September 2026 Privacy Pulse: Radaris, Military Data and Removal Evidence

This month’s Privacy Pulse looks at what happens when a people-search business loses its domains, why exposed military records create risks beyond identity theft, and what evidence to look for when choosing a removal service. It also includes an important Priwall account reminder and practical steps you can take now, from freezing your credit to using California’s DROP service.

One development deserves particular attention: Priwall by mePrism’s removal-rate figures have been independently recalculated by Sensiba LLP under an AICPA AT-C Section 215 agreed-upon procedures engagement, with the signed practitioner report available on our website. We explain the findings and their limits below, because a privacy recommendation should come with evidence you can inspect.

Radaris loses its domains, exposing a tangled people-search business

Radaris’s main people-search site has been taken out of its operators’ hands: KrebsOnSecurity reported on September 16 that a New Jersey court transferred 14 domains in the Radaris family to Atlas Data Privacy following litigation over alleged violations of Daniel’s Law (KrebsOnSecurity). At the time of the report, Radaris.com displayed an Atlas notice instead of selling personal dossiers; defense counsel said they were seeking to vacate the judgment and intended to appeal (KrebsOnSecurity).

This was not an ordinary website closure. Krebs described Radaris’s long reputation for ignoring removal requests, earlier reporting about a fictitious CEO, and disputes over ownership involving offshore entities and a Boston-area operating group (KrebsOnSecurity).

The case also exposed how difficult it can be to identify who is actually behind a people-search brand. According to Atlas, documents obtained in litigation linked Radaris and at least 25 other people-search websites to a small group using shared administrative, financial, and technical infrastructure; Atlas also described commercial relationships involving other people-search and data-removal businesses (KrebsOnSecurity). Those documentary interpretations are Atlas’s account, not a finding here that every connected company committed wrongdoing.

For anyone trying to reduce personal-data risk, the distinction matters: a different website name may not mean a separate operation. Our view is that effective remediation requires tracking the sites where information appears, the entities handling requests, and what can actually be verified afterward.

A website becoming unavailable is not the same as confirmed deletion. The domain transfers do not establish that every related business has closed or that all copies of the underlying data have disappeared. Treat this as a meaningful enforcement development, not a reason to stop checking your exposure elsewhere.

The Pentagon breach makes military data removal more urgent

On September 25, CNN reported that a breach at the Defense Manpower Data Center exposed Social Security numbers and other personal information belonging to current and former military personnel, including occupational specialties in some cases (CNN). The number affected remained uncertain, and the Pentagon reported no indication of misuse at that time (CNN).

The concern goes beyond fraudulent credit applications: CNN described how exposed records could be combined with commercial datasets to profile or target defense personnel (CNN). This is not a newly discovered threat; Duke University’s 2023 research, sponsored by the U.S. Military Academy at West Point, demonstrated purchases of sensitive information about active-duty personnel, veterans, and their families for as little as 12 cents per record (Duke University).

We previously discussed the military exposure problem in “The West Point Warning: Why Personal Data is a National Security Liability.” Our recommendation for active-duty and retired personnel is to follow official breach instructions, protect credit, and begin reducing broker-held personal information.

Removal cannot recover stolen government records. It addresses a separate problem: additional personal information still readily available to supplement them.

Priwall’s AT-C 215 report: evidence of removal outcomes

How should you judge a data-removal service? We recommend asking what was measured, which population the results cover, and whether someone independent performed procedures on the reported figures.

Sensiba LLP performed an AICPA AT-C Section 215 agreed-upon procedures engagement on Priwall by mePrism’s removal-tracking data, independently recalculating results across a representative sample of our enterprise customers (signed practitioner report). The reported findings were:

  • Greater than 92% confirmed removal at 30 days across the measured enterprise population (practitioner report).

  • Greater than 99% confirmed removal at 90 days across the measured enterprise population (practitioner report).

  • Four days median time to first confirmed removal in the measured data (practitioner report).

To our knowledge, this is the first published AICPA AT-C Section 215 engagement on data-removal efficacy figures in the category, as described in our report announcement. Its significance is specific: readers can inspect a CPA firm’s stated procedures and factual findings about removal-rate calculations, rather than relying only on a marketing claim or a count of requests sent (methodology).

It is not an audit, certification, endorsement, or guarantee of future performance, and it does not establish military-specific protection or prevention of harm (scope and limitations; signed report). Read the report alongside its scope; the distinction between a measured result and a blanket promise is important.

October 1 reminder: access Priwall through the web app

The Priwall by mePrism iOS and Android companion apps are retiring on October 1, 2026, with account access continuing through our mobile-optimized web app (retirement announcement). You do not need to create a new account or migrate your data yourself (retirement announcement).

If you subscribed through Apple or Google, your subscription continues through its current paid period but will not auto-renew through the app store after the transition; to maintain service, resubscribe directly through the web app (billing instructions). Check your paid-through date and follow the renewal reminder rather than assuming app-store billing transfers automatically.

The separate Social Media Privacy Controls feature is also being discontinued; review the full product update if you use it. For help with access or billing, contact support@meprism.com (support details).

Four privacy and account-security steps worth taking now

These precautions address different problems. Use them together rather than expecting any one tool to cover every risk.

  • Freeze your credit: Place a free security freeze with Equifax, Experian, and TransUnion to make it harder for someone to open new credit in your name; continue monitoring existing accounts, which a freeze does not protect from unauthorized charges (FTC credit guidance).

  • Turn on multifactor authentication: Enable MFA on important accounts, especially email and financial services; choose phishing-resistant security keys or passkeys where supported (CISA and FBI guidance).

  • Use a password manager: Generate a strong, unique password for each account instead of reusing passwords, and protect the manager itself with a strong master passphrase (CISA guidance).

  • Register for Do Not Call: Add or verify your home and mobile numbers at the FTC’s National Do Not Call Registry; registration is free and does not expire, but it does not block scammers or stop every permitted call (FTC registry guidance).

California residents: use CalPrivacy’s free DROP service

California residents can use CalPrivacy’s Delete Request and Opt-out Platform, or DROP, to send a single deletion request to registered data brokers for free (CalPrivacy DROP). We recommend using it even if you already take other steps to manage your privacy.

Start at the official DROP website, verify California residency, provide the information you choose to include, and save your DROP ID so you can check status (how DROP works). Brokers’ processing obligations began August 1, 2026, and status updates can take up to 90 days; after initial processing, brokers must continue checking for new matching data on the required cycle (CalPrivacy processing guidance).

DROP is ongoing, not a one-time request, but it is not a universal internet eraser: exemptions apply, and it does not delete first-party information you gave directly to a business or publicly available data outside its deletion scope (DROP limitations). Check the actual status rather than assuming submission means everything has been deleted.

September’s takeaway is to distinguish action from outcome: a submitted request, an unavailable website, and confirmed removal are different things. Choose one unfinished step this week, complete it, and keep checking what happens next

Ready to try Priwall by mePrism?

If you're a company protecting at-risk employees, or an individual concerned about your digital footprint, start your privacy removal today at mePrism.com
Because your data shouldn’t be a roadmap for violence.

Click here to create your Free Basic account.
 

Explore more from Our Team

Browse more posts written by our team to help you stay in control.

Be Part of the Conversation


 
Next
Next

Military Data Removal: What to Do After the Pentagon Breach