• To chevron_right

      Anna’s Archive Owes $340 Million, Lost Several Domains, but It’s Still Online

      news.movim.eu / TorrentFreak • 11:35 • 2 minutes

    anna's archive Mid August, shadow library Anna’s Archive faced extended downtime, which had many regular visitors concerned.

    These worries didn’t come out of nowhere as the site has been under quite a bit of legal pressure in recent months.

    Lawsuit Takes Domains Offline

    In January, the site lost its flagship .org domain . Initially it wasn’t clear what was behind this action but unsealed court records eventually connected it to a lawsuit filed by music companies. This case was a direct response to a Spotify scrape Anna’s Archive announced a few weeks earlier.

    The music companies obtained an injunction from a U.S. federal court to go after the site’s domain names. This took out not only the .ORG domain but also the .SE domain, as well as the .PM and .VG domains that were put in place as backups.

    Anna’s Archive eventually landed on .GL, .PK, and .GD domains, which remain active today. These are connected to registrars and registries based outside the United States that, apparently, do not comply with U.S. court orders.

    Two Lawsuits, $340 Million

    The music industry injunction also came with a substantial default judgment that was handed down in April. This includes a $322 million default judgment against the unknown operators of Anna’s Archive, who failed to show up in court.

    Anna’s Archive

    anna

    This judgment was soon followed by a similar request from a group of major book publishers, including Penguin Random House, Elsevier, and HarperCollins, who sued the shadow library at a New York federal court.

    That case also resulted in a default judgment, with a damages award that is smaller, but still substantial at $19.5 million . In addition, the court also issued an injunction targeting Anna’s Archive’s domain registrars and registries.

    ‘Coordinated Attack’

    With this backdrop, it is no surprise that legal troubles came to mind when the site became unreachable earlier this month. However, this time around, the threat appears to have come from elsewhere.

    After the site came back online, the official AnnaArchivist account attributed it to a coordinated attack by an unnamed party.

    “Apologies for the issues. We suspect a coordinated attack. We’ve mitigated the attack vectors…” the message read, while noting that memberships already include one to two extra days per month to account for downtime.

    Message from AnnaArchivist on Reddit

    anna

    Theoretically, an attack can also come from a rogue anti-piracy group, but there’s no evidence for that. A scam or phishing operation, which tries to cash in on Anna’s Archive search traffic, is another option. Neither is confirmed.

    What Options Are Left?

    Looking more broadly at the enforcement action that has taken place over the past months, we see that U.S. courts have run into their jurisdictional borders on the Internet.

    This likely comes as a disappointment for rightsholders, but it also offers a clear takeaway.

    U.S. courts can’t reach domains registered beyond their jurisdiction. That’s likely to increase calls for site-blocking legislation, a measure the industry has long favored and that remains high on the political agenda in the United States.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Take-Two Expands GTA 6 Leak Hunt With DMCA Subpoenas to X and Google

      news.movim.eu / TorrentFreak • 21 hours ago • 4 minutes

    gta6 Grand Theft Auto VI is one of the most anticipated game releases in years, with the official launch scheduled this fall.

    Rockstar Games and its parent company, Take-Two Interactive, have kept the game’s marketing under tight control, with a planned “Extended Look” at the gameplay premiering on Netflix later this month.

    However, a few days ago, millions of fans already got a sneak peek. On August 18, someone identifying as “Cyberleek” started posting unreleased gameplay footage online. These clips went viral on social media, despite Take-Two issuing a barrage of takedown notices.

    The leak came with a manifesto, criticizing the move away from physical discs, among other things. In addition, the leaked gameplay was branded with a Solana token advert.

    The Discord and Microsoft ‘Dragnet’ Subpoenas

    Take-Two did not take this leak lightly. As widely reported in the media, the game company requested two DMCA subpoenas at the U.S. District Court for the Southern District of New York, directed at Discord servers and at Microsoft’s internal cyberleek investigation, device identifiers, IP logs, and OneDrive content tied to GTA.

    The Discord subpoena is particularly broad. As highlighted by Tom’s Hardware , Kotaku , and others, the subpoena sought identifying details for every account that communicated in three named Discord servers since June 1, not only those tied to the leaks.

    Take-Two also seeks “all identifying information associated with all user accounts that are/were members of the Discord community servers and channels listed below.”

    Targeting Discord Users

    all data

    The Discord and Microsoft DMCA subpoena requests were filed by law firm Kirkland & Ellis. While some media reports suggest they have been issued, that’s not the case yet. A judge signed an order directing the clerk to issue, but the clerk hasn’t issued them.

    The docket does include a proposed subpoena, requiring Discord and Microsoft to disclose the requested information, as shown above. But there’s more.

    Take-Two Targets X

    A day after the initial subpoenas were requested, Take-Two applied for DMCA subpoenas against X Corp. and Google, again at the Southern District of New York. These filings came from a different law firm, Ruttenberg IP Law, and are more narrowly targeted.

    The proposed X subpoena lists three usernames: @cyberleek_ar_io, @cyberleekario, and @MrCyberLeek. For each, it demands the account ID, registration email, IP access logs, phone numbers, connected accounts, and any associated device identifiers, again covering June 1 to the present.

    Proposed subpoena

    proposed

    Notably, the GTA fan community had flagged these accounts as impostors before the subpoena was filed. Cyberleek also watermarked “CYBERLEEK DOES NOT HAVE TWITTER” onto later leaked videos. The named X accounts are now all suspended.

    NO TWITTER

    no twitter

    Whether Take-Two treats these X accounts as impostors who copied the leaks, or as the source, is not mentioned in the filing.

