• To chevron_right

      ACE Targets Dozens of Streaming Pirates Through Cloudflare and Discord Subpoenas

      news.movim.eu / TorrentFreak • 7:29 • 4 minutes

    doscord Under U.S. law, rightsholders have an option to identify alleged copyright infringers, without having to file a lawsuit.

    Instead, they can request a DMCA subpoena . These documents are typically signed by a court clerk and don’t require any judicial oversight.

    These DMCA subpoenas allow rightsholders to obtain the personal details of anonymous alleged infringers through third-party service providers. In recent years, this legal shortcut has shown to be a capable OSINT tool, with the Alliance for Creativity and Entertainment (ACE) as the most avid user.

    This week, the Motion Picture Association, representing ACE, filed two new subpoena requests at federal courts in California. The first subpoena targets Internet infrastructure company Cloudflare and the second targets Discord users who allegedly operate pirate servers.

    Miruro.to, Aniworld.to, and 47 Other Domains

    The first request, filed at the Central District of California, lists 49 domain names. On behalf of ACE members including Disney, Netflix, Warner Bros., Universal, Paramount, and UEFA, the MPA asks Cloudflare to identify the people who run the associated accounts.

    Three domains clearly stand out. The anime network Miruro is in the lead per Similarweb’s data, with 45 million monthly visits for the .to domain, and 37 million for the .tv variant. The German-language anime and television site Aniworld.to draws an estimated 23 million visits a month, most of them from Germany.

    Miruro

    miruro

    The rest reads like an international tour of well known streaming piracy brands. There are clones trading on the 123movies, Fmovies, and SolarMovie names, Spanish-language Pelisflix mirrors, the Chinese-language Gimy network, Hindi download portals, and some StreamEast-branded sports streaming portals that show matches from ACE member UEFA’s competitions.

    A full list of all domain names is available below . These include many mirror and copycat sites that only have minimal traffic.

    Some of the domains

    cf

    For every domain, ACE wants Cloudflare to hand over names, physical addresses, IP addresses, phone numbers, email addresses, payment details, and account histories. Whether this will yield any usable intel has yet to be seen, as pirate site operators tend to register false information. However, ACE hopes it points to at least some of the people involved.

    Two Discord Servers

    The second subpoena targets Discord and is filed at the Northern District of California. On behalf of ACE members, the MPA is requesting information linked to two servers and two accounts. These servers allegedly posted links to pirated copies of films including Wreck-It Ralph and Shutter Island, as well as episodes of Invincible and The Pitt.

    The legal paperwork isn’t very informative as it only lists numeric server, account, and channel IDs, without any server or usernames attached. We could not link this information to any server names, but we do know when they were created.

    Discord servers

    discord

    Every Discord ID is stamped with the moment it was created. For one of the servers, the user, channel and server were all created in September 2025, in the span of 30 minutes. After that, it remained active until earlier this month.

    The second server is much older. It was created in September 2020, while the account flagged alongside it was created last November. This means that the account that allegedly posts the content isn’t the one that created the server.

    The Servers are Gone

    At the time of writing, both servers have already been deleted. Whether Discord pulled the servers or the operators deleted them first is not clear, but MPA specifically asked Discord to take action in a separate takedown notice.

    MPA informed Discord that the sole purpose of these servers is to “link Discord users to an online service” that provides access to pirated movies and series. This suggests that the Discord server was linked to a pirate streaming portal.

    “We request that Discord remove or otherwise disable access to the server,” MPA’s notice reads.

    Notably, the subpoena request is much more targeted than the DMCA subpoena Take-Two requested in its search of the GTA 6 leaker. That subpoena requested information of thousands of users connected to three servers. Here, it only seeks identifying information on the operators of the two servers and two specific accounts.

    The DMCA subpoena requests have yet to be signed off by a court clerk, which means that the subpoenas have yet to be issued.

    The Cloudflare DMCA subpoena request, filed at the U.S. District Court for the Central District of California, is available here (pdf) . The Discord subpoena request is available here (pdf) and was filed at the Northern District of California.

    The 49 domains named in the Cloudflare subpoena are:

    Aniworld.to, miruro.tv, flixbaba.mov, flixbaba.is, flixmomo.tv, encontrei.info, fastflix.top, seeflix.to, empire-streaming.us, fmoviess.org, yesmovies.ag, tinyzone.org, solarmovie2.com, streamzy.org, watchnest.to, watchnest.org, indexflix.to, indexflix.org, imdb.su, streamimdb.ru, miruro.ru, pelisflix200.work, pelisflix200.club, pelisflix200.best, pelisflix1.cc, pelisflix1.bio, pelisflix1.de, coflix.esq, gimy.tv, gimy.now, gimyv.com, 94580.net, movieffm.net, gimytv.biz, gimytube.com, miruro.to, miruro.bz, repelisplus.my, 94itv.app, 99itv.net, solarmovies.co, 123moviesfun.is, moviesmod.at, moviesmod.zone, nupload.top, thestreameast.fun, direttecommunity.online, livetv903.me, streameasti.is.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Belgian Orders Demand Pirate Site Operators’ Bank Details, Crypto Wallets and Server Logs

      news.movim.eu / TorrentFreak • 2 days ago • 4 minutes

    bitcoin Belgium’s Department for Combating Online Infringement ( BAPO ) regularly issues site blocking decisions, which are grounded in orders from the Brussels Business court.

