Operation Offsides: US Seizes 1,000+ Piracy Domains
US authorities have seized more than a thousand domains that illegally broadcast matches from the 2026 FIFA World Cup. Many such sites did more than infringe copyright. They could also seed visitors’ devices with malware or harvest their payment details.
The Justice Department carried out three separate seizure actions across the tournament. Nearly 400 sites fell by the end of June. Subsequently, the total surpassed one thousand.
How Investigators Built the Case
The campaign bears the name Operation Offsides. Investigators established that the sites streamed matches live and without permission, running alongside the official broadcasts. Notably, HSI special agents personally confirmed that the illicit streams were active before seeking court authority to seize the domains. Prosecutors filed the seizure warrant application in the US District Court for the Eastern District of Virginia.
Homeland Security Investigations’ Washington Field Office led the enquiry with the National Intellectual Property Rights Coordination Center. FIFA helped identify the pirate platforms. Media companies beIN Media Group, NBCUniversal, and Warner Brothers contributed further intelligence, as did the Motion Picture Association’s Alliance for Creativity and Entertainment and the Ultimate Fighting Championship. Law enforcement notices now greet anyone visiting the seized addresses.
The Security Warning
The Justice Department cautioned that operators of unlawful video services can embed malicious code in their pages. They can equally collect bank card data and siphon other confidential information. Officials reasoned bluntly: people already willing to break copyright law may just as readily plant malware. Viewers were therefore urged to watch matches only through official platforms.
Operation Red Card Sweeps the Americas
In parallel, law enforcement across North and South America mounted Operation Red Card. The Justice Department’s ICHIP programme coordinated efforts among Argentina, Brazil, Chile, Colombia, the Dominican Republic, Ecuador, Paraguay, and Peru. Officials also convened a two-day intergovernmental meeting in Bogotá on 1 and 2 July.
The blocking figures varied considerably by country. Colombia blocked 1,140 pirate sites. Brazil followed with 309, the Dominican Republic with 256, and Ecuador with 223. Peru accounted for 28 and Argentina for 14.
Arrests in Colombia
Colombian authorities additionally executed 13 nationwide search-and-seizure operations targeting counterfeit sports apparel. Those raids produced 11 arrests and convictions.
A second strand proved more technical. Phase II of Operation Red Card launched on 10 July, building on a first phase from 17 June. Simultaneous operations ran across Bogotá, Soacha, MarÃalabaja, ManatÃ, and SincerÃn. A cybercrime prosecution team mentored under ICHIP then arrested four members of the group Los Ciberinfiltrados.
According to investigators, the suspects had infiltrated telecommunications systems since 2024 and sold access to pirated broadcasts. Their methods leaned on stolen credentials and virtual private networks. Furthermore, they intercepted security codes and manipulated profiles within corporate systems.
Enforcement Continues
Europe saw parallel action too, with ICHIP Bucharest coordinating alongside Europol. American authorities have stated that they will keep hunting and seizing domains that show World Cup matches without the rights holders’ consent.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.