The U.S. Department of Justice announced Friday the seizure of nearly 400 internet domains that were illegally broadcasting live 2026 FIFA World Cup matches — the largest sports-piracy enforcement action in U.S. history, roughly five times the scale of the comparable crackdown during Qatar 2022. But the story that matters most to the millions of fans who used those free streams is not copyright law: federal investigators confirmed the seized sites were active malware delivery operations, using underground advertising networks to harvest banking credentials and infect devices without requiring a single deliberate download.
The operation, called Operation Offsides , is led by the National Intellectual Property Rights Coordination Center (IPR Center) alongside Homeland Security Investigations (HSI). A seizure warrant was filed June 26 in the U.S. District Court for the Eastern District of Virginia. Investigators confirmed the domains were actively broadcasting World Cup matches in real time without authorization at the moment of seizure.
"When you open your network to illegal streaming sites, you're taking a significant risk," HSI Special Agent in Charge Eric Weindorf of the Washington Field Office warned. "These streamers not only violate copyright laws but also expose viewers to potential threats — including malware attacks and unsecure connections that can compromise personal and financial data."
The scale of this action dwarfs the 2022 precedent. When HSI ran the original Operation Offsides during the Qatar World Cup in December 2022, it seized 78 domains . The 2026 action seized nearly 400 — approximately five times as many — reflecting a combination of expanded piracy operations and the broader jurisdictional reach the U.S. holds as a co-host nation.
The seized domains were identified with direct assistance from FIFA, with additional intelligence provided by beIN Media Group, NBCUniversal, the Motion Picture Association's Alliance for Creativity and Entertainment (ACE), UFC, and Warner Bros. Through the International Computer Hacking and Intellectual Property (ICHIP) Network of U.S. prosecutors, the operation extended beyond domain names: servers in Peru and Bulgaria — two known centers of online piracy activity — were targeted directly, with additional disruptions in Croatia, Romania, Poland, and Colombia.
Assistant Attorney General A. Tysen Duva put the enforcement in explicit host-nation terms: "This operation illustrates the Department's respect for intellectual property rights and the responsibility of the United States as a host nation to protect the FIFA World Cup from criminals."
Visitors to seized domains now see a government banner: "This website has been seized by law enforcement authorities as part of Operation Offsides, a coordinated global effort led by the National Intellectual Property Rights Coordination Center with international law enforcement and private sector partners. This action was taken to protect consumers and enforce intellectual property rights worldwide."
The DOJ confirmed that Operation Offsides remains active, with additional seizures and potential prosecutions of operators still possible as the tournament continues through July 19.
The cybersecurity research makes clear why federal agents framed their warning around malware rather than copyright. Piracy sites cannot sell advertising to legitimate ad networks — no brand will place ads alongside stolen content. So they partner with underground malvertising networks, which do not sell ad space in any conventional sense. They sell access to users.
Security research cited by Tom's Hardware from Webroot (now part of OpenText) found that 92% of the 20 illegal sports-streaming sites analyzed in 2021 carried some form of malicious content, typically delivered through those underground ad networks. A separate analysis of 50 popular free-to-view sports sites found that every single one contained links to malicious or misleading content. The business model the researchers documented is not incidental piracy contaminated by bad actors in the advertising supply chain. It is intentional: the stream is bait, and the ad network is the product.
Cybersecurity firm Malwarebytes reported in June 2026 that its researchers identified more than 40 World Cup-themed streaming sites with identical page templates, identical code, and identical advertising infrastructure. When a user visits one of these sites, a script fires immediately on the first click or tap anywhere on the page — opening a malicious ad in a new background tab. The stream itself often loads nothing; the page loops through fake "Streams loading... Retry" prompts to generate additional ad impressions while the real payload is delivered.
The infection chain documented by security researchers across multiple piracy-site investigations is almost entirely passive once a user visits the site.
Fake video player controls: Clicking what appears to be a standard play button or mute toggle triggers a redirect chain that passes the user's browser through several intermediate advertising domains before landing on a page delivering the malicious payload — without any download prompt and without requiring any credentials to be entered.
Banking trojans embedded in interface elements: Research cited by Tom's Hardware documented banking trojans hidden specifically behind fake unmute buttons on illegal sports streams. One click begins quietly harvesting banking credentials in the background, with no visible indication to the user.
Infostealer delivery via GitHub-hosted redirectors: A December 2024 campaign documented by Microsoft Threat Intelligence traced its origins directly to illegal streaming sites. Redirectors embedded in video frames funneled users through several hops to information-stealing malware — including Lumma and Doenerium — hosted on GitHub repositories. Microsoft found the campaign reached close to one million devices across both consumer and enterprise machines.
Browser hijacking: Some piracy sites quietly overwrite a browser's notification permissions on the first visit, then use those permissions to deliver scam notifications and redirect future results — indefinitely, even after the user has left the site.
Phishing overlays: Pop-ups styled to replicate Google, bank, or cable-provider login screens prompt users to "verify" their account to continue watching. Credentials entered into these overlays go directly to operators.