    The YouTube Channel Subpoena

    The Google/YouTube subpoena is a lot narrower than the Discord sweep. It names a single YouTube video and three channels that are believed to be associated with it: CyberLeeks, Surfer24k, and Cyberleek_ar_io.

    Surfer24k also appears in the Discord subpoena, as it is linked to one of the named servers. Obtaining personal records for this user from both Google and Discord allows Take-Two to compare the information of both platforms.

    An exhibit filed with the petition lists Rockstar’s takedown request on YouTube. The company logged a reference file as “UNAUTH_2026AUG_VIDEO2,” and YouTube’s Content ID system flagged and claimed the matching upload shortly after it went live.

    YouTube flag

    yt

    The same exhibit shows a “BUY $CYBERLEEK ON SOLANA” watermark on the footage, as shown above.

    Not Disclosed, Yet

    None of the four filings is a lawsuit. They are subpoenas issued under Section 512(h) of the DMCA, which lets a copyright holder compel a service provider to identify an alleged infringer without first suing anyone.

    These subpoenas do not require a ruling on the merits and a signature from the court clerk is sufficient, as long as all other conditions are met.

    As it stands, none of the four subpoenas has been issued. Judge Andrew L. Carter Jr. and Judge Jennifer L. Rochon each signed an order directing the clerk to act, but the clerk has not yet done so. No user data has changed hands as a result.

    Notably, DMCA subpoenas are restricted to targeting alleged infringers that are tied to specific material. Whether that covers thousands of Discord users, many of whom may have posted nothing at all, is up for debate.

    Take-Two’s counsel declared that the purpose of the subpoenas is “to obtain the identity of an alleged infringer or infringers, and that such information will only be used for the purpose of protecting Take-Two’s rights.” This means that a lawsuit could eventually follow.

    The purpose…

    purpose

    Before that happens, however, it is possible that the targeted intermediaries or their users will file an objection. Service providers regularly resist DMCA subpoenas which they see as being overbroad, and targeted users can move to quash.

    It’s clear that Take-Two is determined to get the leaker’s identity, but how broad its DMCA dragnet can reach has yet to be seen.

    A copy of the request for a DMCA subpoena directed at Google/YouTube is available here ( pdf , pdf , pdf ) and the X Corp variant is here ( pdf , pdf , pdf ).

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Nintendo Wipes Out 400+ Switch Emulator Repos in Single-Day GitHub Sweep

      news.movim.eu / TorrentFreak • 2 days ago • 3 minutes

    nintendo-sw-emu-s GitHub is home to hundreds of millions of code repositories, including some repositories that rightsholders would rather not see online.

    For Nintendo, Switch emulators have become the main challenge, one that keeps rearing its head.

    Most of these emulators were killed off long ago. Yuzu settled in February 2024, for example, Ryujinx shut down that October, and the successors that tried to keep edited versions online have been targeted in waves ever since.

    These waves keep coming. Earlier this week, Nintendo filed seven separate DMCA anti-circumvention notices at GitHub, all on the same day, targeting a variety of Switch emulator repositories and their forks. The combined reach is substantial. In the seven notices, more than 400 repositories were targeted.

    More Than 400 Repos

    The most detailed notice targets suyu, an emulator that became popular after Yuzu’s collapse. Because the reported network was larger than 100 repositories, GitHub processed the notice against the entire network, which covered 311 repos.

    The remaining six notices ranged from a lone repository to networks of a few dozen, including the independent Skyline emulator, as shown below.

    Parent repo (notice) Project Targets
    vstyler96/suyu suyu (yuzu successor) 311 repos (full network)
    skyline-emu/skyline Skyline (Android, independent) 29 repos (full network)
    NicolasArvani/yuzu yuzu fork 14 repos (full network)
    liushuyu/yuzu-android yuzu (Android port) 8 repos (full network)
    exverge-0/yuzu-EA4176 yuzu (Early Access build 4176) 21 forks listed
    irlbunny-archive/MonoNX MonoNX (C#-based) 17 forks listed
    IpwnedU/yuzu-master yuzu fork Parent only

    For four of the seven notices, the table shows GitHub’s own count of the processed network, including the parent repo. For the other three, no network details were published, so the table shows the repositories named in the notice itself, including some that were redacted as “[private].”

    The legal argument is the same in all seven. Nintendo argues that the emulators exist to bypass the encryption that protects its games, which violates the DMCA.

    “During operation, the emulators at the reported repositories necessarily use unauthorized copies of these cryptographic keys to decrypt unauthorized copies of Nintendo Switch games, or ROMs, at or immediately before runtime without Nintendo’s authorization,” the notice read.

    Repository Unavailable

    suyu

    Most of these repositories now link to notices informing visitors that they were removed. In some cases, they point to a 404 error, suggesting that the developer voluntarily removed the repository after being notified.

    Precedents Without a Trial

    To back the circumvention argument, every notice cites two court decisions as precedents, neither of which was challenged in court.

    The first is the 2024 consent judgment against Tropic Haze, the company behind Yuzu, which ended in a $2.4 million settlement . The second is newer: Nintendo’s case against streamer Jesse Keighin, aka “EveryGameGuru,” who was ordered to pay $17,500 last October after a Colorado court entered a default judgment against him.

    One was a settlement, the other a default judgment after Keighin reportedly stopped responding and destroyed evidence. In neither case did a court weigh the emulator circumvention question on the merits.

    From Nintendo’s notice

    suyu

    At the takedown stage Nintendo does not need to show a legal precedent. GitHub says it reviews circumvention claims carefully and will “err on the side of the developer, and leave the content up” when validity is unclear. The Yuzu framework has made Nintendo’s notices close to routine anyway.

