A viewer opens a browser, types the address of a streaming site they have leaned on all tournament and waits for the match to load. The page resolves, yet the game is gone, replaced by a flat banner announcing that the name now belongs to law enforcement. Nothing in that moment tells the viewer whether agents walked into a data center and carried out disks, cancelled a hosting account, withdrew a route or simply rewrote the records that decide where the name should lead. That ambiguity is the entire story.
On 20 July 2026 the United States Department of Justice announced that more than 1,000 domains used to stream 2026 FIFA World Cup matches without authorization had been taken across three enforcement waves, the largest sports piracy action the country has ever run. The first publicly announced wave, filed on 26 June in the Eastern District of Virginia, covered close to 400 names. Set against the comparable Qatar 2022 effort, which reached 78 domains, the 2026 campaign lands as a thirteenfold escalation.
The number travelled further than the mechanism, which is the reverse of how it deserves to be read. A domain is not a server. Naming is not routing. Blocking is not seizure. Redirecting a name is a wholly separate act from removing the content sitting behind it. Operation Offsides is a clean study in how these strata rest on top of one another, why the naming system is such a productive place to intervene and where that leverage quietly runs out.
Authorities rarely need to seize a server. They can climb one level higher, to the name people use to reach it.
The seizure that did not seize the servers
Homeland Security Investigations, working through its Washington Field Office and the National Intellectual Property Rights Coordination Center, built the tally over three enforcement rounds during the tournament, with warrants supported by affidavits filed in the Eastern District of Virginia. FIFA helped flag the offending names, while rights holders including beIN Media Group, NBCUniversal, the Motion Picture Association coalition, UFC and Warner Bros supplied corroborating detail. Investigators said agents confirmed the domains were carrying live unauthorized broadcasts. Officials added a consumer angle that rarely accompanies a copyright case, warning that many of the pirate sites pushed banking trojans through fake play buttons.
The verb doing the heavy lifting in every account is seized, which hides more than it reveals. Seizing a thousand names is not the same as seizing a thousand machines. One streaming operation can register dozens of domains. Several domains can front a single box. A single domain can stand in for many services layered behind it. The Department itself slides between "domains," "sites" and "websites" in the same release, though those words carry different technical weight even when the press treats them as synonyms.
The precise claim
The United States seized control of more than 1,000 domain names. It did not announce the confiscation of a thousand servers, the withdrawal of a thousand routes or the permanent destruction of a thousand services. One seized name equals one seized name. Nothing automatically follows about the hardware behind it.
To see what changed hands, it helps to walk a single request from the name a person types to the machine that finally answers.
The strata between a name and a machine
Reaching a stream is a relay across half a dozen independent handoffs, each owned by a different party and each breakable on its own terms. Naming and routing sit at opposite ends of that relay and answer opposite questions. The Domain Name System resolves which address a client is trying to reach. The Border Gateway Protocol, running between the autonomous systems that make up the internet, works out which path the packets take to get to that address once it is known.
A seizure at the naming end can erase or rewrite the answer to the first question while leaving the second untouched. The original address block stays globally routed. The host stays powered. The streaming software stays installed and configured. Ordinary users simply stop arriving, because the coordinate they used to find the place has been pointed somewhere else.
The tidy slogan going around is that DNS "routes" traffic, a claim wrong in a way that hides the whole point. Naming supplies the addressing information a client needs before any routed connection begins. It hands over a destination, then steps aside while the routing layer does the moving.
What a domain seizure actually does
Behind a single name sits a chain of custodians. A registrant holds the right to use the domain. A registrar sells and manages that registration. A registry operator keeps the authoritative database and zone for a whole top-level domain. An authoritative DNS operator publishes the name's live answers, a recursive resolver fetches those answers for users and a hosting or CDN provider serves the content itself. A court order takes effect by reaching one of these custodians and compelling a change.
ICANN's own guidance for takedowns points at three things an order tends to touch, the registration record, the DNS configuration and the registration-data service that exposes ownership. Depending on which party falls under the court's reach, a registrar or registry can be told to lock the name against transfer, hand control to a law-enforcement account, swap the authoritative nameservers, point the domain at servers that answer with a government-run address, apply a hold status so the name drops out of the zone and stops resolving entirely or preserve the ownership records for the case to come.
The published banner is the tell. A user reached the seized name, the naming layer sent the browser to infrastructure serving a takeover notice and that controlled page answered. Redirecting a name toward a machine you control has an established term in security work, sinkholing, the same maneuver used to point botnet command channels at a research server, here aimed at a copyright notice instead.
