DCA Reports High Incidence of Credit Card Fraud on Pirate Sites

Digital Citizens Alliance (DCA) released a new report yesterday with the eye-popping statistic that 72% of Americans who subscribe to pirate media sites experience incidences of credit card fraud compared to 18% prevalence of credit card fraud among those who do not subscribe to pirate sites. These data are based on a survey of 2,030 Americans, of which 1 in 3 reported watching some pirated content in the last year, and 1 in 10 reported subscribing to a pirate streaming service. The report titled Giving Pirate Site Operators Credit states …

… piracy was once primarily a headache for content creators, users of these sites now face significant risks. Piracy subscription services make an estimated $1 billion a year providing services to at least nine million U.S. households.

DCA’s findings indicate that around 6.5 million Americans who choose to access movies, TV shows, and games in this black market, have been targeted for credit card fraud as a direct result of their subscriptions. And although I say the stat is “eye-popping,” given the environment we’re talking about, perhaps the real surprise is that the rate of unauthorized credit card charges in this network isn’t closer to 100%. After all, it’s one thing when hackers steal credit card data from legit retailers et al., but subscribing to a pirate site is cutting out the middleman and giving credit card info directly to a network of hackers.

The shift to high-quality streaming a little over ten years ago created an opportunity for pirates to launch new platforms offering low-price subscriptions to “everything” because, of course, none of the material they’re streaming is legally obtained but is stored on pirate servers around the world. Just as other DCA reports have shown that among the hidden costs of this all-you-can-eat offer is a high probability of infection with life-altering malware, the likelihood of unauthorized charges to a credit card is apparently even greater. “Combined with our previous research highlighting the risks associated with free piracy apps and services, the situation becomes even clearer. The pursuit of pirated content is an inherently risky behavior that threatens the devices, wallets, and privacy of consumers,” says DCA executive director Tom Galvin in a press release accompanying the new study.

DCA Research Subscriptions Trigger Fraud Within Eleven Days

Prior to conducting its survey of American consumers, DCA researchers subscribed to 20 pirate sites using a new credit card obtained for the experiment. In less than two weeks, the fraudulent charges began to appear from China, Singapore, Hong Kong, and Lithuania, and within three-months, DCA’s card was targeted with $1,495 in executed and attempted unauthorized transactions. The largest attempted transaction was $850, which was stopped by fraud protection, and the largest approved charge was $244.78. Given the implied cost to credit card services to provide protection against such transactions, DCA’s first recommended remedy—that the payment processors terminate relationships with known pirate sites—seems like a no-brainer.

DCA also recommends that the Federal Trade Commission “take piracy more seriously” and prioritize warning Americans about the risks associated with pirate sites; it recommends more consumer protection group outreach on this issue; and it recommends that law enforcement more aggressively investigate pirate site operators, now armed with the 2020 amendment to the U.S. Copyright Act which elevated large-scale piracy by means of streaming from a misdemeanor to a felony. “Given that the piracy ecosystem is now a $2 billion industry, the Department of Justice should use that authority to target piracy operators,” the report states.

Personally, I would be curious to know something about the thinking of 9 million Americans who want cheap media streaming so badly that they’re willing to tolerate the high risk of credit card fraud and/or a dangerous malware attack. Of course, to DCA’s point, perhaps the majority of these subscribers don’t know how risky accessing these sites can be.


Photo source by: Wichayada57844

Pirate Sites Calling Themselves Libraries are Pirate Sites

I know I’m arriving late to this party. It’s almost Thanksgiving, but it was back on November 3 that two Russian nationals—Anton Napolsky and Valeriia Ermakov—were arrested in Argentina at the request of the United States on charges of criminal copyright infringement, wire fraud, and money laundering. Concurrent with the arrests, authorities seized 241 domains controlled by the book piracy enterprise the pair allegedly operated called Z-Library. According to TorrentFreak, the repository has migrated, at least in some form, to the dark web.

The indictment against Napolsky and Ermakov was unsealed in a Brooklyn, NY court on November 16, and while they await likely extradition to the U.S., author and publisher organizations and other creators’ rights advocates applaud the efforts of the law-enforcement agencies involved with the investigation. My friend Neil Turkewitz notes, “I have been operating in the copyright world for nearly four decades, and I could probably count on one hand the number of times that a piracy story focused on individual creators rather than the much maligned ‘Big Media.’”

True. Not that “Big Media” piracy is justified, but it is substantially harder to fool oneself that book piracy does not directly harm individual authors, who generally make less than a living wage for their writing. In a statement released by the Authors Guild (AG) praising the interdiction of Z-Library, CEO Mary Rasenberger states, “We owe a tremendous debt of gratitude to the U.S. Attorney’s Office for the Eastern District of New York and to the FBI for all of their hard work in not only shutting down the site but also finding and apprehending the perpetrators. We also thank the U.K. Publishers Association and international authorities who assisted in the investigation, as well as the authors who assisted us by filing statements reporting piracy of their books on Z-Library.”

I will decline to wade again into the morass of rationalizations for piracy that predictably erupted on social media when Z-Library was taken offline. That story never changes. Though, perhaps the rhetoric of the pirates themselves changes—at least a little. “There is a growing — and disturbing — trend of pirate operations masquerading as libraries to manipulate and evade the law,” states Lui Simpson, Senior VP, Global Policy for the Association of American Publishers (AAP). “This action [against Z-Library] sends a clear message that industrial scale infringement will not be tolerated, no matter what the perpetrators call themselves.”

