U.S. authorities seized more than 1,000 domains allegedly used to illegally stream World Cup 2026 matches in an enforcement campaign known as Operation Offsides, led by Homeland Security Investigations and the National Intellectual Property Rights Coordination Center. The Justice Department said earlier actions in June had already targeted nearly 400 domains and related infrastructure tied to Bulgaria and Peru, while partner agencies in Latin America and Europe blocked thousands of additional piracy sites during the broader crackdown.
The international investigation also led to the arrest in Colombia of four suspected members of Los Ciberinfiltrados, a group accused of illegally accessing telecommunications systems since 2024 and selling pirated streaming services using fraudulent credentials, VPNs, intercepted security codes, and manipulated corporate profiles. Colombian authorities also carried out search-and-seizure operations tied to counterfeit sports apparel, resulting in 11 arrests and convictions, while U.S. officials warned that illicit streaming platforms can expose users to malware, scams, and payment or data theft.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Colombian authorities also carried out search-and-seizure operations tied to counterfeit sports apparel, resulting in 11 arrests and convictions.
Colombian authorities arrested four suspected members of Los Ciberinfiltrados in connection with the broader investigation into illegal access to telecom systems and pirated streaming sales.
Partner agencies across Latin America and Europe blocked thousands of additional piracy sites as part of the same international enforcement operation targeting illegal World Cup streams.
The U.S. Department of Justice announced that authorities seized more than 1,000 domains allegedly used to illegally stream World Cup 2026 matches during the tournament under Operation Offsides.
U.S. and Colombian authorities said the group Los Ciberinfiltrados had been illegally accessing telecommunication systems and selling pirated streaming content since 2024, using methods such as fraudulent credentials, VPNs, intercepted security codes, and manipulated corporate profiles.
Earlier enforcement actions in June targeted nearly 400 domains and related infrastructure tied to Bulgaria and Peru as part of the broader anti-piracy campaign around World Cup streaming.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
5 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcebleepingcomputer.com
Open sourcesecurityonline.info
Open sourcejustice.gov
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.