    These blocking efforts yield some results but pirate sites often switch domain names quickly, frustrating the enforcement efforts.

    With a series of new decisions issued this week, Belgium’s anti-piracy department is trying to tackle the piracy problem more directly. Instead of blocking the sites, they compel domain name registrars to identify the associated operators.

    Domain Registrars and a Registry

    As with the blocking effort, the five decisions are linked to an order from the French-speaking Business Court of Brussels . Four decisions are addressed to domain registrars, while the fifth targets a domain name registry that holds registrant records directly.

    The order and the decisions are redacted and don’t mention the rightsholder or the targeted websites.

    That said, the court’s reasoning refers to the need to preserve “the sports economy and the European solidarity model”, which clearly points at sports piracy. And there are more tells that allow us to name several of the targeted intermediaries.

    BAPO told TorrentFreak the secrecy is not its own choice but the court’s. The judge “ordered the disclosure of information to enable the plaintiff to identify the infringer and conduct further investigations,” it said, and separately “ordered that the identity of the targeted content and intermediary may not be disclosed.”

    BAPO did not say whether the domain names would be identified later, but three intermediaries are accidentally mentioned by name. One decision instructs Hosting Concepts to send the requested information to BAPO, another sets a deadline for Hostinger , while a third does the same for Key Systems . Every other mention in those documents is replaced with placeholders.

    These are all EU-based domain registrars. The fourth registrar and the domain name registry are not named. The same is true for the domain names that are targeted.

    Bank Details, Crypto Wallets, and Server Logs

    The four registrar decisions each demand the same seven categories of information. This includes a long list of data that should be handed over, including the customer’s name, every postal address, email address and phone number ever attached to the account.

    The intermediaries are also compelled to disclose “the full IBANs and the exact names of the holder(s) of the relevant bank accounts”, and card details down to the issuing bank, country of issue and card type.

    Payments in cryptocurrency are covered too. The orders cover any “means of payment in crypto-assets, where applicable, including in particular the wallet addresses used, the type of crypto-asset concerned, and the transaction identifiers (hash IDs)”.

    Targeted information

    The registrars also have to check their logs for the target’s IP address, device type, operating system and browser used to create the account, followed by “all logs and connection data retained by the relevant intermediary relating to the use of the customer account over the last twelve (12) months”.

    IP-addresses, logs, user-agent

    The domain registry decision is more narrow, requesting registrant details, the identity of the registrar, the nameservers in use, and the history of changes. The Brussels Business court concluded that these demands are proportionate and BAPO has relayed these to the intermediaries.

    Gag Order

    The decisions come with a gag order. The domain registrars and registry are not allowed to disclose the information-seeking request to their customers or any third parties, including the press.

    That order covers “any information concerning the very existence of these proceedings or of the order, or of any matter connected with the proceedings”.

    The EU’s Digital Services Act ( DSA ) normally requires a provider to inform affected users that their data has been handed over. However, BAPO notes that there is an exception when criminal investigation and prosecution are at stake, which it believes applies here.

    Not Informed

    not informed

    What the criminal allegations are isn’t immediately clear. However, the order effectively means that the pirate site operators can have their identity, banking history and connection logs handed over to rightsholders without their knowledge.

    Can it be Enforced?

    The decisions rely on Article 10 of the DSA, which covers how an information order applies to a provider elsewhere in the EU. BAPO’s actual powers come from Belgian law, and all the named intermediaries sit outside Belgium, so whether it can enforce the measures against them has yet to be seen.

    BAPO went further, telling TorrentFreak the orders aren’t even limited to the EU. Under the Belgian civil procedure and the DSA, it said, “every intermediary whose service is being used to give access to illegal content within the Belgian territory can be ordered to disclose information regarding its customer.”

    That is a broad claim. Whether it holds up in practice is another matter.

    Unfortunately, the press and the public at large are left in the dark, as it remains a mystery who requested the order, who it targets, and which other intermediaries it applies to.

    Whether any of the intermediaries have complied yet is unknown and, given the gag order, they are not likely to let anyone know.

    Copies of BAPO’s five decisions are available here (pdf) , here (pdf) , here (pdf) , here (pdf) and here (pdf) .

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Cineby Starts Staged Shutdown of Its Piracy Empire

      news.movim.eu / TorrentFreak • 3 days ago • 2 minutes

    cineby logo Piracy portal Cineby has started its planned shutdown , which now comes with a detailed schedule.

    A new announcement on the site lays out a staged process that runs for more than a week, taking the operation offline one service at a time.

    “We’ve decided to wind things down in stages,” the operators write, without explaining why they are throwing in the towel.

    With more than 160 million estimated visits last month, Cineby is one of the most popular pirate sites online. The same operation also includes Fmovies+ and Cineplay, each with millions of monthly visits on their own.

