The U.S. Department of Justice said it seized nearly 400 internet domains that were illegally broadcasting live 2026 FIFA World Cup matches, calling the action part of Operation Offsides. The enforcement effort was led by the National Intellectual Property Rights Coordination Center with support from Homeland Security Investigations, international partners, and private-sector rights holders including FIFA and media organizations. According to the DOJ, the domains were providing unauthorized real-time streams in violation of U.S. copyright law, and the seizures were backed by an affidavit filed in the Eastern District of Virginia.
Authorities said the operation also targeted infrastructure tied to servers in Peru and Bulgaria, with coordinated disruptions in Croatia, Romania, Poland, and Colombia, reflecting a broad international crackdown. U.S. officials warned that illegal sports-streaming sites are not only piracy hubs but also a cybersecurity risk, exposing visitors to malware, insecure connections, and theft of personal or financial data; reporting cited prior threat intelligence linking such platforms to malicious advertising campaigns that delivered information stealers including Lumma and Doenerium. The Justice Department said the operation remains active as investigators continue pursuing the operators behind the seized domains.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
On June 26, 2026, the U.S. Department of Justice announced the seizure of nearly 400 internet domains used to illegally stream 2026 FIFA World Cup matches as part of Operation Offsides. The action was supported by Homeland Security Investigations, international partners, and private-sector rights holders, with related targeting and disruptions in Peru, Bulgaria, Croatia, Romania, Poland, and Colombia.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcetomshardware.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.