Skip to content

Risk Digest

Legal Consequences of Doxing Wealthy Property Owners in 2025

The NYC Mamdani database publication exposed nearly a million property owners to potential harassment, yet existing state and federal doxing laws offer limited protection for private individuals targeted by government-compelled disclosure.

By Editorial TeamUpdated Jul 29, 2026Verified Jul 29, 2026
REPORTED — UNVERIFIED
Jurisdiction
US-New York
Court
New York City (Mamdani database publication)
AI tool named
Mamdani property database
Ruling date
Jul 1, 2026
Source document
View primary court order ↗
Last verified
Jul 29, 2026

Lex Machina Review is an independent risk-tracking and reference resource. Nothing on this site is legal advice, and using it does not create an attorney-client relationship. Every record is reviewed against primary sources but may not reflect the most current status of a matter — always verify directly against the cited court order, rule text, or a licensed attorney before relying on it.

Companion explanation — secondary to the source document above

The legal consequences of doxing wealthy property owners in 2025 are easier to describe when the publisher is a private antagonist than when the publisher is a city agency. The July 2026 New York City property database shows why. It reportedly made roughly 960,000 properties searchable, even though the pied-a-terre tax at issue was aimed at about 31,000 homes.[1] The city defended the disclosure as part of a state-law-required tax process.[2] Critics called it doxing.[3] No court has yet supplied the missing answer: whether a government-published, searchable owner-address database can be treated as actionable doxing when the information is tied to a tax roll.

Searchable property database display over a New York City skyline beside a law book and gavel

That uncertainty is not a technical footnote. It is the practical problem counsel faces when a client says the database has turned a home address into a targetable coordinate. The instinctive answers are both too fast. Public-record status does not make every republication harmless. A doxing label does not, by itself, identify a defendant, a mental state, a statutory violation, or a waiver of governmental defenses.

The first legal separation is therefore basic: compelled disclosure, doxing function, and actionable remedy are different questions. A disclosure can be required by law and still create a safety risk. It can function like doxing for the people whose locations become searchable and still fall outside current doxing statutes. It can be politically reckless without being an easy civil claim.

What the Database Changed

A tax roll does not become dangerous only when it contains secret information. The risk often comes from aggregation, searchability, and context. A person who would never pull scattered municipal records can use a single searchable interface. A protest organizer, obsessive critic, extortionist, trespasser, or swatter does not need the database to reveal a private fact in the colloquial sense. The database needs only to reduce the work of locating a person or connecting wealth, ownership, and an address.

That is why the scale matters. The reported gap between roughly 960,000 listed properties and roughly 31,000 homes targeted by the tax does not prove illegality.[1] It does show overbreadth as a risk fact. More people became part of the searchable surface than the tax target alone would suggest. For litigation purposes, overbreadth may support foreseeability arguments, political criticism, or requests for narrowing. It does not automatically create a doxing cause of action.

The city’s stated position also matters. The Mayor’s Office framed the notice process as required for implementation of the pied-a-terre tax.[2] If the publication is treated as a government act taken under state-law authority, the affected owner’s claim is no longer a standard “someone posted my address online” dispute. It becomes a challenge to how a public agency collected, structured, and released information under a statutory program.

The political fight around the database is useful mainly because it shows how quickly the disclosure was understood as a safety issue. REBNY and Republican critics reportedly characterized the publication as doxing that could expose owners to harassment or violence.[3] Press coverage also identified high-profile owners, including reporting involving Ken Griffin’s properties.[4] Those details may help show foreseeability, but they do not answer the legal question. Wealth does not erase a resident’s interest in not having a home address operationalized for strangers.

Why New York Is an Awkward Forum for a Doxing Claim

New York does not have a standalone doxing criminal statute in the materials reviewed here. That leaves lawyers looking at more familiar tools: harassment, stalking, trespass, threats, intentional infliction theories, negligence-style arguments, and requests for injunctive or declaratory relief. The fit is uneven because the alleged wrong is not a direct threat from the database publisher. It is publication that may make later threats easier.

New York Penal Law harassment and stalking provisions are built around conduct such as repeated unwanted contact, threatening behavior, following, monitoring, or placing a person in reasonable fear. A searchable tax database does not map neatly onto that conduct when the publisher is a government office acting through an administrative program. The database may assist someone else’s harassment. It is much harder to characterize the database itself as the harassing course of conduct unless the facts show intent, targeting, or use beyond routine publication.

That distinction is often lost in public commentary. Calling the database doxing describes the experienced harm: personal location information becomes easier to find and use. A criminal statute asks narrower questions. Who acted? With what intent? Against whom? Did the act fall within the prohibited verbs? Was there a threat, a course of conduct, or a protected category? In the Mamdani database scenario, those questions do not naturally point to a clean New York doxing charge because there is no standalone doxing offense to receive them.