    September 5: The End

    The shutdown started by redirecting these companion sites to the main domain, followed by seven additional stages, listed below.

    Aug 25: Mirror sites Fmovies+ and Cineplay redirect to Cineby.
    Aug 26: Anime and sports streams switched off.
    Aug 27: File downloads switched off.
    Aug 28: Account system taken down, user accounts deleted.
    Aug 30: Last day to watch films and series.
    Aug 31: Film and series streaming switched off.
    Sept 1: Cineby says goodbye.
    Sept 5: Every remaining domain taken down for good.

    Earlier today the second step was completed on schedule with the livestream page going dark. The initial announcement suggested the whole operation would disappear on August 26, but the plans have changed.

    Cineby Live

    cineby live

    The operators now say the last films and series will play on August 30. The final domain names are now being taken offline on September 5, with Cineby noting that this step is irreversible.

    TorrentFreak reached out to Cineby earlier this week, hoping to find out more about the reason for the shutdown. The official email address bounced, however, so we don’t expect to get a response anytime soon.

    Legal Pressure

    The shutdown follows a year of steady legal pressure. For example, last fall the Motion Picture Association (MPA) named Cineby as a notorious piracy operation in its submission to the US Trade Representative, linking the operation to Russia.

    The Cineby brand was also targeted in several site-blocking orders this year. The site was listed in the UK “omnibus” order and Canada’s “expanded scope” order , which both covered Cineby and its future successors.

    In July a Delhi High Court order obtained by HBO targeted four Cineby domains. The main .at domain stayed online, however, suggesting its registrar had not acted on the Indian order.

    Staged

    Given this backdrop, it would not be a stretch to think that Cineby’s operators caved to the legal pressure, but history also leaves room for other options.

    Previously, we have seen popular pirate sites staging their own demise , to continue operating under a new brand. There is no evidence that this is happening here. If that’s the case, visitors will likely be redirected to a new site at some point.

    Announcement 2

    Cineby currently refers users to legal services including Apple TV and Amazon Prime. However, it also points to the FMHY subreddit, which provides an overview of pirate streaming alternatives. For now, the first thing to keep an eye on is whether the site sticks to its own schedule, or if plans change again.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      FlavaWorks Targets 75 Members of Gay-Torrents Tracker With RICO Lawsuit

      news.movim.eu / TorrentFreak • 5 days ago • 5 minutes

    gay torrents Over the past two decades, FlavaWorks has built a reputation as one of the most aggressive enforcers in the adult entertainment industry.

    The company has targeted both individual pirates and private torrent trackers through U.S. federal courts.

    Earlier this year, the Illinois-based company filed a high-profile lawsuit against Gay-Torrents.org, targeting the site’s operators, administrators, a Bulgarian shell company, and hundreds of individual members. That lawsuit prompted the operators to shut the site down , but that did not end their legal worries.

    The tracker’s users also remain on the radar and are at the center of a new legal campaign. A new complaint filed last week at an Illinois federal court targets a fresh batch of 75 members, including one named defendant and 74 John Does who are identified only by their site usernames. Notably, Flava filed it as a RICO case.

    RICO Complaint Against Torrent Users

    The complaint describes Gay-Torrents.org as an “association-in-fact enterprise” with the goal to profit from the unauthorized distribution of copyrighted works. The RICO complaint, referring to the federal racketeering statute, alleges that the tracker’s members contributed to the racketeering operation. This claim comes in addition to a copyright infringement allegation.

    Members who uploaded and downloaded infringing content are characterized as “lower-rung participants” who supplied the site’s infringing inventory, participating in Gay-Torrents’ sharing-ratio system. Those members who paid for VIP access are seen as “funders” and face an additional allegation of wire fraud.

    FlavaWorks argues that every VIP payment was a fraudulent act. Members were sent to sham web-hosting fronts and ordered ‘VPS plans’ they knew did not exist. The goal of these disguised payments was to conceal the true nature of the transaction from banks and payment processors.

    “On information and belief, the enterprise generated in excess of €7,000,000 since 2009 across more than 15,000 documented VIP payment events, each invoiced as a sham “web-hosting” fee,” the complaint reads.

    From the complaint

    7m

    This €7 million figure is an estimation based on Flava’s calculations, covering all revenue that was generated in 17 years. This same number was also cited in the April lawsuit, where Flava requested an asset freezing order targeting the tracker’s alleged payment providers, including PayPal.

    Unique Forensic Identifier

    The sole named defendant is Jason A. S., a Virginia man who, according to the complaint, was a paying subscriber to FlavaWorks’ legal websites from March 2020 to July 2021. During that period, he allegedly downloaded more than 200 of the company’s works.

    FlavaWorks uses a forensic watermarking system that embeds a unique identifier into every file it delivered to subscribers. So when pirated copies of the videos with his identifier appeared on Gay-Torrents, Flava knew where they originated.

    Identifier

    identifier

    These copies were first spotted in 2022 and Flava writes that it sent a cease-and-desist notice to the defendant at the time. However, the man allegedly continued to use the site and copies of the content kept circulating up until 2025.