    Defunct Skyline & Future Horizon

    Among the targeted emulators Skyline stands out, as it was a Switch emulator for Android devices, not a yuzu fork. Skyline’s developers shut the project down voluntarily in 2023, but as is often the case, the open source code survived.

    This week, Nintendo’s takedown notice cleared a network of 29 Skyline repos, including code that has been dormant for years. This doesn’t necessarily deal with the problem permanently, as future takedown efforts are likely on the horizon.

    Every emulator on this week’s list was already supposed to be gone. However, they were forked, mirrored, or revived, which put them on Nintendo’s radar again.

    For Nintendo, getting these emulator repos removed from GitHub is the easy part. Keeping the code offline is a bigger challenge, as forks may reappear faster than the notices can remove them.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      ‘Filmmaker’ Who Sued PTP, BTN, and Four Other Private Torrent Trackers May Be an Impostor

      news.movim.eu / TorrentFreak • 4 days ago • 4 minutes

    ptp Last September, we reported that a filmmaker named Matthew Schneider obtained a DMCA subpoena through a California federal court, seeking information from Cloudflare on several prominent private trackers.

    These trackers, including PassThePopcorn, BroadcasTheNet, KaraGarga, HDBits, and Beyond-HD, allegedly shared several of his works without permission.

    At the time, multiple sources informed TorrentFreak that several of the “infringing URLs” submitted as evidence did not point to working torrent pages and used URL structures that didn’t match the targeted sites. The films could not be found on several of the trackers either.

    After that, the docket went quiet, until last December, when the person identifying himself as Schneider escalated the matter through a federal copyright lawsuit.

    Filmmaker Files Federal Lawsuit

    In a complaint filed in the Northern District of Illinois, the filmmaker sued ten unnamed ‘John Doe’ defendants, alleging that all six trackers are part of a single coordinated “piracy Enterprise” run by the same people.

    The complaint named PassThePopcorn.me, BroadcasTheNet, KaraGarga.in, HDBits.org, Beyond-HD.me, and Bibliotik.me, calling them “coordinated access points to the same underlying BitTorrent-based distribution service.”

    From the complaint

    unified

    The plaintiff filed pro se, which means that he’s not represented by an attorney. He listed a mailing address in Sanborn, New York, while the complaint described him as a UK-based filmmaker.

    Fabricated Evidence?

    In February 2026, the court allowed Schneider to subpoena seven companies, Reddit, GoDaddy, Cloudflare, PayPal, Stripe, Namecheap, and X Corp, requesting identity information on the Doe defendants.

    This triggered an objection from several of the Doe defendants, who filed motions to quash through their attorneys. As a result, all seven subpoenas were placed in abeyance in May, until these outstanding motions would be decided.

    One of the defendants, identified as Doe 7 and linked to a Reddit account, accused the plaintiff of building the case on fabricated evidence.

    Doe 7 wrote that the sworn declaration supporting the discovery motion came from “Saumya Shah, Partner and Senior Investigator” at a UK firm called “Northbridge Digital Investigations.” Doe 7 searched the UK Companies House registry and found no such company. No trace of Shah appeared anywhere online. TorrentFreak independently confirmed these claims.

    From Doe 7’s motion to quash

    show

    The same Doe defendant also challenged the roughly 130 URLs submitted as evidence. Intriguingly, the exhibit also includes URLs from other pirate sites and WHOIS lookups on at least ten additional private tracker domains not named in the complaint.

    Schneider, meanwhile, doubled down that the copyright infringement claims against Doe 7 are valid, but he did not address whether an investigator named Shah exists or Northbridge is a real company.

    The Real Matthew Schneider

    Yesterday, TorrentFreak listened in as all parties were present at a telephonic hearing before Judge Andrea R. Wood, to address the motions to quash and a motion to proceed anonymously. However, that hearing took an unexpected turn, which changes the stakes.

    Before the hearing began, defense counsel Erin Russell , representing Doe 1, had contacted the judge’s chambers directly to address an important matter. Russell acknowledged that this was an extraordinary step that wasn’t taken lightly. However, she felt it needed to be addressed before any rulings would be made.

    Russell, working alongside counsel for the other Does, Haley Finch , told the court they had developed serious suspicions that the person litigating as Matthew Schneider is not the real Matthew Schneider.

    Both counsel conducted detailed research and traced the listed films and Schneider to a Canadian production company, Dirtbag Films , which we had separately identified in our earlier coverage.

    Some of Dirtbag Films’ works

    dirtbag

    However, the finding that Schneider is Canadian does not match the information shared by the person who presented himself as Schneider in court.

    Finch, who is a Canadian attorney, had a personal contact connected to Dirtbag Films and through that connection, she eventually reached the actual filmmaker. Russell, meanwhile, reached out to a Dirtbag contact separately and was also connected to the Canadian Matthew Schneider.

    The attorneys informed the court that the real Matthew Schneider signed a declaration confirming his identity and that he resides in Ontario, Canada.

    After being confronted with this information, Judge Wood asked the plaintiff on the call to respond. He said he did not see why this information would delay any rulings. At the end of the hearing, he stated, “I’m Matthew Schneider,” while stressing that the case should not be delayed.

    The Stakes Shift

    Judge Wood did not rule on any of the pending motions to quash or proceed anonymously. She also denied the plaintiff’s motion to strike Doe 7’s filings.

    Instead, she signaled that, if the allegations are true, the plaintiff could face sanctions, directing the defense to file a motion supported by the declaration from the Canadian Matthew Schneider. In addition, she scheduled an in-person hearing next month to resolve the identity questions.