The risk is compounded for any user who accesses piracy streams on a device also used for banking, work email, or online shopping. Both consumer and enterprise devices were confirmed affected in the December 2024 Microsoft campaign.
The DOJ did not release an official list of seized domain names, but DNS tracking by TorrentFreak confirmed dozens of well-known piracy domains now resolve to the government seizure page. Confirmed or reported domains include kooora365.com, kora-shoot.com, bein-match-worldcup.com, beinmatchtv.com, rojadirectastv.org, pelotalibrehd.org, futbollibreusa.com, viper-play.org, and redditsoccerstreams.name. According to TorrentFreak's DNS tracking, istreameast.app — a site that reportedly drew approximately 15 million visits the month — was among the seized domains.
Domain seizures are a limited instrument against operators who run piracy networks as organized businesses. BleepingComputer reported that the week before Operation Offsides 2026, ACE, UEFA, and Mexican authorities shut down 44 domains linked to the PirloTV streaming network, which generated more than 950 million annual visits. That platform continued operating within hours on replacement domains. Piracy operators routinely maintain backup domains and mirror sites on foreign registries — particularly Russian-operated .su domains that fall outside U.S. jurisdictional reach. A site seized at .com may reappear at .su within hours of enforcement.
Investigators know this. Operation Offsides 2026 targeted server infrastructure in Peru and Bulgaria alongside the domain names specifically to disrupt the supply chain rather than just the storefronts.
Even with nearly 400 domains seized, new sites will appear before the World Cup match. Security researchers consistently flag the following signals:
A site displaying HTTP rather than HTTPS in the address bar is transmitting data unencrypted, making any information passed over that connection visible to anyone monitoring the network. Immediate pop-ups demanding that you click "Verify you are human" or "Press Allow to continue" are among the most common delivery mechanisms for browser-hijacking malware. Legitimate streaming sites do not route users through five or more redirects before showing video. Real licensed streams display the broadcaster's logo — FOX, Telemundo, beIN — inside the video player itself, not just on the surrounding page.
Any site offering "Free HD stream, no sign-up" for a live World Cup match is not legitimate: every legal live stream in the U.S. requires at minimum a free account registration. Sites that accept payment for "HD" or "premium" access are collecting card details with no intention of delivering anything of value. Links to "free streams" distributed through Discord servers, threads, or Telegram channels with no official broadcaster attribution carry particularly high risk: legitimate streams are indexed on official broadcaster websites, not crowdsourced in fan chat groups.
There are more genuinely free or near-free legal options for the 2026 World Cup than any prior tournament.
Free with no payment information required: Tubi , Fox's ad-supported streaming service, streamed the tournament's two opening matches live in 4K and carries full on-demand replays of all matches within hours of broadcast — a free account is all that is required, with no credit card. An over-the-air TV antenna — available for $25–$40 as a one-time purchase — receives all FOX network matches (70 of 104 total games) and all Telemundo matches broadcast free over the air. FIFA+ (fifa.com/fifaplus) offers select live matches and free replays in certain markets. Official broadcaster YouTube channels stream the first ten minutes of every match live, with full replays posted free after the broadcast window closes.
Paid options under $20/month: FOX One, Fox's own streaming service, carries all 104 matches in English starting at $19.99/month, with a three-day free trial. Peacock Premium carries all 104 matches in Spanish (Telemundo/Universo broadcast) at $10.99/month — and is included free with Walmart+ and Instacart+ memberships. Fubo carries both FOX and FS1 and offers a five-day free trial. YouTube TV, Hulu with Live TV, and Sling all carry FOX and FS1 with varying free trial periods.
Are illegal World Cup streaming sites dangerous even if you don't click anything?
Yes. Research on illegal sports-streaming sites shows that infection can occur pre-click through drive-by downloads — malicious code embedded in the page or its advertising assets that executes automatically when the page loads. The most dangerous documented interactions require only a single click on a fake play or mute button. Entering personal information is not required for device compromise to occur.
Can a piracy site banking trojan steal money without me noticing?
Yes. Banking trojans documented on illegal sports streams — delivered via fake unmute buttons — install silently and monitor browser sessions in the background, capturing credentials and session tokens as users log into financial accounts. Victims typically notice only when unauthorized transactions appear on their statements.
I visited an illegal World Cup streaming site. What should I do right now?
Run a full scan with up-to-date security software immediately. From a separate, clean device, change your banking, email, and primary passwords. Review recent bank and card statements for unauthorized transactions. If you clicked any pop-up or interactive element on the site — especially a play button, mute button, or "verify" prompt — treat your device as potentially compromised until scanned. In Chrome, go to Settings → Privacy and security → Site settings → Notifications, and revoke any permissions you do not recognize.
Does a VPN protect me from malware on free streaming sites?
No. A VPN masks your network-level IP address but does not prevent malicious code from executing locally on your device after you click a fake video player control. Malware delivered through a piracy site's advertising runs on your machine regardless of whether your traffic is routed through a VPN.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