    In addition to distributing pirated content, Jason A. S. allegedly paid for a VIP membership too. That means he is both an uploader and a funder under the complaint’s RICO theory. This makes him the “anchor defendant” whose connection to Illinois gives the court jurisdiction over the remaining defendants through RICO’s provisions.

    The Case for RICO

    The first lawsuit also targeted members, but relied on copyright and state-law claims. That legal approach ran into a common problem: the amended complaint had to drop hundreds of defendants, apparently because they would not fall under the jurisdiction of an Illinois court.

    RICO solves that problem. The statute authorizes nationwide service of process, so Flava only needs one “anchor defendant” with ties to Illinois. After that, all co-conspirator defendants can be added to the case, as long as they live in the United States.

    It also raises the legal stakes. RICO provides higher damages and introduces conspiracy liability, which effectively means that a member who only paid VIP fees and never uploaded a single file could still face liability for the enterprise’s copyright infringement.

    To make the RICO theory work, Gay-Torrents’ operators should remain out of the case. Indeed, the complaint identified the operators as non-party co-conspirators instead of defendants.

    74 Does & the Evidence Trail

    The complaint lists 74 John Does, who are all identified by their Gay-Torrents.org username and internal user-ID number. Flava will try to identify these defendants as the case moves forward.

    Some of the evidence trail is straightforward. Usernames and user IDs are presumably visible to any member of a private tracker, and FlavaWorks clearly had at least one account on the site. After all, the forensic identifier matches come from FlavaWorks’ own system, comparing copies downloaded from the tracker against its subscriber records.

    In addition, the evidence shows that a Flava investigator purchased a VIP subscription at the tracker.

    VIP purchase

    payment

    The VIP payment data can also come from a different source. The complaint notes that subpoenas were issued to Skrill and PayPal in the first lawsuit, and those records would show which users paid for VIP memberships.

    How Flava identified the user download activity and other internal records is not immediately clear to us. The complaint refers broadly to “the Site’s own per-member records” without explaining how they were obtained.

    RICO Raises the Bar

    The RICO complaint accuses the defendants of direct and contributory copyright infringement, a RICO violation, and RICO conspiracy. It lists 85 copyrighted works, with statutory damages of up to $150,000 per work on the copyright claims. The RICO counts could add treble damages on top of that.

    However, RICO comes with a higher evidence bar. The criminal copyright infringement allegations, for example, need to show willfulness and commercial advantage or financial gain. On top of proving that, Flava must show a pattern of racketeering activity, how each defendant is involved, and more.

    The wire-fraud count also requires detailed evidence, to document the who, what, when, and how of each alleged fraudulent transaction.

    Whether Flava will litigate these claims in a trial has yet to be seen. Filing a RICO case raises the pressure on the defendants, but actually proving these claims against individual users at trial is much harder than pursuing a standard copyright infringement claim.

    For now, however, Flava has already reached its key goal by shutting the tracker down. In a way, this means that everything it gets out of the RICO complaint is a bonus. For the users, however, the stakes have been raised and the concerns are real.

    copy of the complaint, filed by FlavaWorks Entertainment, Inc. at the U.S. District Court for the Northern District of Illinois, is available here (pdf) .

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Anna’s Archive Owes $340 Million, Lost Several Domains, but It’s Still Online

      news.movim.eu / TorrentFreak • 6 days ago • 2 minutes

    anna's archive Mid August, shadow library Anna’s Archive faced extended downtime, which had many regular visitors concerned.

    These worries didn’t come out of nowhere as the site has been under quite a bit of legal pressure in recent months.

    Lawsuit Takes Domains Offline

    In January, the site lost its flagship .org domain . Initially it wasn’t clear what was behind this action but unsealed court records eventually connected it to a lawsuit filed by music companies. This case was a direct response to a Spotify scrape Anna’s Archive announced a few weeks earlier.

    The music companies obtained an injunction from a U.S. federal court to go after the site’s domain names. This took out not only the .ORG domain but also the .SE domain, as well as the .PM and .VG domains that were put in place as backups.

    Anna’s Archive eventually landed on .GL, .PK, and .GD domains, which remain active today. These are connected to registrars and registries based outside the United States that, apparently, do not comply with U.S. court orders.

    Two Lawsuits, $340 Million

    The music industry injunction also came with a substantial default judgment that was handed down in April. This includes a $322 million default judgment against the unknown operators of Anna’s Archive, who failed to show up in court.

    Anna’s Archive

    anna

    This judgment was soon followed by a similar request from a group of major book publishers, including Penguin Random House, Elsevier, and HarperCollins, who sued the shadow library at a New York federal court.

    That case also resulted in a default judgment, with a damages award that is smaller, but still substantial at $19.5 million . In addition, the court also issued an injunction targeting Anna’s Archive’s domain registrars and registries.

    ‘Coordinated Attack’

    With this backdrop, it is no surprise that legal troubles came to mind when the site became unreachable earlier this month. However, this time around, the threat appears to have come from elsewhere.

