CSIPE

Published

- 21 min read

Radaris Lost Its Domain. Your Address May Still Be Easy to Find


Books by the author

Compare all 5

As an Amazon Associate I earn from qualifying purchases. Buying through these links costs you nothing extra and helps pay for the blog.

Type a person’s name, age, and town into the right search box and you may get a home address, old phone numbers, relatives, neighbours, and a tidy list of previous homes. The facts may have come from records that were scattered across county offices, property sites, voter files, marketing lists, and old accounts. A people-search company does the joining. That joining turns several inconvenient clues into one cheap route to a front door.

On 16 September 2026, KrebsOnSecurity reported that the Radaris.com domain and more than a dozen related domains had been transferred following a New Jersey privacy case. The site now shows a court-transfer notice instead of selling personal dossiers. That is a real interruption. A prominent doorway into the people-search market has closed, at least for now.

The useful lesson reaches beyond Radaris. One domain transfer does not pull copied records out of other databases, repair the public records underneath them, or stop another broker from assembling the same profile tomorrow. If your safety depends on making your home harder to find, treat this case as a map of the system. Remove the convenient copies, reduce the source material where the law permits it, and keep checking the routes an adversary would actually use.

What changed on Radaris.com

Open Radaris.com as of 17 September 2026 and the usual search service is gone. The replacement page says that a final judgment of the New Jersey Superior Court transferred the domain to Atlas Data Privacy Corporation. It identifies the case as Atlas Data Privacy Corporation, et al. v. Radaris.com, et al., docket MID-L-000847-24, and says the former operators no longer control the domain. The notice also says a default judgment was entered on 27 August 2026 against Radaris.com, Rehold.com, and Trustoria.com (Radaris court-transfer notice).

The case grew out of Daniel’s Law, a New Jersey measure created after an attacker killed Daniel Anderl, the son of federal judge Esther Salas, at the family’s home. New Jersey’s official portal describes a process through which covered judges, prosecutors, law-enforcement personnel, and certain family members can demand that protected home addresses and unpublished telephone numbers be removed from public-facing sites (State of New Jersey: Daniel’s Law). The statute bars a person, business, or association from knowingly publishing that protected information after receiving a valid request, subject to the law’s conditions (New Jersey Revised Statutes 56:8-166.1).

According to the notice now served from Radaris.com, Atlas asserted claims assigned by about 21,760 covered people. The court found that the defendants had violated Daniel’s Law as set out in the amended complaint and awarded control of the domain to help prevent further disclosure. That page presents the plaintiffs’ account of the judgment. The underlying court record remains the authority, and the defendants can pursue the routes still available to challenge a default judgment.

KrebsOnSecurity adds reporting from both sides. Its 16 September article says a lawyer for the defendants intended to seek relief from the default judgment and appeal, arguing in part that Radaris.com was a domain rather than a legal entity. The same report says the New Jersey court had transferred 14 domains tied to the Radaris group at the time of publication (KrebsOnSecurity: Data Broker Radaris Loses Domains in Privacy Fight). A live transfer and a pending legal fight can exist together. The first is what visitors see today; the second means the final shape of the dispute remains unsettled.

For someone whose details appeared on the site, the immediate effect is simple. A searcher can no longer use that domain to buy or view the same dossier. Search results may still show cached titles or snippets for a while, but the destination now leads to the transfer notice. Friction has increased.

That matters. Cheap surveillance works through convenience. A stalker, harasser, scammer, or angry stranger is more dangerous when a ten-second name search supplies a current address and a family map. Removing a popular result forces the searcher to spend more time, try another service, or reconcile records by hand. Some will stop.

The victory has an edge, though. Radaris was one window into a much larger room.

Why one closed site leaves the profile behind

A people-search result looks like a record, but it is better understood as a product assembled from many records. The broker collects names, addresses, telephone numbers, property links, possible relatives, business filings, and other signals. It matches them, scores the likely relationships, then puts the package behind a search box or payment screen. The package can disappear while the ingredients stay available.