    In the meantime, Judge Wood stressed that the plaintiff may not seek to obtain personal information about the Does and that nothing identifying the defendants should be filed on the docket.

    Doe 7, who also appeared on the call with his prospective counsel, indicated that he anticipates filing a motion to join the defense filings submitted by the other Does.

    Before yesterday’s hearing, this lawsuit was already quite novel, as it is the first one that targets multiple prominent private torrent trackers. Now, the stakes have completely changed, with an unprecedented impersonation claim, which, if it turns out to be true, will likely lead to a dismissal and sanctions for the plaintiff.

    A copy of Doe 7’s motion to quash is available here (pdf) . The plaintiff’s motion to strike Doe 7’s filings can be found here (pdf) . The original complaint can be found here (pdf) .

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      A German Court Drew the Piracy Line at 81.5%, KinoGO Was Blocked with (at least) 82.4%

      news.movim.eu / TorrentFreak • 4 days ago • 3 minutes

    stop danger Since 2021, major German Internet providers have agreed to block the country’s most egregious pirate sites through the Clearing Body for Copyright on the Internet, better known as CUII .

    The system started as an administrative scheme without judicial oversight. CUII’s own committee issued blocking recommendations, and the Federal Network Agency signed off before providers acted.

    This setup changed in mid-2025 , when the stakeholders rewrote their code of conduct so that every block now starts with a rightsholder suing one ISP. Once a court confirms the block, the other providers follow.

    CUII no longer issues the orders, but it will still communicate the recommendations to all participants. In recent weeks, the clearing body published several new ones based on orders from the Cologne Regional Court, targeting KinoGo and Streamed.

    The structural infringement check

    The court orders are not available to us, but according to CUII’s paperwork, these targets are classified as structurally copyright infringing websites, making the blocking orders “reasonable and proportionate.”

    As is typical in Germany, the requesting rightsholders and the targeted domains are not mentioned. However, based on the brands and data from the independent transparency portal CUIIListe , streamed.pk, streamed.st, and kinogo.ec were all blocked in Germany this month.

    CUII’s paperwork does reveal one hard statistic. For each site, a private investigator pulls a random sample of the site’s content, to see how much of it infringes at a 95.5 percent confidence level. This number is used to determine whether the target site is indeed ‘structurally’ infringing.

    For example, for Streamed, the investigator put the infringing share somewhere between 96.16 and 100 percent. For KinoGo, meanwhile, between 82.4 and 94.6 percent of the content is pirated.

    The 82.4 percent floor is the lowest we have seen so far, below all previous German blocking orders we have seen, including the ones below.

    Site Ruling Share infringing
    KinoGO Jul 2026 82.4% to 94.6%
    LIVETV.SX Apr 2026 85.28% to 96.72%
    SPORTPLUS Feb 2026 88.8% to 100%
    MegaKino Feb 2024 89.8% to 100%
    Kinoger Nov 2025 91.4% to 99.0%
    Anna’s Archive Sep 2025 91.6% to 94.8%
    NSWPedia Jan 2026 94.4% to 99.8%
    s.to Feb 2021 94.84% to 100%
    LibGen May 2024 96.07% to 98.23%
    Streamed Jul 2026 96.16% to 100%
    cine.to Jun 2022 96.28% to 100%

    The 81.5% ‘Line’

    In a March 2025 order targeting HDFILME, STREAMCLOUD and FILMPALAST, CUII specifically stated when illegal content clearly outweighs the legal content on a site.

    “The illegal content on the websites far outweighs the legal content. This is the case in any event when at least 81.5% of the website’s content is illegal,” the order reads , translated from German.

    It is the only CUII order we found that puts a number on it. The figure traces back to the Cologne Regional Court, which set it in a January 2025 default judgment against the download portal NOX, a case the operator never contested. That same judgment triggered NOX’s own block.

    In KinoGo’s example, the 82.4 percent floor is getting quite close to the 81.5 percent.

    KinoGo

    This percentage is not a hard benchmark for the court or for CUII to determine whether a site is blockable. However, one can imagine that it’s not a good look when it drops lower than that, especially when legal content would outweigh their pirated counterparts.

    This doesn’t mean that KinoGo is a questionable target. The site has been a thorn in the side of rightsholders for many years. It has more than 50 million monthly visits, mostly from Belarus and Ukraine, which it has historically targeted.

    Hiding in Plain Content?

    The open question is how much of a site’s library has to be pirated before a block can be issued in Germany, and whether 81.5 percent is considered to be a general benchmark or just a figure tied to that one case.

    If there is a fixed percentage, there are some obvious exploits that come to mind. In theory, an operator could pad an archive with public domain films or AI generated filler, pushing the investigator’s interval below the line while the pirated library stays intact.

    We asked CUII whether the 81.5 percent can be treated as a fixed benchmark, but it has not responded by the time of publication. We will update this article if they do.

    Update: Romsns.com is also blocked. CUII just published the associated recommendation. The Virustotal scan below shows that there are multiple malware warnings for this comain.

    romsns

    A copy of the Streamed order can be found here (pdf) and the KinoGo order can be found here (pdf) . An archive of all CUII determinations is also available on the clearinghouse’s official website .

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Pirate Streaming Giant Cineby Announces Surprise Shutdown

      news.movim.eu / TorrentFreak • 17 August 2026 • 2 minutes

    cineby logo With more than 160 million visits last month, Cineby is one of the most popular pirate streaming sites on the Internet.

    The streaming portal has been a thorn in the side of Hollywood, with the Motion Picture Association ( MPA ) listing it as a notorious pirate site in its submission to the USTR last fall .