    After the site came back online, the official AnnaArchivist account attributed it to a coordinated attack by an unnamed party.

    “Apologies for the issues. We suspect a coordinated attack. We’ve mitigated the attack vectors…” the message read, while noting that memberships already include one to two extra days per month to account for downtime.

    Message from AnnaArchivist on Reddit

    anna

    Theoretically, an attack can also come from a rogue anti-piracy group, but there’s no evidence for that. A scam or phishing operation, which tries to cash in on Anna’s Archive search traffic, is another option. Neither is confirmed.

    What Options Are Left?

    Looking more broadly at the enforcement action that has taken place over the past months, we see that U.S. courts have run into their jurisdictional borders on the Internet.

    This likely comes as a disappointment for rightsholders, but it also offers a clear takeaway.

    U.S. courts can’t reach domains registered beyond their jurisdiction. That’s likely to increase calls for site-blocking legislation, a measure the industry has long favored and that remains high on the political agenda in the United States.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Take-Two Expands GTA 6 Leak Hunt With DMCA Subpoenas to X and Google

      news.movim.eu / TorrentFreak • 6 days ago • 4 minutes

    gta6 Grand Theft Auto VI is one of the most anticipated game releases in years, with the official launch scheduled this fall.

    Rockstar Games and its parent company, Take-Two Interactive, have kept the game’s marketing under tight control, with a planned “Extended Look” at the gameplay premiering on Netflix later this month.

    However, a few days ago, millions of fans already got a sneak peek. On August 18, someone identifying as “Cyberleek” started posting unreleased gameplay footage online. These clips went viral on social media, despite Take-Two issuing a barrage of takedown notices.

    The leak came with a manifesto, criticizing the move away from physical discs, among other things. In addition, the leaked gameplay was branded with a Solana token advert.

    The Discord and Microsoft ‘Dragnet’ Subpoenas

    Take-Two did not take this leak lightly. As widely reported in the media, the game company requested two DMCA subpoenas at the U.S. District Court for the Southern District of New York, directed at Discord servers and at Microsoft’s internal cyberleek investigation, device identifiers, IP logs, and OneDrive content tied to GTA.

    The Discord subpoena is particularly broad. As highlighted by Tom’s Hardware , Kotaku , and others, the subpoena sought identifying details for every account that communicated in three named Discord servers since June 1, not only those tied to the leaks.

    Take-Two also seeks “all identifying information associated with all user accounts that are/were members of the Discord community servers and channels listed below.”

    Targeting Discord Users

    all data

    The Discord and Microsoft DMCA subpoena requests were filed by law firm Kirkland & Ellis. While some media reports suggest they have been issued, that’s not the case yet. A judge signed an order directing the clerk to issue, but the clerk hasn’t issued them.

    The docket does include a proposed subpoena, requiring Discord and Microsoft to disclose the requested information, as shown above. But there’s more.

    Take-Two Targets X

    A day after the initial subpoenas were requested, Take-Two applied for DMCA subpoenas against X Corp. and Google, again at the Southern District of New York. These filings came from a different law firm, Ruttenberg IP Law, and are more narrowly targeted.

    The proposed X subpoena lists three usernames: @cyberleek_ar_io, @cyberleekario, and @MrCyberLeek. For each, it demands the account ID, registration email, IP access logs, phone numbers, connected accounts, and any associated device identifiers, again covering June 1 to the present.

    Proposed subpoena

    proposed

    Notably, the GTA fan community had flagged these accounts as impostors before the subpoena was filed. Cyberleek also watermarked “CYBERLEEK DOES NOT HAVE TWITTER” onto later leaked videos. The named X accounts are now all suspended.

    NO TWITTER

    no twitter

    Whether Take-Two treats these X accounts as impostors who copied the leaks, or as the source, is not mentioned in the filing.

    The YouTube Channel Subpoena

    The Google/YouTube subpoena is a lot narrower than the Discord sweep. It names a single YouTube video and three channels that are believed to be associated with it: CyberLeeks, Surfer24k, and Cyberleek_ar_io.

    Surfer24k also appears in the Discord subpoena, as it is linked to one of the named servers. Obtaining personal records for this user from both Google and Discord allows Take-Two to compare the information of both platforms.

    An exhibit filed with the petition lists Rockstar’s takedown request on YouTube. The company logged a reference file as “UNAUTH_2026AUG_VIDEO2,” and YouTube’s Content ID system flagged and claimed the matching upload shortly after it went live.

    YouTube flag

    yt

    The same exhibit shows a “BUY $CYBERLEEK ON SOLANA” watermark on the footage, as shown above.

    Not Disclosed, Yet

    None of the four filings is a lawsuit. They are subpoenas issued under Section 512(h) of the DMCA, which lets a copyright holder compel a service provider to identify an alleged infringer without first suing anyone.

    These subpoenas do not require a ruling on the merits and a signature from the court clerk is sufficient, as long as all other conditions are met.

    As it stands, none of the four subpoenas has been issued. Judge Andrew L. Carter Jr. and Judge Jennifer L. Rochon each signed an order directing the clerk to act, but the clerk has not yet done so. No user data has changed hands as a result.