The national landscape does not make the gap disappear. As of June 2025, the Council of State Governments reported 19 states with 54 anti-doxing bills, but only California, Alabama, and Illinois defined doxing as a standalone crime; seven states limited protections to public officials only.[5] That is a narrow foundation for a broad assumption that American law already treats address publication as a general doxing offense.

QuestionWhy it matters in the NYC database scenario
Was the information lawfully compelled?The city says publication was required for the pied-a-terre tax process, which supports a governmental-authority defense.
Did the release function like doxing?Searchability and aggregation can make owner addresses operationally useful even when underlying records are not wholly secret.
Is there a cause of action against the publisher?New York lacks a standalone doxing statute, and ordinary harassment or stalking theories are difficult to apply to a government tax-roll publication.
Has a third party misused the data?Trespass, stalking, swatting, threats, or targeted harassment may create stronger claims, but only after additional misconduct occurs.

Federal Law Is Narrower Than the Label Suggests

Federal law offers less help to private property owners than the phrase “federal doxing law” implies. 18 U.S.C. § 119 is directed at restricted personal information of covered persons, including categories such as federal officials, judges, and witnesses. A law-firm summary describes penalties of up to five years and a $250,000 fine, but the protected-person limitation is the critical point for private owners.[6]

A wealthy apartment owner, investor, executive, or family member does not become a covered person merely because the disclosure creates security risk. If the person is not within the statute’s protected class, § 119 does not convert the database publication into a federal doxing offense. That is not a minor drafting choice. It means the most obvious federal criminal label is largely unavailable for the very people most likely to be named in coverage of a luxury-property tax database.

Other federal theories may arise if later conduct includes threats, extortion, interstate stalking, cyber intrusion, or swatting. But those are not direct database-publication claims. They depend on what someone does with the information after it is published. The legal system becomes more responsive when the risk has matured into a separate act.

California Shows a Remedy Model, Not a New York Answer

California’s AB 1979, effective January 1, 2025, is the clearest civil-remedy model in the materials reviewed. A law-firm summary describes the Doxing Victims Recourse Act as allowing statutory damages from $1,500 to $30,000, attorney’s fees, and pseudonymous filings.[7] Those features matter because they respond to two recurring failures in doxing cases: victims may not be able to prove large out-of-pocket losses before danger escalates, and forcing a plaintiff to litigate under a public name can compound the exposure.

But AB 1979 does not solve the New York database problem. It is California-specific. It is a civil remedy model, not a general federal rule. And even where a doxing statute exists, a government publisher claiming statutory duty raises issues that ordinary private-actor doxing statutes were not necessarily built to handle.

The practical lesson is narrower than “California protects doxing victims.” California has built a more explicit path for some victims to seek damages and confidentiality in court. New York property owners affected by a New York City tax database cannot simply import that path. Counsel can use it as a legislative comparison or policy benchmark, not as a ready-made cause of action against the city.

The Government-Publisher Barrier

A private doxer and a government agency create different litigation problems. With a private actor, the case may turn on intent, threats, foreseeability, platform conduct, or statutory definitions. With a government publisher, the threshold fight may be whether the agency was doing what the law required, whether the plaintiff can sue the government at all, whether immunity or notice-of-claim rules apply, and whether the court can order a change in disclosure practice without colliding with the underlying statute.

That same structural problem appears in other government-disclosure disputes. The Epstein survivor doxing lawsuit raised a related concern: when the government is the disclosure source, privacy injury may be obvious before the remedial path is obvious. The obstacle is not that exposure cannot harm people. It is that ordinary doxing remedies often assume a private wrongdoer, not an agency acting through a public-record or compelled-disclosure regime.

The First Amendment adds another layer. The Daily Mail principle, drawn from Smith v. Daily Mail Publishing Co., generally protects publication of lawfully obtained truthful information, and FIRE’s discussion of doxing law treats that principle as a major reason doxing regulation becomes constitutionally difficult.[8] That protection is usually discussed in relation to speakers and publishers, not as a complete answer to every government database case. Still, it complicates any theory that truthful owner information can be suppressed or punished simply because publication increases risk.

For affected owners, the most plausible direct challenges may therefore look less like classic doxing claims and more like administrative-law, statutory-authority, privacy, due-process, or tailoring arguments. Did the city publish more than the statute required? Was a searchable interface necessary? Were owner names and addresses disclosed in a form broader than needed to administer the tax? Could the same notice function have been served with less exposure? Those questions matter because they attack the government act on its own terms. They are also uncertain because the public record supplied here does not include a court ruling on the database’s legality.