Picture a teacher who buys a home, registers to vote, obtains a professional licence, uses one telephone number for school business, and lists a relative as an emergency contact. No single source needs to publish a complete family diagram. A broker can connect the home to the owner’s name, connect the number to an account, connect the relative through an old address, and place the result on one page. Aggregation changes the risk.

The Federal Trade Commission explains that people-search sites buy information from other data brokers, collect it from public social profiles, and compile it from public records. It also warns that opting out of one site does not remove the information from public records or from other people-search services (FTC: What To Know About People Search Sites That Sell Your Information). That distinction should govern every removal plan.

A domain transfer acts on the convenient copy presented through that domain. It does not automatically alter a county assessor’s page, a company registration, a cached marketing file, a breached customer database, or a second broker’s index. Nor does it tell you which other sites bought, scraped, or inferred the same relationship before the transfer. Data moves by duplication. Taking one copy out of circulation rarely recalls the rest.

The problem has three layers. The first is the visible profile, the result that appears when someone searches your name. The second is the broker’s retained data and the feeds that replenish it. The third is the source trail, including records and accounts created for legitimate purposes. Each layer needs a different response.

Removing the visible profile buys immediate friction. Sending a deletion or suppression request may address retained data, depending on the law, the broker, and any exceptions. Fixing the source trail may require a confidential-address programme, a corrected public record, a business address, a separate telephone number, or a change in what you publish next time. One opt-out form cannot do all three jobs.

This is why repeated exposure is common. A profile vanishes, then returns months later after the broker refreshes from a source or matches a new identifier. The return does not prove the first request was useless. It proves the supply line stayed open. Removal is maintenance.

For a person facing a specific threat, that maintenance is worth doing. For everyone else, it still has a sensible purpose: make the cheapest search less complete. You are trying to raise the cost of joining clues, not erase every fact about your life.

The case exposes a market built for persistence

The Radaris dispute also shows why deletion can become a contest of endurance. A consumer sends one request. The broker may sit behind several brands, legal entities, registrars, hosts, data suppliers, and support addresses. If responsibility moves between them, the person requesting removal must keep proving that the same practical operation still exposes the same home.

KrebsOnSecurity reported that Atlas expanded its complaint in 2025 to cover more sites and entities associated with the Radaris operation. The article describes changing corporate identities and disputes over which entity operated or owned particular domains. It also reports Atlas’s claim that documents obtained in litigation tied a group of people-search sites to a small common operation. Those details are allegations and reported evidence from a live dispute, rather than findings this article can independently establish. The live transfer notice does independently confirm the judgment and the change in control of Radaris.com.

The structure matters because an address can outlive a brand. A company can stop displaying a profile while a supplier retains it. A sister site can present a similar record. A new domain can buy an old feed. Search engines can continue to point toward pages that changed yesterday. The person at risk sees a dozen separate chores; the market sees reusable data.

This persistence creates a bad mismatch. The subject must find every prominent copy, use the correct process, receive the confirmation message, keep the receipt, and return later. A searcher needs one result. The burden falls on the person whose home is exposed.

Some laws are beginning to attack that mismatch. California’s Delete Request and Opt-out Platform, known as DROP, lets a California resident submit one request to participating registered data brokers. California says brokers must access the system at least once every 45 days beginning 1 August 2026, and a status update can take up to 90 days (California Privacy Protection Agency: DROP). It is a wider control than visiting one broker at a time, although legal exceptions and matching limits still apply.

New Jersey’s Daniel’s Law takes a narrower approach for people whose public service creates a recognised safety risk. It gives covered people a route focused on home addresses and unpublished home telephone numbers. That can produce strong relief in the cases it covers, as the Radaris transfer demonstrates. Most residents fall outside that protected class.

The gap is the point. A judge, police officer, domestic-violence survivor, reproductive-health worker, journalist, activist, teacher, or ordinary person with a persistent stalker may face the same practical problem: a home address has been packaged for instant retrieval. Their legal options differ by job, location, and circumstance. Their operational task is similar.

Start with the search path. Then work backward.