    Notably, DMCA subpoenas are restricted to targeting alleged infringers that are tied to specific material. Whether that covers thousands of Discord users, many of whom may have posted nothing at all, is up for debate.

    Take-Two’s counsel declared that the purpose of the subpoenas is “to obtain the identity of an alleged infringer or infringers, and that such information will only be used for the purpose of protecting Take-Two’s rights.” This means that a lawsuit could eventually follow.

    The purpose…

    purpose

    Before that happens, however, it is possible that the targeted intermediaries or their users will file an objection. Service providers regularly resist DMCA subpoenas which they see as being overbroad, and targeted users can move to quash.

    It’s clear that Take-Two is determined to get the leaker’s identity, but how broad its DMCA dragnet can reach has yet to be seen.

    A copy of the request for a DMCA subpoena directed at Google/YouTube is available here ( pdf , pdf , pdf ) and the X Corp variant is here ( pdf , pdf , pdf ).

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Nintendo Wipes Out 400+ Switch Emulator Repos in Single-Day GitHub Sweep

      news.movim.eu / TorrentFreak • 21 August 2026 • 3 minutes

    nintendo-sw-emu-s GitHub is home to hundreds of millions of code repositories, including some repositories that rightsholders would rather not see online.

    For Nintendo, Switch emulators have become the main challenge, one that keeps rearing its head.

    Most of these emulators were killed off long ago. Yuzu settled in February 2024, for example, Ryujinx shut down that October, and the successors that tried to keep edited versions online have been targeted in waves ever since.

    These waves keep coming. Earlier this week, Nintendo filed seven separate DMCA anti-circumvention notices at GitHub, all on the same day, targeting a variety of Switch emulator repositories and their forks. The combined reach is substantial. In the seven notices, more than 400 repositories were targeted.

    More Than 400 Repos

    The most detailed notice targets suyu, an emulator that became popular after Yuzu’s collapse. Because the reported network was larger than 100 repositories, GitHub processed the notice against the entire network, which covered 311 repos.

    The remaining six notices ranged from a lone repository to networks of a few dozen, including the independent Skyline emulator, as shown below.

    Parent repo (notice) Project Targets
    vstyler96/suyu suyu (yuzu successor) 311 repos (full network)
    skyline-emu/skyline Skyline (Android, independent) 29 repos (full network)
    NicolasArvani/yuzu yuzu fork 14 repos (full network)
    liushuyu/yuzu-android yuzu (Android port) 8 repos (full network)
    exverge-0/yuzu-EA4176 yuzu (Early Access build 4176) 21 forks listed
    irlbunny-archive/MonoNX MonoNX (C#-based) 17 forks listed
    IpwnedU/yuzu-master yuzu fork Parent only

    For four of the seven notices, the table shows GitHub’s own count of the processed network, including the parent repo. For the other three, no network details were published, so the table shows the repositories named in the notice itself, including some that were redacted as “[private].”

    The legal argument is the same in all seven. Nintendo argues that the emulators exist to bypass the encryption that protects its games, which violates the DMCA.

    “During operation, the emulators at the reported repositories necessarily use unauthorized copies of these cryptographic keys to decrypt unauthorized copies of Nintendo Switch games, or ROMs, at or immediately before runtime without Nintendo’s authorization,” the notice read.

    Repository Unavailable

    suyu

    Most of these repositories now link to notices informing visitors that they were removed. In some cases, they point to a 404 error, suggesting that the developer voluntarily removed the repository after being notified.

    Precedents Without a Trial

    To back the circumvention argument, every notice cites two court decisions as precedents, neither of which was challenged in court.

    The first is the 2024 consent judgment against Tropic Haze, the company behind Yuzu, which ended in a $2.4 million settlement . The second is newer: Nintendo’s case against streamer Jesse Keighin, aka “EveryGameGuru,” who was ordered to pay $17,500 last October after a Colorado court entered a default judgment against him.

    One was a settlement, the other a default judgment after Keighin reportedly stopped responding and destroyed evidence. In neither case did a court weigh the emulator circumvention question on the merits.

    From Nintendo’s notice

    suyu

    At the takedown stage Nintendo does not need to show a legal precedent. GitHub says it reviews circumvention claims carefully and will “err on the side of the developer, and leave the content up” when validity is unclear. The Yuzu framework has made Nintendo’s notices close to routine anyway.

    Defunct Skyline & Future Horizon

    Among the targeted emulators Skyline stands out, as it was a Switch emulator for Android devices, not a yuzu fork. Skyline’s developers shut the project down voluntarily in 2023, but as is often the case, the open source code survived.

    This week, Nintendo’s takedown notice cleared a network of 29 Skyline repos, including code that has been dormant for years. This doesn’t necessarily deal with the problem permanently, as future takedown efforts are likely on the horizon.

    Every emulator on this week’s list was already supposed to be gone. However, they were forked, mirrored, or revived, which put them on Nintendo’s radar again.

