same operation, per KrebsOnSecurity. | Atlas's email corpus is unpublished and untested in court |
| homeflock.com, bizstanding.com | Bot challenge; not checked. | Anything about current content |
Three details on radaris.net stand out. Its privacy policy, dated 1 May 2026, still sends users to a contact form on radaris.com, a domain its operator no longer controls. Its Data Privacy Center has a dedicated route for Daniel's Law covered persons. And radaris.net sits under the .net registry, which is operated by Verisign, the same US registry operator that answered the 2017 order. In principle it is as reachable by a US court order as radaris.com was. The regional sites mostly are not: country-code registries such as those for .co.uk, .de and .ru sit outside US jurisdiction, which is where a registry-level remedy from a US state court gets weakest. That last point is general inference about how the domain system works, not something any court in these cases has considered.
Powerful or shallow? What the evidence supports
What domain seizure removed. Radaris.com was registered on 30 July 2009, according to Verisign. Seventeen years of links and search ranking now point at a court notice. KrebsOnSecurity reports that radaris.com still appears prominently when people search for US residents by name, and that anyone clicking through now sees Atlas's notice instead of a dossier. For a business that, according to Atlas's reading of internal emails, earned roughly $42,000 a month from radaris.com alone, that is the asset worth taking. It is also the only remedy in the case that has visibly taken effect: no damages figure has been published, and Atlas's own lawyer, Raj Parikh of PEM Law, told KrebsOnSecurity that recovering money from foreign actors will be difficult.
What it did not remove. A domain is an address. The judgments quoted by Atlas do not say that any database was seized or deleted, and the 2017 attempt to order database deletion failed when the hosting provider declined after the reversal. The operator, whoever it is, kept a working product under the same brand on radaris.net, and a network of regional Radaris sites, 21 days after losing radaris.com. Nothing in the record shows that the underlying data changed.
What decides whether it is shallow. Two things, neither yet known. First, whether the judgments survive the motion to vacate and any appeal; the 2018 precedent shows a domain order can be undone on due process grounds. Second, whether Atlas goes back to court under the "affiliated domains" language and whether that language is applied to radaris.net or the regional sites. If the answer is yes each time, domain seizure becomes a repeatable, if slow, lever: 931 days elapsed between filing and the radaris.com judgment. If the answer is no, the operator only has to keep one address the order does not name.
Our reading of the evidence: domain control is powerful against the brand's best-known address and its search visibility, and shallow against the capability behind it. Its depth depends on the plaintiff's willingness to keep returning to court for the next domain. Parikh put the history bluntly: "In the past, they won by attrition."
Method, interests and allegations
Every party in this story has an interest, and the record is uneven.
- Atlas is a commercial company that takes assignments of covered persons' claims and pursues data brokers for them. Its domain notices are a litigant's summary of the judgments; we quote the judgments only through them because we could not obtain the orders from the New Jersey courts. Its description of an email corpus of more than 10,000 documents, of revenue figures and of commercial partnerships comes from a summary Atlas shared with KrebsOnSecurity. That corpus is not public and those claims have not been tested in a contested hearing.
- KrebsOnSecurity has investigated Radaris's ownership since March 2024 and reported being threatened with a defamation suit by Radaris's lawyers over that reporting. Its account of who founded and runs Radaris is its own reporting and has been disputed by Radaris's lawyers. We do not repeat the individuals' names here because nothing in this briefing turns on them and no court has made findings about them.
- Radaris's lawyers argue the judgment is void and the transfer an unconstitutional forfeiture. That is an argument, not a finding.
- The data broker industry is challenging Daniel's Law on First Amendment grounds. The West Virginia ruling cited here is summarised by lawyers who act for data broker appellants in the New Jersey litigation.
The default judgments are real court orders, and the domains visibly changed hands. Everything about ownership, revenue and intent beyond that is attributed to whoever said it.
The UK angle: reachable here, harder to reach from here
Reachability. Every live site in the table above loaded from a London connection without a geoblock, and the radaris.net profile page we tested was readable without logging in. That is a single-day test from one connection, not a survey, but it is enough to say a UK-based attacker can use these services as easily as a US one. A UK executive with a US footprint, such as a US home, US-registered company or US phone number, is the most likely to appear; we did not test how much data about UK residents any of these sites holds, and radaris.co.uk returned no profile for our test.