    “Cineby is a fast-growing one-stop-shop piracy site in the ‘hydra site’ category. These are a rapidly expanding category of one-stop piracy sites offering content somewhat comparable to IPTV services, but without the need for subscriptions or dedicated devices,” MPA wrote at the time, linking the operation to Russia.

    Enforcement Pressure Builds

    In addition to the diplomatic pressure, the movie industry was also the driving force behind several high-profile blocking orders against the site this year.

    In May, Cineby was listed as a target in the new UK “omnibus” site blocking order , for example, which also covers the site’s successors preemptively. The same applies to the recent “expanded scope” order from Canada’s federal court, which also covers Cineby and any potential successors.

    Cineby

    cineby

    In July, a Delhi High Court order obtained by HBO and other movie studios went further . This injunction covered four Cineby domains and directed Indian ISPs to block the sites, while domain registrars were ordered to suspend them.

    Despite the Indian order, Cineby’s main .at domain name remains online, suggesting that Registrar.eu has not complied with the Indian order. However, according to a recent announcement by the site’s operators, there soon might be no need to take action anymore.

    A Voluntary Shutdown?

    Visitors to Cineby’s website are currently greeted with a new announcement, suggesting that the site will shut down permanently in a few days.

    “Cineby and all related services will cease operations on August 26th. It’s been a good run, but the time has come to stop,” the site announces, adding that “all servers will be shut down, and every user account will be deleted.”

    The operators provide no rationale for this surprising decision. However, it is a reasonable assumption to suggest that the mounting enforcement pressure played a role.

    The shutdown announcement

    cineby shut down

    What will happen to the domain name when the site shuts down has yet to be seen. With millions of daily visits, the site has a massive audience, which will be looking for an alternative.

    The Hydra…

    Whether the operators will indeed shut down the site and get out of the business has yet to be seen. In the past, other sites have simply rebranded in an attempt to shake off the legal pressure. This includes the now-defunct HiAnime operation , which started as Zoro and also used the Aniwatch brand.

    According to the MPA, Cineby relied heavily on piracy-as-a-service (PaaS) infrastructure, embedding videos from third party sites. These remain online, which means that the underlying piracy problem remains.

    In the typical ‘hydra’ fashion, Cineby’s planned shutdown will result in plenty of new sites popping up; whether these are linked to the original site or not.

    This problem is one of the key reasons why the UK and Canadian site blocking orders were expanded to cover future Cineby copycats and successors, even if they don’t use the same brand. If everything happens according to plan, this new blocking power can be put to the test later this month.

    For now, however, cineby.at remains online, streaming pirated movies and TV shows as usual.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Researchers Hunt Telegram Pirates with AI Tool, Flag Hundreds of Channels

      news.movim.eu / TorrentFreak • 16 August 2026 • 4 minutes

    telegram logo Like many other public communication services, Telegram can be abused to facilitate illegal activities.

    While much of this occurs beyond the company’s purview, pirates appear to be drawn to the platform, sharing links to pirated movies, TV-shows and other content in dedicated channels.

    Despite this reputation, the platform’s piracy ecosystem has rarely been mapped in any detail. A new academic paper sets out to fill that gap, while also trying to offer a potential AI-powered solution to the problem.

    Researchers from Louisiana State University and the University of Texas at Arlington examined 1,057 channels that shared roughly 209,000 posts between December 2023 and January 2026. They describe it as the first large-scale study of video piracy on the platform.

    The results are detailed in the paper titled “Binge, Bot, Repeat: Unpacking the Ecosystem of Video Piracy on Telegram,” which provides some interesting new insights.

    The paper

    bbr paper

    The findings reveal that piracy is certainly not a fringe activity on Telegram. On the contrary, it is massively popular.

    4.85 billion post views for 19,033 titles

    To map the ecosystem, the researchers relied on a locally run large language model to label posts. This helped them to identify 19,033 unique pirated titles across various Telegram channels, including 14,632 movies and 4,401 TV shows produced by 3,941 companies.

    As on regular pirate sites, anime is rather popular. The most pirated rightsholder is Japan’s Toei Company, home to One Piece and Dragon Ball, which accounted for 17% of the titles. As shown below, Netflix is in second place with 15%, followed by Warner Bros. at 12.4%.

    Top Rightsholders

    top rightsholders

    These numbers get more context when looking at the total views. According to the researchers, the ‘pirate’ posts were found on 983 channels where they amassed 4.85 billion views.

    The views are not per title, as a single post can include more titles. Nonetheless, the researchers estimate a total loss of $17.49 billion, with United States content accounting for $8.17 billion and Japanese content $3.72 billion.

    This is a loose estimate, assuming that 1% of the views translate into lost sales, based on the cheapest legal option available. Also, the researchers capped lost sales at a single subscription cost when multiple titles from one service were linked.

    Built to Survive Takedowns

    One of the most noteworthy findings is that piracy channels use a wide variety of distribution techniques, with content scattered across interconnected channels, bots, and backup accounts.

    Roughly 94% of the AI-mapped channels were connected to at least one other and many of these were unfindable using traditional searches.

    “We also find that this ecosystem is deliberately engineered to be resilient against takedown efforts, frequently redirecting users through chains of intermediary channels and automated bots that collectively handle hosting, access control, monetization, and channel discovery.”

    Telegram piracy chain

    telegram piracy

    Most pirate links pointed to external hosting platforms such as TeraBox, Terashare, and GoFile. Torrents and magnet links, meanwhile, were a rarity, and the researchers only spotted nine of these links in their research.