Technical seam · the certificate does not come with the name
Redirection exposes a gap. The server now answering for the seized domain does not hold the private key tied to that domain's TLS certificate, so a browser arriving over HTTPS should throw a certificate warning before any banner renders. Where it does not, the notice is served over plain unencrypted HTTP instead. Taking the name does not hand over the cryptographic identity bound to it, which is why a seizure page so often looks slightly broken before it looks official.
What the public releases withhold is as instructive as what they confirm. They do not say, domain by domain, which registrar or registry executed each change, whether a given name was transferred or held or merely redirected, which nameservers were substituted, whether any hosting accounts were terminated, whether the original routes stayed live or whether any United States server was imaged or physically hauled away. The supporting affidavit may hold those answers. It was not attached to the release and did not surface in indexed public records during this research pass.
Five acts, not one
Careful separation of the mechanisms is where this subject either holds together or collapses into slogans. Each act lives at a different level, changes a different thing, reaches a different set of users and invites a different escape. The one property they share is that none of them, on its own, requires the underlying server to stop running.
| Mechanism | Level | What changes | Reach | Server stops? | Common escape |
|---|---|---|---|---|---|
| Domain seizure / transfer | registration + auth DNS | control of the name and its delegation | potentially global | no | new name, alternate TLD |
| Suspension / serverHold | registry + parent zone | name removed from the zone, stops resolving | global for that name | no | new name |
| Recursive DNS blocking | resolver / ISP | selected resolvers refuse or redirect | local to those users | no | other resolver, encrypted DNS, VPN |
| IP blocking | ISP / firewall | traffic to an address is filtered | network specific | no | new address, proxy, CDN |
| Null route | routing / filtering | traffic to a prefix is discarded | where applied | no | new address or path |
| BGP withdrawal | interdomain routing | prefix no longer advertised | potentially broad | no | new prefix or upstream |
| Hosting suspension | provider / account | provider stops serving the workload | service specific | at host | move to another host |
| Physical seizure | hardware | machine confiscated or unplugged | that machine | yes | restore from replicas |
| Application shutdown | software | service or account disabled | service specific | no | redeploy elsewhere |
The distinction that trips people up
A VPN or an alternate resolver defeats local resolver-level blocking, yet it does nothing for a name whose authoritative delegation has been globally rewritten by the registrar or registry. In that case every resolver, encrypted or not, fetches the same altered answer from the same authority. Encrypted DNS over HTTPS or TLS hides the lookup from an internet provider and slips past filtering. The query still arrives at an authoritative source that now returns the seizure address to everyone who asks.
Holding these apart keeps the reader from importing anti-censorship advice about resolver blocking into a story that is really about a registry-level takeover, where that advice does not apply.
Why the name is such a productive chokepoint
A domain earns its power by concentrating value that has nothing to do with storage. User memory and habit collect around it. So do search ranking, inbound links, social references, brand recognition, saved bookmarks, certificate identity, API endpoints, email addresses, advertising relationships and payment integrations. Removing the name erases none of the underlying bits and breaks the public coordinate the whole service is organized around.
Against live sports the leverage sharpens, because the product spoils fast. A replacement domain launched after the final whistle recovers none of the audience or advertising revenue lost during the ninety minutes that counted. Enforcement never has to make the service permanently impossible. It only has to manufacture enough delay and confusion at the exact hour demand peaks.
Timing cuts both ways · the TTL lag
A seizure is not instantaneous. Recursive resolvers cache the previous answer for the lifetime set on the record, so a user whose resolver still holds a valid cached address keeps reaching the original server until that timer runs down. For content measured in ninety-minute windows, a long cache lifetime can blunt the takeover at precisely the moment it was meant to bite, which is one reason operators tune those timers with care.
Powerful but incomplete
The infrastructure underneath is stubborn, so a seizure disrupts far more easily than it eradicates. Independent reporting during the tournament traced operators jumping from taken names to pre-positioned fallbacks within hours. TorrentFreak documented several brands switching to Iranian .ir domains, a country-code registry deliberately chosen for sitting well outside easy United States reach, with variants of the buffstreams brand turning up among the seized names as fast as they were cut.
The lesson underneath the whack-a-mole is that domain identity and server identity are separable, the same backend re-emerges under a fresh label, fallbacks can be stockpiled years ahead and jurisdiction over a generic top-level domain does not translate into practical control over every national registry. A takedown becomes a repeated contest across discovery, registration, hosting, money and user migration rather than a single decisive blow.
The tempting shortcut, "just use the raw IP address," fails more often than it works. Several sites can share one address. The server may demand a specific host header. TLS uses the requested hostname to pick a certificate and a virtual host. The origin may hide behind a CDN, direct access to it may be firewalled, application code may bounce the visitor back to the canonical name and cookies, tokens and APIs may all be bound to the hostname. The machine can still exist without ordinary users being able to reach it easily or safely once the name is gone.