    For Nintendo, getting these emulator repos removed from GitHub is the easy part. Keeping the code offline is a bigger challenge, as forks may reappear faster than the notices can remove them.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      ‘Filmmaker’ Who Sued PTP, BTN, and Four Other Private Torrent Trackers May Be an Impostor

      news.movim.eu / TorrentFreak • 20 August 2026 • 4 minutes

    ptp Last September, we reported that a filmmaker named Matthew Schneider obtained a DMCA subpoena through a California federal court, seeking information from Cloudflare on several prominent private trackers.

    These trackers, including PassThePopcorn, BroadcasTheNet, KaraGarga, HDBits, and Beyond-HD, allegedly shared several of his works without permission.

    At the time, multiple sources informed TorrentFreak that several of the “infringing URLs” submitted as evidence did not point to working torrent pages and used URL structures that didn’t match the targeted sites. The films could not be found on several of the trackers either.

    After that, the docket went quiet, until last December, when the person identifying himself as Schneider escalated the matter through a federal copyright lawsuit.

    Filmmaker Files Federal Lawsuit

    In a complaint filed in the Northern District of Illinois, the filmmaker sued ten unnamed ‘John Doe’ defendants, alleging that all six trackers are part of a single coordinated “piracy Enterprise” run by the same people.

    The complaint named PassThePopcorn.me, BroadcasTheNet, KaraGarga.in, HDBits.org, Beyond-HD.me, and Bibliotik.me, calling them “coordinated access points to the same underlying BitTorrent-based distribution service.”

    From the complaint

    unified

    The plaintiff filed pro se, which means that he’s not represented by an attorney. He listed a mailing address in Sanborn, New York, while the complaint described him as a UK-based filmmaker.

    Fabricated Evidence?

    In February 2026, the court allowed Schneider to subpoena seven companies, Reddit, GoDaddy, Cloudflare, PayPal, Stripe, Namecheap, and X Corp, requesting identity information on the Doe defendants.

    This triggered an objection from several of the Doe defendants, who filed motions to quash through their attorneys. As a result, all seven subpoenas were placed in abeyance in May, until these outstanding motions would be decided.

    One of the defendants, identified as Doe 7 and linked to a Reddit account, accused the plaintiff of building the case on fabricated evidence.

    Doe 7 wrote that the sworn declaration supporting the discovery motion came from “Saumya Shah, Partner and Senior Investigator” at a UK firm called “Northbridge Digital Investigations.” Doe 7 searched the UK Companies House registry and found no such company. No trace of Shah appeared anywhere online. TorrentFreak independently confirmed these claims.

    From Doe 7’s motion to quash

    show

    The same Doe defendant also challenged the roughly 130 URLs submitted as evidence. Intriguingly, the exhibit also includes URLs from other pirate sites and WHOIS lookups on at least ten additional private tracker domains not named in the complaint.

    Schneider, meanwhile, doubled down that the copyright infringement claims against Doe 7 are valid, but he did not address whether an investigator named Shah exists or Northbridge is a real company.

    The Real Matthew Schneider

    Yesterday, TorrentFreak listened in as all parties were present at a telephonic hearing before Judge Andrea R. Wood, to address the motions to quash and a motion to proceed anonymously. However, that hearing took an unexpected turn, which changes the stakes.

    Before the hearing began, defense counsel Erin Russell , representing Doe 1, had contacted the judge’s chambers directly to address an important matter. Russell acknowledged that this was an extraordinary step that wasn’t taken lightly. However, she felt it needed to be addressed before any rulings would be made.

    Russell, working alongside counsel for the other Does, Haley Finch , told the court they had developed serious suspicions that the person litigating as Matthew Schneider is not the real Matthew Schneider.

    Both counsel conducted detailed research and traced the listed films and Schneider to a Canadian production company, Dirtbag Films , which we had separately identified in our earlier coverage.

    Some of Dirtbag Films’ works

    dirtbag

    However, the finding that Schneider is Canadian does not match the information shared by the person who presented himself as Schneider in court.

    Finch, who is a Canadian attorney, had a personal contact connected to Dirtbag Films and through that connection, she eventually reached the actual filmmaker. Russell, meanwhile, reached out to a Dirtbag contact separately and was also connected to the Canadian Matthew Schneider.

    The attorneys informed the court that the real Matthew Schneider signed a declaration confirming his identity and that he resides in Ontario, Canada.

    After being confronted with this information, Judge Wood asked the plaintiff on the call to respond. He said he did not see why this information would delay any rulings. At the end of the hearing, he stated, “I’m Matthew Schneider,” while stressing that the case should not be delayed.

    The Stakes Shift

    Judge Wood did not rule on any of the pending motions to quash or proceed anonymously. She also denied the plaintiff’s motion to strike Doe 7’s filings.

    Instead, she signaled that, if the allegations are true, the plaintiff could face sanctions, directing the defense to file a motion supported by the declaration from the Canadian Matthew Schneider. In addition, she scheduled an in-person hearing next month to resolve the identity questions.

    In the meantime, Judge Wood stressed that the plaintiff may not seek to obtain personal information about the Does and that nothing identifying the defendants should be filed on the docket.