    In addition to posting links to pirated content, some channels also shared compromised Netflix, Hulu, Disney+, and Crunchyroll logins, and VPN tutorials to help people bypass blocking measures.

    Anti-RIP: AI Powered Channel Hunting

    The researchers went beyond simply mapping the ecosystem. Their findings also motivated the development of “Anti-RIP,” a real-time AI-powered tool that can detect video piracy on Telegram.

    To catch channels before they grow, the researchers generated candidate Telegram handles and probed them to see which ones were linked to piracy communities. Between February 3 and April 10, 2026, the tool scanned 249,133 newly discovered channels.

    The Anti-RIP framework

    anti-RIP

    From that sweep, Anti-RIP flagged 802 piracy channels with a median age of less than 5 days, along with 299 connected channels and 108 bots.

    Rather than sending bare links, the team compiled the findings into evidence reports that paired each flagged channel with contextual labels describing what it was doing, from hosting and redirecting to monetizing content. These reports were sent to Telegram’s abuse department as well as 17 major U.S. rightsholders.

    The research notes that 14 of the 17 US studios acknowledged the reports, and 4 explicitly stated that the contextual labels helped them assess and prioritize the notices.

    “Over a 61-day period, the framework facilitated the takedown of 524 previously unknown piracy channels and 71 bots,” the paper reads. Additionally, Telegram removed many flagged posts.

    AI Tool Isn’t Flawless

    Anti-RIP’s reports produced measurable results. Within two weeks, 524 of the 1,101 reported channels had become inaccessible, and Telegram removed many individual flagged posts on top of that.

    The AI tool is far from perfect, and the researchers acknowledge that it produces false positives. When two coders reviewed a random sample of 1,000 posts used to validate the system, they found that the model had wrongly flagged 4 legitimate posts as piracy.

    The detection model built for the live tool is reported to be 98% accurate in testing. That figure comes from a controlled test set, however, and the paper does not publish a verified error rate for the channels that were flagged during its real-world run.

    The researchers have open-sourced Anti-RIP and released the dataset publicly through GitHub . This means that Telegram and rightsholders can put it to use, if they like. Similarly, pirates will likely use AI tools to evade detection, triggering an AI-driven game of cat-and-mouse.

    A copy of the paper, “Binge, Bot, Repeat: Unpacking the Ecosystem of Video Piracy on Telegram,” is available here . It is a preprint that hasn’t been peer-reviewed yet.

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Hollywood’s UK “Omnibus” Pirate Site Blocking Order Surfaces Through Cloudflare

      news.movim.eu / TorrentFreak • 12 August 2026 • 5 minutes

    pirate flags When the Motion Picture Association (MPA) described its new UK blocking order to WIPO in May, it was presented as a key step in the fight against online piracy.

    The “omnibus” order would make it easier and quicker to block new domain names and pirate site brands that pop up in response to blocking efforts.

    According to the MPA, it allows Hollywood studios to seek blocking of any “structurally infringing audiovisual piracy services that meet defined criteria, without having to bring a fresh court application for each new domain or site name available in the future.”

    Cited but Inaccessible

    As we reported at the time, the order itself was nowhere to be found. The judgment was not on BAILII or in the National Archives, and none of the targeted ISPs had mentioned it. The MPA’s summary was the only public account.

    The significance of the order was clear though. The MPA prominently featured it at WIPO and the UK ruling was also referenced and used as an example in a Canadian site blocking order that was handed down last month.

    Canada’s Federal Court noted that the purpose of the order is to “address increased fragmentation in the Internet piracy landscape” that is the result of people switching from blocked to non-blocked sites and domains.

    This “expanded scope” order, as Canada’s Federal Court called it, allows Hollywood studios and broadcasters to add unrelated sites to the blocklist, without having to go back to court. However, the UK order that it was based on remained unpublished, until recently.

    This week, we spotted a new transparency filing from Cloudflare, which was added to the Lumen database . This filing references the UK omnibus order and also attaches a copy of it.

    Omnibus Order Details Surface

    That attachment is, as far as we know, the first public copy of the omnibus order. It is headed a “Public Version,” a copy with a confidential schedule removed, which confirms the broad powers the MPA described as well as other details.

    The order, handed down by Mr Justice Mellor on 7 May 2026, was requested by Columbia, Disney, Netflix, Paramount, Universal and Warner Bros. The respondents are the UK’s six largest ISPs: BT, EE, Plusnet, Sky, TalkTalk and Virgin Media.

    The order (public version)

    hc order

    Like previous UK blocking orders, the ISPs are required to block access to a series of websites. In this case, the first part of schedule 1 specifically lists 345movie.nl and 456movie.nl, cineby.app, movies2watch.watch and streamm4u.com.co. These are the ‘seeds,’ followed by an open-ended category in part 2 of the same schedule.

    The ‘seed’ domains and brands

    schedule 1

    Since 2022, UK court orders also support subsequent blockades of similarly branded websites. The latest order expands this power to a much broader list of pirate sites, regardless of the brand used, as long as these are similar in functionality.

    “[E]ach Part 2 Target Website has essentially the same mode of operation as one or more of the Part 1 Target Websites in so far as it enables users to stream film/audiovisual content by indexing and aggregating links to unauthorised copies of such content,” the order reads.

    There is a clear set of boxes newly added sites have to tick, so future expansions are not unlimited. In this case, all pirate movie streaming sites that are available in the UK and unresponsive to complaints, should be fair game.

    The ‘add site’ requirements

    addedreq

    The order does not come with a transparency clause that requires the list of blocked domains to be made public, which makes it impossible for the public and journalists to review the blocking efforts.