The law that applies. There is no UK counterpart to Daniel's Law that we could find: no statute gives UK officials or executives a notice-and-takedown right backed by liquidated damages. The closest general tool is UK GDPR. Article 3(2) applies it to a controller not established in the UK where its processing relates to offering goods or services to people in the UK or monitoring their behaviour in the UK. Article 27 then requires that controller, subject to narrow exceptions, to designate a UK representative whom the Information Commissioner and data subjects can address. Whether a people-search site built around US residents' data is offering services to a UK data subject in the Article 3(2) sense is a question of fact that we have not seen a UK regulator or court answer for this kind of site. Radaris's terms name a Marshall Islands operator, and the radaris.net privacy policy and terms we reviewed do not mention the UK or UK GDPR or name a UK representative. We did not review every page.
What the ICO's data broking record shows. The ICO's leading data broking enforcement is its enforcement notice to Experian Limited, dated 12 October 2020, after a two-year investigation into how credit reference agencies used personal data for direct marketing. The notice noted Experian's use of sources including the Open Electoral Register. On 20 February 2023 the First-tier Tribunal allowed Experian's appeal in large part and substituted a scaled-down notice. On 22 April 2024 the Upper Tribunal dismissed the ICO's appeal, and the ICO later confirmed it would not appeal further. That case concerned a UK-established credit reference agency and the transparency principle, not an offshore people-search site, but it is the precedent UK teams have. It shows that even against a UK company inside the regulator's reach, enforcement over data broking was slow and was substantially cut back on appeal. Against an operator that names a Marshall Islands company, we would expect it to be harder, not easier; that is inference.
UK levers for reducing a person's exposure to people-search and data broker sites. Sources: GOV.UK, Companies House, UK GDPR on legislation.gov.uk, ICO, Google Search Help.
| Lever | What it does | What it does not do |
|---|---|---|
| Open register opt-out | Removes a voter from the version of the electoral register anyone can buy | Cannot remove anyone from the full register; GOV.UK does not say copies already sold are recalled |
| Companies House removal (SR01) | Removes a home address, signature, occupation or, on pre-2015 filings, day of birth from filed documents, at 34 pounds per document | Does not reach sites that have already copied the filings |
| UK GDPR erasure and objection requests | Asserts rights against controllers within UK GDPR scope, including non-UK ones under Article 3(2) | No liquidated damages; enforceability against an offshore operator is uncertain |
| Complaint to the ICO | Can lead to investigation and an enforcement notice | The Experian case shows notices can be cut back on appeal |
| Google Results about you and doxxing removal | Requests removal of contact details and doxxing content from Google Search results | Content stays on the site and on other search engines |
What to do, in order
For a UK organisation running executive protection or a staff doxxing response, the Radaris case changes one working assumption: a headline about a broker losing its domain is not a reason to close a ticket. The order below puts the cheap, durable steps first and the uncertain ones last.
Take this with you
Exposure reduction for people-search and data broker sites
- Agree who is in scope: named executives, staff who have been threatened, and anyone whose role draws hostile attention, and record their consent before searching for them.
- Close the UK sources first: help each person opt out of the open register and, where they are or were a director, apply to Companies House to remove home addresses from filed documents.
- Search each person across brands and extensions, not single domains: for Radaris that means radaris.net and the regional sites as well as the seized radaris.com, plus sister brands such as veripages.com.
- Record evidence before acting: URL, date, time, a screenshot and what personal data is shown, kept somewhere access-controlled.
- Use search engine removal tools for contact details and doxxing content, because delisting reduces discovery even when the source site will not act.
- Send erasure and objection requests to the controller a site names in its own terms, ask for its UK representative, and diarise the response deadline: one month under UK GDPR Article 12A, extendable by two months.
- Where a person is a New Jersey covered person or has comparable US state protections, use that route through qualified US counsel rather than a generic request.
- Escalate to the ICO where a controller in scope ignores a valid request, while being realistic about timescales.