Search like the person you are worried about

A privacy audit often begins in the wrong place. People open account settings, disable advertising toggles, and feel busy. Those controls may reduce future collection, but they do not show what a stranger can find today. Begin outside your accounts, with the sparse facts an adversary already knows.

Write down the likely starting points. A local harasser may know your full name and town. An angry customer may know your work email and employer. A former partner may know old addresses, relatives, and telephone numbers. A reporter’s hostile subject may know a byline and a rough location. The audit should use those facts, no more.

Search from a private browsing window while signed out. Private mode does not make the search anonymous, but it reduces personalisation from your own signed-in history. Try your full name in quotation marks with a town, employer, profession, old address, telephone number, and email address. Search common name variants. If your name is shared by many people, add one stable clue at a time.

Record results before requesting removal. Save the page URL, the date, the visible fields, and a screenshot that does not expose the information to a new cloud service. If a page has multiple profiles for you, record each one. The receipt helps you track progress and provides evidence if a broker says no profile existed.

Do not copy a dangerous address into a shared task board or ordinary support ticket. The cleanup process can create another copy. Keep the audit in an encrypted local file or another workspace appropriate to your threat model, and share only with people doing the removal work.

EFF’s 2026 doxxing-prevention guide recommends searching for combinations of personal identifiers, documenting the exposed material, and addressing broker listings as part of broader footprint management. It also stresses that the plan should match the person and the threat, because the useful response for an occasional nuisance differs from the response to a credible, targeted adversary (EFF: Doxxing Safety Pt I).

Prioritise by consequence, not by the number of results. A current home address beside a partner’s name deserves attention before a ten-year-old forum account. A child’s school, a daily work location, a personal telephone number, or a vehicle registration clue can matter more than an incorrect age. Accuracy is not required for a listing to cause harm; an old address may identify a relative who still lives there.

Give each result one of four labels: direct location, relationship bridge, contact route, or noise. Direct-location results reveal where you sleep, work, study, or regularly appear. Relationship bridges connect you to family or housemates. Contact routes provide a channel for impersonation or harassment. Noise is stale or wrong material with little practical value to the threat you named.

The labels turn a frightening pile of search results into work. Fix direct locations first. Then break the relationship bridges that lead back to them. Close or separate contact routes. Leave low-value noise until the dangerous routes are under control.

Remove the easy copies without giving away more

Most people-search sites provide an opt-out or suppression route, though it may be difficult to find. The FTC advises searching the service’s name with “opt out” or “remove my information” if the link is not obvious. Follow the route from the broker’s own domain rather than trusting the first sponsored search result. A fake removal service would begin with the exact data you are trying to protect.

Use a dedicated email address for removals. It should not contain your full name, birth year, employer, or home domain. Keep it separate from sensitive accounts. The address gives you one place for confirmation links and follow-up notices without handing brokers another strong identifier tied to your everyday inbox.

Supply the minimum evidence the process requires. A broker may need the exact profile URL, a name variant, or an email confirmation to match the request. Be cautious when a site asks for a government identity document, a selfie, or unrelated personal fields. Read the stated purpose and retention terms. If the demand seems excessive, check whether your state offers an authorised-agent route or a regulator’s complaint process before sending more identity material.

Complete the confirmation step. Many requests fail quietly because the email link was never clicked, landed in spam, or expired. Capture the final screen and retain the confirmation message. Set a check date based on the site’s stated processing period, then verify from a signed-out browser.

Ask search engines to refresh or remove stale results only after the source page has changed. Search removal cannot repair a live broker page, and source removal does not instantly clear an old snippet. Treat them as separate queues. Verify both.

California residents should consider the state’s DROP process in addition to urgent manual removals. The single request can reach registered brokers, while manual work can address a dangerous live page now. As of September 2026, California warns that brokers work on a rolling cycle and status may take time. A central request is useful coverage, not an emergency button.

If you hire a removal company, understand the service boundary. Ask which brokers it covers, how it verifies deletion, how often it rescans, what proof you receive, what identifiers it stores, and how you cancel. A dashboard that says “removed” should correspond to a checked URL and date. Marketing counts are a poor substitute for evidence.