    Doe 7, who also appeared on the call with his prospective counsel, indicated that he anticipates filing a motion to join the defense filings submitted by the other Does.

    Before yesterday’s hearing, this lawsuit was already quite novel, as it is the first one that targets multiple prominent private torrent trackers. Now, the stakes have completely changed, with an unprecedented impersonation claim, which, if it turns out to be true, will likely lead to a dismissal and sanctions for the plaintiff.

    A copy of Doe 7’s motion to quash is available here (pdf) . The plaintiff’s motion to strike Doe 7’s filings can be found here (pdf) . The original complaint can be found here (pdf) .

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      A German Court Drew the Piracy Line at 81.5%, KinoGO Was Blocked with (at least) 82.4%

      news.movim.eu / TorrentFreak • 19 August 2026 • 3 minutes

    stop danger Since 2021, major German Internet providers have agreed to block the country’s most egregious pirate sites through the Clearing Body for Copyright on the Internet, better known as CUII .

    The system started as an administrative scheme without judicial oversight. CUII’s own committee issued blocking recommendations, and the Federal Network Agency signed off before providers acted.

    This setup changed in mid-2025 , when the stakeholders rewrote their code of conduct so that every block now starts with a rightsholder suing one ISP. Once a court confirms the block, the other providers follow.

    CUII no longer issues the orders, but it will still communicate the recommendations to all participants. In recent weeks, the clearing body published several new ones based on orders from the Cologne Regional Court, targeting KinoGo and Streamed.

    The structural infringement check

    The court orders are not available to us, but according to CUII’s paperwork, these targets are classified as structurally copyright infringing websites, making the blocking orders “reasonable and proportionate.”

    As is typical in Germany, the requesting rightsholders and the targeted domains are not mentioned. However, based on the brands and data from the independent transparency portal CUIIListe , streamed.pk, streamed.st, and kinogo.ec were all blocked in Germany this month.

    CUII’s paperwork does reveal one hard statistic. For each site, a private investigator pulls a random sample of the site’s content, to see how much of it infringes at a 95.5 percent confidence level. This number is used to determine whether the target site is indeed ‘structurally’ infringing.

    For example, for Streamed, the investigator put the infringing share somewhere between 96.16 and 100 percent. For KinoGo, meanwhile, between 82.4 and 94.6 percent of the content is pirated.

    The 82.4 percent floor is the lowest we have seen so far, below all previous German blocking orders we have seen, including the ones below.

    Site Ruling Share infringing
    KinoGO Jul 2026 82.4% to 94.6%
    LIVETV.SX Apr 2026 85.28% to 96.72%
    SPORTPLUS Feb 2026 88.8% to 100%
    MegaKino Feb 2024 89.8% to 100%
    Kinoger Nov 2025 91.4% to 99.0%
    Anna’s Archive Sep 2025 91.6% to 94.8%
    NSWPedia Jan 2026 94.4% to 99.8%
    s.to Feb 2021 94.84% to 100%
    LibGen May 2024 96.07% to 98.23%
    Streamed Jul 2026 96.16% to 100%
    cine.to Jun 2022 96.28% to 100%

    The 81.5% ‘Line’

    In a March 2025 order targeting HDFILME, STREAMCLOUD and FILMPALAST, CUII specifically stated when illegal content clearly outweighs the legal content on a site.

    “The illegal content on the websites far outweighs the legal content. This is the case in any event when at least 81.5% of the website’s content is illegal,” the order reads , translated from German.

    It is the only CUII order we found that puts a number on it. The figure traces back to the Cologne Regional Court, which set it in a January 2025 default judgment against the download portal NOX, a case the operator never contested. That same judgment triggered NOX’s own block.

    In KinoGo’s example, the 82.4 percent floor is getting quite close to the 81.5 percent.

    KinoGo

    This percentage is not a hard benchmark for the court or for CUII to determine whether a site is blockable. However, one can imagine that it’s not a good look when it drops lower than that, especially when legal content would outweigh their pirated counterparts.

    This doesn’t mean that KinoGo is a questionable target. The site has been a thorn in the side of rightsholders for many years. It has more than 50 million monthly visits, mostly from Belarus and Ukraine, which it has historically targeted.

    Hiding in Plain Content?

    The open question is how much of a site’s library has to be pirated before a block can be issued in Germany, and whether 81.5 percent is considered to be a general benchmark or just a figure tied to that one case.

    If there is a fixed percentage, there are some obvious exploits that come to mind. In theory, an operator could pad an archive with public domain films or AI generated filler, pushing the investigator’s interval below the line while the pirated library stays intact.

    We asked CUII whether the 81.5 percent can be treated as a fixed benchmark, but it has not responded by the time of publication. We will update this article if they do.

    Update: Romsns.com is also blocked. CUII just published the associated recommendation. The Virustotal scan below shows that there are multiple malware warnings for this comain.

    romsns

    A copy of the Streamed order can be found here (pdf) and the KinoGo order can be found here (pdf) . An archive of all CUII determinations is also available on the clearinghouse’s official website .

    From: TF , for the latest news on copyright battles, piracy and more.