- Treat any threat that uses the exposed details as a security incident: involve the police and legal counsel, and do not rely on takedown as the response.
- Re-run the searches on a schedule, monthly for high-risk people, because the Radaris record shows the same brand can reappear on another address within weeks.
The question that exposes the gap
A New Jersey court did something UK regulators have not attempted: it took a data broker's best-known address away and put a warning in its place. Twenty-one days later, the same brand was answering on the next extension, from a domain a federal court had already tried and failed to take.
So the question for anyone who owns a doxxing or executive protection process is not whether Radaris lost its domains. It is this: when the order names the address and not the database, who in your organisation checks the next address, and how soon?
Key facts
Sources
- PrimaryCourt-transfer notice on radaris.com quoting the 27 August 2026 final judgment, docket MID-L-000847-24, filing and amended complaint dates, 21,760 assignorsAtlas Data Privacy Corporationaccessed 2026-09-17
- PrimaryCourt-transfer notice quoting the 12 June 2026 final judgment and listing its twelve domain namesAtlas Data Privacy Corporationaccessed 2026-09-17
- PrimaryAtlas Data Privacy Corp. v. We Inform, LLC (A-8-25), decided 12 August 2026: current text and history of N.J.S.A. 56:8-166.1, no mental state for actual damagesSupreme Court of New Jersey (via CourtListener)accessed 2026-09-17
- PrimaryHuebner v. Radaris, LLC, 3:14-cv-04735 docket: 2017 default judgment, 2018 relief order, case closureUS District Court, N.D. California (via CourtListener)accessed 2026-09-17
- PrimaryOrder granting default judgment, 19 June 2017: $7,500,000 liability and domain, registry and hosting injunction naming radaris.netUS District Court, N.D. Californiaaccessed 2026-09-17
- PrimaryOrder granting non-parties relief from the default judgment, 4 May 2018US District Court, N.D. Californiaaccessed 2026-09-17
- PrimaryPlaintiffs' status report, 7 June 2018: EuroDNS refusal, Verisign and Neustar registrar changes, domains transferred backUS District Court, N.D. Californiaaccessed 2026-09-17
- PrimaryTerms of service naming Dilangi, Inc, Majuro, Marshall Islands as operator; checked live with the regional sites page and Data Privacy CenterRadaris (radaris.net)accessed 2026-09-17
- PrimaryEnforcement notice to Experian Limited dated 12 October 2020, including use of the Open Electoral RegisterInformation Commissioner's Officeaccessed 2026-09-17
- PrimaryInformation Commissioner v Experian Ltd [2024] UKUT 105 (AAC), decision of 22 April 2024 dismissing the ICO appealUpper Tribunal (Administrative Appeals Chamber)accessed 2026-09-17
- PrimaryICO statement on the Upper Tribunal ruling, updated 24 May 2024 to say no further appealInformation Commissioner's Officeaccessed 2026-09-17
- PrimaryUK GDPR Article 3, territorial scopelegislation.gov.ukaccessed 2026-09-17
- PrimaryUK GDPR Article 27, UK representatives of non-UK controllerslegislation.gov.ukaccessed 2026-09-17
- PrimaryOpting out of the open registerGOV.UKaccessed 2026-09-17
- PrimaryRemoving personal details from the Companies House register, including the 34 pound fee per documentCompanies Houseaccessed 2026-09-17
- PrimaryRemoving personal contact information and doxxing content from Google SearchGoogleaccessed 2026-09-17
- Reported byData Broker Radaris Loses Domains in Privacy Fight: lead report, defence and Atlas quotes, Atlas's characterisation of the email corpusKrebsOnSecurityaccessed 2026-09-17
- Reported bySummary of the 20 August 2025 Northern District of West Virginia ruling on West Virginia's Daniel's Law (firm acts for data broker defendants)Troutman Pepper Lockeaccessed 2026-09-17
- Reported byMarch 2024 investigation into Radaris and its sister people-search sitesKrebsOnSecurityaccessed 2026-09-17
- Reported byJune 2024 follow-up: defamation threat, hosting overlaps, Andtop and BitsellerKrebsOnSecurityaccessed 2026-09-17