Keep a small register. For each profile, record the broker, URL, request date, confirmation date, promised deadline, verification date, and next check. This is one of the rare privacy jobs where a plain spreadsheet can materially improve safety. Do not turn the register into a new dossier by storing full documents or unnecessary family details inside it.

The work feels repetitive because it is repetitive. That is also why a schedule beats determination. Review high-risk names and addresses monthly during an active threat, then move to quarterly checks when the trail stays quiet. A lower-risk household may check twice a year and after a move, property purchase, business filing, licence change, or public controversy.

Work on the sources that keep rebuilding the profile

Repeated opt-outs are a signal to look upstream. The broker may be reading a record you can change, a field you can separate next time, or an account you forgot was public. Source work takes longer, but it can prevent several downstream profiles from returning.

List the records that genuinely need your residential address. Tax authorities, banks, insurers, courts, licensing bodies, and election offices have legal or operational reasons to collect it. Collection does not always require public display. Ask the record holder whether a confidentiality programme, non-public mailing address, agent address, or protected-person process applies to your circumstances.

Do not enter a false address in an official record. That can create legal trouble and may break service of important documents. Use a lawful alternative that the record holder accepts. Depending on location and purpose, that might be a post-office box, commercial mailbox, registered-agent address, office address, or a state address-confidentiality programme.

Separate public contact details from private recovery details. A public-facing project, company, campaign, or professional profile may need an email address and telephone number. Give it dedicated ones. Keep the telephone number used for bank recovery, healthcare, and close family out of business directories, domain records, newsletters, and public biographies.

Business filings deserve special attention. A home-based founder can expose a residential address through a company registry, local permit, professional licence, or domain registration. Before filing, find out which fields become public and whether the jurisdiction permits a registered agent or service address. Fixing the structure before the filing is easier than chasing copies afterward.

Property records are harder. Ownership and tax records are public in many places, and eligibility for suppression varies. Some at-risk groups can request confidential treatment. Others may need professional legal advice before a future purchase, especially if a trust or other ownership structure is being considered. Do not build a property structure from an internet privacy tip; tax, lending, disclosure, and beneficial-ownership rules matter.

Social accounts create bridges even when they never show an address. A public birthday post, a photograph outside a new home, a tagged relative, a running route, and a marketplace listing can confirm that two records belong to the same person. Review old public posts from the adversary’s starting facts. Remove the joins that turn a vague result into a current location.

Family needs to be part of the plan. A parent may post a birthday. A partner may list the relationship publicly. A school club may publish a roster. A relative’s obituary can map an entire family. Give close contacts a short, specific request: do not tag the home, post travel in real time, publish children’s routines, or answer unsolicited questions about contact details.

The goal is compartmentation. Public work details should lead to a public channel. Private recovery details should lead nowhere visible. A home address may still exist in records, but fewer cheap links should connect it to the name an adversary starts with.

If the address is already being used against you

An active threat changes the order of work. Do not spend the first hour submitting twenty opt-outs while messages escalate or someone is travelling toward your home. Move immediate safety, evidence, and trusted support ahead of long-term cleanup.

Preserve the threatening message, account name, full headers where available, timestamps, URLs, and screenshots. Avoid editing the original. Store a copy somewhere the harasser cannot reach through your compromised account or device. If the threat names a location, family member, weapon, time, or intended action, say that plainly when asking for help.

Tell the people who can change the physical situation. That may include household members, workplace security, a school, building staff, an editor, an advocacy organisation, or emergency services. Share the minimum useful facts and a photograph or description if you have a credible suspect. Agree on who answers the door, who screens calls, and where vulnerable household members will go if the risk rises.

EFF’s doxxing incident-response guide recommends documenting the exposure, reporting harmful content through the relevant service, tightening account security, and making a safety plan suited to the severity of the threat. It also points readers toward support rather than treating doxxing as a purely technical cleanup (EFF: Doxxing Safety Part II).