    Voluntary Expansion

    Importantly, adding new sites to the blocklist does not involve a judge. When the studios flag a new Part 2 site, they notify the ISPs that the conditions are met, and it is added. There is no court hearing or independent review.

    The order states that the ISPs are “wholly reliant on the Applicants accurately identifying” the URLs to block, and that they “have no obligation to verify whether the Applicants’ or their agents’ determination is correct.” The studios are in charge of expanding the blockades.

    These expansions are not limited to the ISPs either. As mentioned earlier, Cloudflare published the order without being a party. This is because the American company voluntarily blocks targeted sites if these use its CDN services. These blocks are limited to the UK, as we documented before .

    Error HTTP 451

    error 451

    As shown above, Cloudflare shows an Error HTTP 451 to UK visitors that try to access movies2watch.watch, explaining that the site is unavailable for legal reasons.

    Guardrails and Limitations

    The order is not without safeguards. In addition to the earlier mentioned expansion requirements, site operators or other people caught up in these blocking efforts have the right to object.

    Importantly, rightsholders are also strictly prohibited from asking ISPs to block an IP address if the underlying server also hosts legitimate, non-infringing websites. This should prevent overblocking incidents.

    Finally, there is also a relatively short time limit on the order, which expires after six months.

    “This Order shall cease to have effect at 23:59pm on the date 6 months from the date of this Order, unless the Court orders otherwise,” it reads.

    This doesn’t mean that the blocking order will cease to exist after that. In practice, it means that the Hollywood studios will return to court to request an extension. While there is no formal blocklist review, if there are any concerns they can be brought up then as well.

    As far as we know, the judgment linked to the order has yet to be added to BAILII or the National Archives. Ironically, we only know of it because of the transparency efforts of Cloudflare, which isn’t even a formal party in the case.

    A copy of the public “omnibus” blocking order is available here (pdf) . The Cloudflare blocking notice, published at the Lumen Database, can be found here .

    From: TF , for the latest news on copyright battles, piracy and more.

    • To chevron_right

      Paris Court Kicks Off New Football Season with Multi-Intermediary Piracy Blocking Orders

      news.movim.eu / TorrentFreak • 11 August 2026 • 5 minutes

    canalplus While site blocking efforts were a novelty in France a few years ago, they have since transformed into a streamlined annual ritual.

    Ahead of each new football season, broadcaster Canal+ goes to the Paris Judicial Court, requesting site blocking orders to stop pirate streaming sites and services.

    Over several years, these blocking requests have grown from simple ISP blocks to cover DNS resolvers, CDN providers, VPN services, and search engines. Initially these orders were scattered, but a batch signed last month reveals a clear pattern.

    On July 17, Vice-President Irène Benac signed the latest batch. The fourteen orders are split evenly between the 2026/2027 Champions League and Premier League seasons. These two batches cover every type of intermediary Canal+ has pursued since 2022, all in one coordinated action.

    ISPs, DNS, CDN, VPNs, and Search Engines

    The Premier League orders target 47 domain names and the Champions League orders cover 26 domain names. This includes ones using popular brands such as Totalsportek, LiveTV, Kevinsport, as well as various IPTV gateways. An overview of all domain names is available below .

    The ISP orders will have the most direct impact. They cover France’s largest providers, including Orange, SFR, Free, and Bouygues Telecom, who all have to block access to the listed domain names. The other orders aim to cover potential bypasses.

    If subscribers try to get around these ISP blocks by switching to an alternative DNS resolver, the orders against Google DNS, Cloudflare DNS, Quad9 and DNS4EU prevent this. The latter two did not present a defense in court.

    #ddd;">
    #333;font-weight:bold;"> Category #333;font-weight:bold;"> Targeted Services #333;font-weight:bold;"> Action #333;font-weight:bold;white-space:nowrap;"> EPL (RG) #333;font-weight:bold;white-space:nowrap;"> UCL (RG)
    #ddd;font-weight:bold;"> ISPs & Telecoms #ddd;"> Orange, Free, SFR, Bouygues, plus overseas operators (SPM, Telco OI, UTS Caraïbe, Zeop, etc.) #ddd;"> Block domains/subdomains for subscribers in France. #ddd;"> 26/08401 #ddd;"> 26/08386
    #ddd;font-weight:bold;"> DNS, CDN & Proxy #ddd;"> Cloudflare #ddd;"> Block across DNS resolver, CDN, and reverse proxy. #ddd;"> 26/08356 #ddd;"> 26/08361
    #ddd;font-weight:bold;"> Public DNS #ddd;"> Google Public DNS #ddd;"> Block domain resolution for French users. #ddd;"> 26/08379 #ddd;"> 26/08380
    #ddd;font-weight:bold;"> Public DNS #ddd;"> Quad9 & Whalebone (DNS4EU) #ddd;"> Block resolution; both defaulted. #ddd;"> 26/08377 #ddd;"> 26/08378
    #ddd;font-weight:bold;"> VPN #ddd;"> Proton VPN #ddd;"> Block access via VPN; defaulted, provisional order. #ddd;"> 26/08364 #ddd;"> 26/08366
    #ddd;font-weight:bold;"> VPN #ddd;"> CyberGhost & ExpressVPN #ddd;"> Block access via VPN; contested and lost. #ddd;"> 26/08368 #ddd;"> 26/08371
    #ddd;font-weight:bold;"> Search Engines #ddd;"> Google Search & Microsoft Bing #ddd;"> De-index ( déréférencement ) targeted domains in France. #ddd;"> 26/08382 #ddd;"> 26/08383

    #ef4b92;"> Notes: All fourteen orders were issued on July 17, 2026 by the Tribunal Judiciaire de Paris (Vice-President Irène Benac). Enforcement is required within three days (five for UTS Caraïbe). Blocks run for the 2026/2027 seasons — Premier League (47 domains) until May 30, 2027, and Champions League (26 domains) until June 5, 2027 — and can be updated dynamically through ARCOM.

