The clerk entered the order and, just like that, a people-search company that had treated deletion requests as optional lost the keys to its storefront. A New Jersey judge directed that radaris.com and more than a dozen related data-broker domains be transferred to the plaintiffs after Radaris’s lawyers stonewalled a case under a state privacy statute that hits brokers for publishing personal details of law enforcement officers. If you run cybersecurity for a police department, a city, or any shop that employs people with home addresses worth harvesting, this is the week you stop assuming the public web forgot your staff.
Brian Krebs documented the grind: ignored removal requests, then counsel who stalled until a judge treated the hostnames as seizable property. Toast the officers who brought the case. Then update the threat model. The order reassigned the front doors. Downstream clones, partner feeds, search caches, and the dumps already sitting in criminal shops still need your attention.
The Hostnames Moved and the Warehouse Did Not
Data brokers sell convenience dressed as public records. Radaris made removal annoying enough that most targets quit, which is a durable business until a statute attaches real penalties to publishing a cop’s home life and a judge uses the domains as leverage. Seizing the names is crude. It is also one of the few moves that lands when a vendor will not answer mail.
The catch will not make anyone’s victory lap. Those rows were copied on the way in. Other brokers ingested the same files. Archives kept the pages. Crews building spear-phish kits and password lists tied to personal inboxes already pulled what they needed. Your firewall never booked that collection as an event. It was ordinary HTTPS to a people-search site, which your border still treats as weather.
Threat-protection catalogs file a skip-trace page under “the internet.” Threat detection that hunts malware beacons stays quiet when a recruiter widget or a hobbyist scraper lifts your org chart. A defense in depth design that ends at the VPN leaves your domain admin’s home address in a commercial index. That listing is reconnaissance. Price it like reconnaissance, because the attacker who is about to reset a mailbox will.
If you are counting on the new domain holders to run a clean sunset, give that hope a few days and then move. Plaintiffs wanted the sites under control. They did not sign up as your cyber security retention crew. You will see parked pages, broken links, and copies that still answer. You will see the same mobile numbers surface on the next broker by Monday.
Checkout Pages and Baseband Bugs Kept Copying
While New Jersey reassigned hostnames, other pipes kept vacuuming the same class of personal data. Google’s September Pixel bulletin closed 110 holes, including a modem flaw already used in limited, targeted attacks. Baseband bugs sit under the OS your MDM dashboard loves to green-light. A clean compliance score does not mean the radio stack stopped leaking. For executives and investigators who live on Pixel hardware, that patch is an incident-prevention ticket, not a consumer note you forward and forget.

Shops offered a quieter copy path. Researchers watching client-side JavaScript described campaigns that leave a storefront looking healthy while scripts siphon payment flows, hijack clicks, or rewrite analytics. Your quarterly scanner can bless the origin. The browser still executes whatever the tag manager loaded after lunch. That is another dossier factory, running in sessions you file as “customers.”

None of this needs a zero-day on your domain controller. It needs a public identity, a phone, and a page that runs other people’s code. You already burn cycles on brute-force noise against the VPN. Keep doing that. Also notice the collection that never fails a login because it never tries one.
What Your Cybersecurity Team Can Still Freeze
Start with people, not domains. Pull a roster of staff who attract targeting: officers, executives, identity admins, helpdesk resets, anyone with a badge photo on the public site. Search the major people-search properties for those names, personal emails, and home numbers. File every takedown your state law actually supports, and log refusals as open risk rather than a ticket you tossed over the wall to “privacy.”
Do the ugly inventory first. Then lock what you actually administer.
- Treat broker listings of officers and admins as recon exposure: screenshot them, file removals, and watch for reposts on sibling sites after a domain changes hands.
- Push the September Pixel modem fix (and verify it) on executive and investigative handsets; baseband sits outside your usual app-patch cadence.
- Inventory third-party scripts on any payment or account portal you own; hold new tags until someone can explain what data they touch.
- Add “staff PII in public indexes” to the incident response menu so a doxxed officer or exec gets the same urgency as a malware alert.
Ongoing work is slower and less cinematic. Security hardening for this problem looks like shrinking public staff directories, killing personal emails on the corporate site, and stopping the intern wiki from mirroring home numbers. Watch your own career pages and newsroom bios for scraping. Rehearse the call tree for when a home address hits a paste site. Your cyber security program can keep a control owner for data-broker exposure the same way it keeps one for laptop disk encryption. Courts can seize a storefront. You still own the copies that already walked out.
Sources
- Data Broker Radaris Loses Domains in Privacy Fight
- Google Pixel owners urged to patch actively exploited modem flaw
- When scanners miss the attack: how Cloudflare Client-Side Security protects storefronts
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