Ask the publisher or platform to remove the exposed information, but keep your evidence first. A fast takedown can reduce sharing while leaving you without proof of what happened. If the material appears on several services, record each URL separately. Mirrors and screenshots may require separate reports.

Lock down the accounts that could extend the exposure. Change passwords from a clean device if compromise is plausible, revoke unknown sessions, and turn on a phishing-resistant second factor where the service supports it. Review email forwarding rules, recovery addresses, shared albums, location sharing, family plans, and cloud links. An attacker who can read your inbox may see every removal confirmation and undo the work.

Watch for the second move. Public data often supports impersonation, false emergency calls, password-reset attempts, fake deliveries, messages to relatives, and convincing support scams. Tell close contacts how you will verify an urgent request. Use a known telephone number or an agreed phrase, not the contact route supplied in the new message.

A home-address exposure may justify temporary changes that would be excessive in ordinary life. Hold mail, alter a routine, add exterior lighting, tell a neighbour, move a child pickup, or stay elsewhere if credible evidence warrants it. Calibrate the response to behaviour and capability. A nasty comment and a message containing a photograph taken outside your home belong in different risk categories.

Legal advice can matter when a threat intersects with restraining orders, protected records, employment duties, tenancy, or press work. Specialist organisations may also help journalists, activists, survivors, and public-interest workers with safety planning. The useful question is not “Can the internet forget me?” Ask, “Which route can this person use today, and how do we close or watch it?”

A practical seven-step privacy pass

The Radaris transfer offers a good moment to do one focused pass rather than promise yourself a total internet cleanup. Set aside two hours for discovery and the first requests. The remaining work can move onto a calendar.

  1. Name the adversary and starting facts. Write one sentence describing who you are worried about, what they know, and what harm you are trying to prevent. A generic privacy wish produces generic chores. A specific threat model tells you whether a relative link, office number, or home address comes first.

  2. Search from outside your accounts. Use your name variants with a town, work role, telephone number, email address, and old address. Search only with facts the adversary could reasonably possess. Record the dangerous URLs and visible fields in a protected local file.

  3. Rank the routes by consequence. Put current locations, children, close relatives, private telephone numbers, and routine locations at the top. Mark stale or obviously wrong profiles lower unless they point toward someone else who could be harmed.

  4. Remove urgent broker copies. Use each site’s official suppression route, a dedicated email address, and the minimum required data. Complete confirmation links. Keep dates and receipts. California residents can add DROP for broader coverage while handling urgent pages directly.

  5. Trace recurring facts upstream. For every high-risk field, ask where it came from. Check business filings, professional licences, property pages, public biographies, social posts, domain records, and family accounts. Use lawful confidentiality or service-address options where they exist.

  6. Break relationship bridges. Separate public work contacts from private recovery contacts. Ask family not to tag locations or answer information requests. Remove unnecessary public links between names, accounts, homes, vehicles, schools, and routines.

  7. Verify and repeat. Recheck the exact URLs after the promised deadline, then search again from scratch. Put high-risk reviews on a monthly or quarterly calendar. Keep the receipts so each return becomes a small task instead of a fresh investigation.

A removal pass can never promise invisibility. It can remove the first answer, break the easiest join, and force a searcher to spend more time. That is a worthwhile security outcome. Most opportunistic actors work with what is cheap.

What the domain transfer should teach us

Radaris.com now carries a rare kind of privacy notice: the search product itself has been displaced by a court judgment. For the people whose protected information appeared there, that is more than symbolism. One well-known route to their homes no longer works as it did last week.

The event also shows the limit of site-by-site privacy. A profile assembled from copied and public material can survive the company that displayed it. A person can win a removal and still face the same address on another domain. The safety result comes from combining enforcement, repeatable deletion, source control, and a plan for an active incident.

Do the cheap work first. Remove the pages that hand a stranger the answer. Then inspect the records and relationships that keep producing the answer. Save proof, return on schedule, and spend the most effort where exposure would cause real harm.

You cannot make a life leave no records. You can make the route from a name to a front door slower, less certain, and more expensive to follow.

For one practical security and privacy briefing each month, join the newsletter. One email per month, and no noise.

Sources