Not one mechanism, a layered campaign
Read as a whole, Operation Offsides was never a single lever. The United States component seized more than 1,000 domains across three actions, opened with close to 400 names, filed its warrants in Virginia and dressed the taken names in a coordinated banner. Running alongside it, an international effort the Department called Operation Red Card leaned on partner governments to block access inside their own borders. The geographic spread reads better as data than as prose.
The June announcement also described servers and domains targeted in Peru and Bulgaria, with further disruption across Croatia, Romania, Poland and Colombia. A second Colombian phase reached into the physical world, with search-and-seizure operations against counterfeit sports apparel, arrests and convictions in those apparel cases and four alleged members of a group calling itself Los Ciberinfiltrados detained, accused of unauthorized telecom access, fraudulent credentials, VPN abuse, intercepted security codes and doctored corporate profiles.
Domain seizure alone creates friction. Domain seizure joined to server action, arrests and payment disruption raises the cost of coming back.
The escalation gives the 2026 numbers their weight. Where the 2022 tournament saw 78 names taken, this campaign reached more than a thousand, a jump that only reads clearly when the sports-piracy count sits beside its own recent baseline.
The legal frame: property, probable cause and forfeiture
What the current case confirms is narrow and solid. An affidavit supported a seizure warrant, the filing sat in the Eastern District of Virginia, agents attested that the domains were carrying live unauthorized streams and the names were treated as instrumentalities that facilitated a crime rather than as protected speech. The Department's July release does not name the statute, which is the honest limit of what can be said without the warrant in hand.
The general framework these actions usually draw on is well established. Federal Rule of Criminal Procedure 41 authorizes warrants for property used or intended for use in a crime. Section 2323 of Title 18 provides for forfeiture of property that facilitates specified intellectual-property offenses. Sections 506 of Title 17 and 2319 of Title 18 reach criminal copyright infringement. Section 2319C, the illicit digital transmission services provision, targets commercial services built mainly to deliver unauthorized public performances by digital transmission. Presenting these as the standing legal backdrop is fair. Asserting that any single one of them charged every seized name is not, unless the affidavit says so.
Why a name can be taken before anyone is arrested
Domain seizure is often built around the property itself rather than the person. The government argues the name was used to facilitate an offense and is therefore subject to seizure or forfeiture, an in rem logic that lets a domain be taken ahead of any arrest or conviction, subject to the warrant, the forfeiture procedure, notice and later chances to contest. It is the same structure that has driven United States domain seizures since the Operation In Our Sites actions began in 2010.
The jurisdictional chokepoint
An operator, a server, an audience, a registrar, a registry, a DNS provider, a CDN and a payment processor can each sit in a different country. Enforcement therefore hunts for the level over which a court can exercise real authority. A government may have no way into a foreign data center and still be able to compel a registry on its own soil, a registrar answerable to its courts, a domestic DNS or CDN provider, a payment or advertising company, an app store or a search engine.
Why a Virginia warrant reaches a .com used anywhere
The reason a warrant signed in Virginia can lift a .com used from any corner of the world is that the authoritative registry for .com and .net, Verisign, is an American company. The operator of .org sits under United States jurisdiction as well. The generic zones that hold most of the commercial web are administered inside American reach, so an order served on the registry propagates worldwide without a foreign court ever being asked. The Department's own language nods at this, describing warrants filed in Virginia as carrying authority over registrars and registries incorporated there.
Country-code domains break that reach, which is the whole point of the escape to .ir. National registries run under their own arrangements and do not necessarily use ICANN-accredited registrars, so cooperation turns sharply jurisdiction-dependent. Operators moving to an Iranian suffix were choosing a naming authority unlikely to answer American legal process, buying themselves a name that resists the one lever that worked best against the rest. None of this says a particular registry was compelled here. The seized list spans many top-level domains, so the route to each may well have differed.
The hidden cost: overbreadth and collateral damage
Naming-layer power cuts wide by design, which is exactly what makes it risky. ICANN has warned for years that seizures aimed at one target can swallow everything attached to a shared name. In the Mooo.com case, action against a single second-level domain disrupted more than 84,000 subdomains, most unrelated to the alleged offense, with visitors reportedly redirected to a notice tying the sites to child-abuse material. In the Jotform.com case, a suspension tied to one account under investigation cut off a community ICANN put above 100,000 users, including third parties who depended on forms hosted there.
A domain-level action reaches past a website. It can take down email delivery, authentication and password-reset links, APIs, software updates, webhooks, nameserver dependencies, file transfer, monitoring and any third-party service embedded through that name. The blast radius is the feature and the hazard at once.
The lesson is not that domain seizures are illegitimate. It is that a lever this wide demands precision, because it moves everything tied to the name at once.
