A coordinated anti-piracy operation seized 44 domains tied to the PirloTV sports streaming network, disrupting one of the most heavily used sources of unauthorized live match streams in Latin America. The action was carried out by the Alliance for Creativity and Entertainment, UEFA, UC3, and Mexican authorities including the Mexican Institute of Industrial Property (IMPI). PirloTV does not typically host content directly; instead, it aggregates and embeds illicit streams, a model that helped the network draw more than 950 million annual visits worldwide, including roughly 230 million from Mexico, with additional heavy use in Colombia, Spain, and the United States.
The takedown was timed ahead of the UEFA Champions League final and comes during the FIFA World Cup, when PirloTV has reportedly been widely used for mobile viewing of matches. Investigators said some linked domains were still indexed by search engines and a number remained accessible, continuing to offer streams from broadcasters such as ESPN, Fox Sports, and TNT Sports, underscoring the network's ability to quickly migrate to new domains after enforcement actions. ACE said the operation marked its first collaboration with IMPI under a new anti-piracy memorandum of understanding.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
A coordinated anti-piracy operation disrupted 44 domains associated with the PirloTV illegal sports streaming network. The action was carried out by ACE with UEFA, UC3, and Mexican authorities, including IMPI, ahead of the UEFA Champions League final.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcebleepingcomputer.com
Open sourcealliance4creativity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.