Diagram showing government database disclosure separated from direct remedies and connected to remedies after third-party misconduct

When the Claim Gets Stronger, the Harm Has Usually Advanced

The downstream-harm path is the uncomfortable center of the case. If a third party uses the database to trespass, stalk, threaten, swat, vandalize, harass, or coordinate intimidation, the legal posture changes. The owner is no longer arguing only that the database made harm easier. The owner can point to a concrete actor, a concrete act, and a concrete injury or threat.

That is where conventional law becomes more useful. Trespass can address unauthorized entry. Stalking and harassment statutes can address repeated targeting or threats. Swatting may trigger criminal charges and civil claims tied to false emergency reports. Protective orders may become available when a person, rather than a database, is engaging in prohibited conduct. Security costs, relocation costs, emotional distress, and business disruption may become easier to plead once misuse is documented.

But this is a remedial system that often waits for escalation. A lawyer advising a property owner before the first trespass or threat has a weaker set of tools. The owner can preserve evidence, request removal or narrowing if a process exists, assess physical security, monitor misuse, and prepare claims. The direct legal theory against the government publisher remains difficult unless the publication exceeded legal authority or violated some independent protection.

The risk is not imaginary. DHS reported in July 2025 that assaults against ICE agents had increased 700% following doxing campaigns.[9] That report concerns federal officers, not wealthy property owners, and it should not be stretched into proof that a tax database will produce the same pattern. It does show why address exposure is treated as operationally serious when public hostility is already present.

Survey data points in the same general direction, with the same need for restraint. SafeHome.org’s 2025 survey found that 70% of respondents most feared personal safety threats from doxing, and it identified home address as the second-most exposed data point.[10] That measures fear and reported exposure, not legal causation. It helps explain why owners react strongly to searchable address publication; it does not establish that the city is liable for later misconduct.

What Counsel Can Actually Tell an Affected Owner

The cleanest advice is not the most satisfying advice. Direct doxing liability against the city is uncertain and likely difficult on the current record. New York’s existing harassment and stalking laws do not fit neatly around a government tax-roll publication. Federal § 119 largely does not protect private property owners. California’s AB 1979 shows what a more victim-oriented civil remedy can look like, but it does not create a New York claim.

The more useful work is evidentiary and procedural. Identify exactly what was published. Compare the fields and search tools against the claimed statutory requirement. Preserve screenshots, search results, press references, threats, unusual visits, messages, and security incidents. Track whether a third party appears to be using the database as a source. Separate reputational embarrassment from physical-location risk, because courts and insurers may treat those harms differently.

If harm remains prospective, the owner’s strongest arguments may be narrowing, minimization, and statutory compliance: the government should not publish more personally identifying owner information than the law requires, and it should not make threat-relevant information more searchable than necessary to administer the tax. If harm has occurred, the case can expand toward claims against the third-party wrongdoer and, depending on the facts, arguments that the city had notice of a foreseeable and avoidable risk.

The Mamdani database therefore sits in the liability gap. It is not enough to say the information was public, because searchability and aggregation can change the threat surface. It is also not enough to say the disclosure was doxing, because 2025-2026 law still asks for statutory fit, protected status, governmental authority, causation, and a defendant who can be reached. For wealthy property owners, the practical consequence is a thin direct remedy against the government publisher and a stronger but later remedy if someone else turns the database into trespass, stalking, swatting, threats, or harassment.

References

  1. Mamdani database of wealthy NYC property owners draws concern: 'Outright dangerous', Fox News.
  2. Mayor Mamdani Notifies Property Owners of New Pied-a-Terre Tax, NYC Mayor's Office, July 2026.
  3. Mamdani property database sparks doxxing, safety fears, Washington Times.
  4. Mayor Zohran Mamdani under fire, Yahoo News / Globe.
  5. Doxing: State Protections Against Digital Threats, Council of State Governments.
  6. Federal Doxing Crimes, Eisner Gorin LLP.
  7. California Doxing Laws, Eisner Gorin LLP.
  8. Is doxxing illegal?, FIRE.
  9. Anarchists and Rioters in Portland Illegally Dox ICE Officers and Federal Law Enforcement Agents, U.S. Department of Homeland Security, July 11, 2025.
  10. Doxxing & Online Harassment Research, SafeHome.org.

Report a correction or tip

Spotted an outdated figure, a misstated fact, or a ruling this case record should reflect? Public comments are disabled for this content given the professional cost of a misreported case outcome, penalty amount, or rule text — use the structured correction channel instead.

Report a correction or tip for this record →