What the operation reveals about centralization
The internet gets called decentralized because traffic can cross many networks and a service can move between hosts. Practical access tells a different story, running through a short list of concentrated intermediaries, the registries, registrars, DNS providers, certificate authorities, CDNs, cloud platforms, payment processors, search engines, app stores and identity providers that almost everyone routes through. A system can be distributed at the packet level and tightly centralized at the levels of discovery, identity, trust and money.
The internet has no single kill switch. It has many small switches, each owned by a different institution.
For anyone doing infrastructure analysis, the takeaway is that a service cannot be understood from one dataset. BGP tells you who originates the address space. DNS tells you which names point toward it. Registration data tells you who controls or sponsors the names and the addresses. Certificate transparency logs expose the hostname relationships. Hosting and CDN data name the intermediaries, application observation shows what is actually delivered and legal jurisdiction decides which of those parties can be compelled. Operation Offsides is a strong argument for why routing intelligence only means something when it is fused with naming, registration, hosting and jurisdictional context.
What this means for operators and businesses
For network and security teams. Do not diagnose every unreachable domain as a routing failure. Check registry status, authoritative nameservers, DNSSEC validity and resolver behavior before anyone opens a BGP looking glass. Separate a global authoritative change from resolver-specific blocking early, because the two demand completely different responses. Preserve passive DNS and certificate-transparency history during incident response, since the pre-change record is the evidence. Treat a sudden nameserver swap or a changed registry status code as a control-plane event, not a cosmetic one.
For companies. Carry a domain as critical infrastructure rather than a branding asset, with registrar locks, multi-factor authentication, role separation and monitored change control around it. Keep a documented recovery procedure for an unauthorized registrar or DNS change. Know the legal jurisdiction of the registrar, registry, DNS provider, CDN and host. Monitor certificate issuance and delegation changes as a standing signal, not an occasional audit.
For policymakers. Specify the exact technical action an order requires, keeping seizure, transfer, suspension and resolver blocking as distinct instructions. Assess third-party and subdomain dependencies before execution, provide transparent notice and build a correction path for the inevitable false positive. Measure real effectiveness rather than reporting a count of names. Resist treating the number of domains seized as the number of criminal groups dismantled.
Return to the viewer and the banner. What looked like a website switched off was, underneath, a name transferred or redirected, a set of resolvers taught a new answer, packets following a perfectly valid route to a different server and a takeover page dropped in where the stream had been. The experience read as one switch. The infrastructure held several. Operation Offsides did not prove that governments can switch off the internet. It proved something quieter. They often do not need to, because for the overwhelming majority of users the name is where the route begins, so whoever controls the name controls where almost everyone looks first.
What is confirmed and what is not
Reporting on an operation this size rewards keeping the established facts cleanly apart from the plausible inferences. The record supports the first column. The second is where careful writing earns its keep.
| Claim | Publicly established? |
|---|---|
| More than 1,000 domains seized over three United States actions | Yes |
| Close to 400 in the first announced wave | Yes |
| Warrant affidavits filed in the Eastern District of Virginia | Yes |
| Seized names displayed a coordinated takeover banner | Yes |
| The 2022 Qatar operation reached 78 domains | Yes |
| Operators moved to Iranian .ir fallback domains | Yes |
| Every underlying server was confiscated | No |
| Every IP route was withdrawn or null-routed | No |
| All names used the same registrar or registry | No |
| The full official domain list was published | Not located |
| The exact statute and technical instruction per name | Not in release |
| The operation permanently eliminated the services | No evidence |
Sources
U.S. Department of Justice, "United States Seizes More than 1,000 Internet Domains Used to Illegally Stream World Cup 2026 Matches," 20 July 2026, plus a companion release "United States Seizes Hundreds of Internet Domains," 26 June 2026. TorrentFreak, "FIFA World Cup Triggers a Global Anti-Piracy Crackdown," July 2026, on .ir fallback domains. BleepingComputer coverage of the cumulative seizure, July 2026. ICANN guidance on domain-name orders and seizures, the SSAC "DNS Blocking Revisited" advisory and the collateral-damage cases of Mooo.com and Jotform.com. IETF RFC 1034 (DNS) and RFC 4271 (BGP-4); 18 U.S.C. §§ 2323, 2319, 2319C; 17 U.S.C. § 506; Fed. R. Crim. P. 41.
Verification notes. The Operation Red Card country figures are confirmed against DOJ and independent reporting and are foreign blocking actions, distinct from the United States domain seizures. The 78-domain Qatar 2022 baseline is confirmed, giving the 13× figure. The .ir migration is confirmed. The specific claim that a named replacement pointed to the identical server was not independently established and is framed here as reporting rather than fact. No active illicit-streaming links are reproduced.