    The Cloudflare orders are not limited to the 1.1.1.1 DNS resolver either. The Internet infrastructure company must also block the domains across its CDN, and its reverse proxy service under the same rulings, by whatever technical means it chooses.

    The orders add search engines in the same sweep. Google and Microsoft Bing are ordered to de-index the domains, so they no longer surface in results for users in France.

    Finally, VPN services are covered as well. Canal+ secured orders against Proton, CyberGhost, and ExpressVPN, to shut down another bypass. That part of the blocking batch was also the most heavily contested, as covered below.

    All the blocks are dynamic. This means that domains can be added throughout the season once ARCOM, France’s audiovisual regulator, approves them. The Premier League measures run from August 22, 2026 to May 30, 2027, while the Champions League blocks expire on June 5, 2027.

    VPN Defense Fails

    Canal+ previously named five VPN providers in previous seasons. This round it pursued only three, dropping NordVPN and Surfshark without explanation.

    The most detailed defense came from CyberGhost and ExpressVPN. They first asked the court to pause the case pending a referral to the EU Court of Justice. This is the Anne Frank Stichting case, which was decided shortly before the Paris ruling and shielded VPNs from liability in a copyright dispute.

    The Paris court already refused to pause the case, explaining that the Anne Frank case concerns a different directive and a publication that was itself lawful, which is different from the pirate streaming sites that are at stake here.

    The VPN providers further argued that Article L. 333-10 of the Sports Code conflicts with the EU E-Commerce Directive and should be set aside. The court disagreed, stressing that this is a dispute between private companies. Since an EU directive has no “horizontal direct effect,” a national law can’t be disapplied on that basis.

    The court also spelled out why a neutral intermediary can be required to take action, as it enables the transmission of infringing content. The “mere act of serving as a bridge enabling access to the infringing sites fulfills the transmission function,” the ruling states (translated).

    The court stressed that, even though an intermediary may act passively and neutrally, it can still be an essential link in transferring infringing data.

    Google also pushed back in response to the DNS and search orders. It questioned whether Canal+ had enforceable exclusive rights in France, and argued that the Canal+ companies had not proven repeated infringements per channel for every disputed domain. The court rejected both these points.

    Up Next: Automated Real-Time Blocking

    The orders were issued on July 17 but haven’t been picked up in the press, as far as we know. With hindsight, the timing is notable, as they were handed down just four days before the French Parliament adopted a new sports law that rewrites the blocking process.

    As we reported previously , the law replaces the current manual system, where ARCOM agents verify each domain before a block, with an automated process that can add new targets in real time during a live broadcast. ARCOM’s agents keep a review role, but after the fact rather than before.

    The law has not yet been implemented; that’s expected later this year. For now, these orders still run under the old framework. However, if the new law is implemented, Canal+ and other rightsholders will likely switch as soon as they can.


    The Premier League order targets these domain names.

    1. abcsport.tel
    2. akhtv.online
    3. antenasport.org
    4. empire-sports.store
    5. kevinsport.org
    6. livetv880.me
    7. livetv882.me
    8. sports24.cc
    9. streamonsport.art
    10. totalsporteki.com
    11. witv.team
    12. xuperlive.com
    13. abcsport.top
    14. liveon5.zip
    15. zac01bp.mpipzni2naturally32kistomach.ru
    16. zac22bp.mpipzni2naturally32kistomach.ru
    17. lovetier.bz
    18. kevinsport.lat
    19. kevinsport.mom
    20. strongst.link
    21. kevinsport.best
    22. fisherman.click
    23. cdn.livetv880.me
    24. emb.apl407.me
    25. cdn.livetv882.me
    26. livetv883.me
    27. cdn.livetv883.me
    28. kiratop.site
    29. livetv884.me
    30. cdn.livetv884.me
    31. livetv885.me
    32. cdn.livetv885.me
    33. wilderness.click
    34. woundsilk.net
    35. totalsportek.wales
    36. streamlycdn.com
    37. sports-rope.top
    38. l2l2.link
    39. totalsportek.company
    40. live.totalsportek.fyi
    41. yallalive.cfd
    42. iptv-abonnement.tv
    43. ott-premium.tv
    44. iptvpremium-europe.com
    45. cf.orion-2026.xyz
    46. smartippon.com
    47. line.snssmarters.store

    The Champions League orders cover the following domain names.

    1. empire-sport.live
    2. empire-sports.store
    3. kevinsport.org
    4. kzontop.site
    5. sports24.cc
    6. sportsonline.vc
    7. streamonsport.art
    8. witv.team
    9. kevinsport.lat
    10. kevinsport.quest
    11. lovetier.bz
    12. kevinsport.homes
    13. [Address 27]
    14. wilderness.click
    15. v3.sportssonline.click
    16. 7y306yg5flk3x4.dynmaspect.net
    17. j7x31108tgeg77x.dynmaspect.net
    18. woundsilk.net
    19. swopglow.net
    20. iptv-abonnement.tv
    21. tv.business-cloud-8k.ru
    22. cf.orion-2026.xyz
    23. ott-premium.tv
    24. smartippon.com
    25. iptvpremium-europe.com
    26. line.snssmarters.store

    From: TF , for the latest news on copyright battles, piracy and more.