Maybe “library” is the new “sharing service”? Simpson is right, of course, that it doesn’t matter. A pirate operation by any name will still smell like a criminal enterprise, and in case you’re curious about when copyright infringement may be deemed “criminal,” the basics are as follows:  The infringement must be willful and for purposes of commercial or private financial gain; or the works infringed must have a retail value of $1,000 in any 180-day period. That’s not a very high bar, though criminal copyright indictments are typically brought against large-scale, blatant operations like Z-Library, whose estimated 8 to 11-million books it made available obviously exceeds $1,000 by orders of magnitude.

Further, traditional online piracy models demonstrate that the infringer does not have to profit directly from trade in the infringed works themselves. One can copy and distribute works without license and either cross the $1000 threshold (easily), or one can commercialize the traffic generated by “giving away” unlicensed works, which creates a nexus between the infringing activity and commercial/financial gain for the infringer. Historically, the pirate sites made most of their revenue from the online advertising system, but when some of those avenues were closed off by the legit ad industry, the site operators pivoted to various all-you-can-eat subscription models and malware as sources of revenue.

Of course, one does not need to operate a Russian pirate network to engage in illegal copying and distribution of books while telling the public the enterprise is a “library.” Internet Archive calls part of its operation an “Open Library,” even though it does not meet the definition of a “library” under the statute and, more importantly, despite the fact that it does not license in-copyright eBooks but instead produces unauthorized eBooks and makes them available without permission. And it does this under a model that is legally unfounded and operationally so murky as to make anyone wonder exactly how the money flows throughout the organization.

From the author’s perspective, the potential harm caused by IA’s “Open Library” is hardly distinguishable from the harm caused by a Z-Library. So, while IA may not be engaged in criminal copyright infringement, its broad-based efforts to undermine copyright are perhaps even worse. An enterprise like Z-Library will cause harm until it is shut down. What Internet Archive and its friends want to do is to strip copyright rights from authors forever. And I would call that criminal in the colloquial sense, if not in the legal one.

DCA Releases New Report on Piracy Sites and Malware

Apropos my recent response to the EFF’s standard policy of shrugging at online piracy, I want to highlight one paragraph from the post to which I replied. Katherine Trendacosta wrote:

From the fever-pitch moral panic of the early 2000s, discussions about “piracy” disappeared from pop culture for about a decade. It’s come back, both from the side explaining why and the side that wants everyone punished.

Aside from the statement being inaccurate—discussions about piracy have persisted (often quite heatedly) every year since the Napster days—I cite the quote here because its sarcasm derives from that common fallacy which asserts that Piracy is a victimless crime. No it is not.

If one wants to cling to the rationale that because certain artists are wealthy, piracy is therefore harmless to creators, fine. Whatever. But the fact that EFF and other “digital rights” groups so consistently echo the alleged “harmlessness” of piracy suggests that they’re not terribly concerned about the broader security threats posed by this $2billion/year, global, criminal enterprise.

In a new report published yesterday, Digital Citizens Alliance tells us that the 500 pirate sites studied in its latest research—there are thousands of pirate sites—earn at least $121 million per year just by hosting “malvertising” (i.e., ads designed to deliver malware). Entitled, Unholy Triangle, the report was produced in collaboration with brand safety organization White Bullet and cyber security firm Unit 221B. It describes a symbiotic relationship between malvertisers and pirate sites—two sides of the triangle—and the various ways these parties profit by endangering visitors to pirate platforms—the third side of the triangle.

Highlights from the Report

Researchers found that among the sites studied, 8 in 10 were littered with ads specifically created to entice clicks that will instantly download malware to a device or network. One out of every six visits to pirate sites, the report says, will encounter an attempted malware attack. The most popular type of bug is ransomware, but the researchers also found trojan horses and other malware used to obtain personal or financial information and/or to take control of devices. Of that $121 million annual revenue the pirate sites acquire from serving malvertising, the report states that more than half ($68.3 million) came from U.S. visits.

Among the most compelling, albeit ironic, details revealed by the report is that the majority of ads used to trigger responses are based on fear—specifically, fear of malware! It seems that because many pirate site visitors know they are exploring illegal and sketchy platforms, they are more susceptible to pop-up and pop-under ads warning them that their devices may be infected, or that they should make changes to their devices to ensure their security or anonymity.

A visitor clicks that ad offering to protect her device, immediately downloads malware, and within minutes,[1] her files are locked up, and she will soon receive a ransom demand promising to release those files for $800 to $1,000—in crypto, of course. Even people who pay these ransom demands report that, at best, they get about 65% of their data back, and there is no reason to assume that the hacker(s), who this report indicates are mostly located in Russia, will restore any data once they’re paid.

Ad Intermediaries Facilitate Sketchy Ads

DCA notes the success of initiatives like the Trustworthy Accountability Group (TAG), which launched in 2015 to extricate the legitimate advertising industry from the piracy business. But, the report describes certain advertising intermediaries that seem to straddle the legal and illegal trade. For instance, researchers focused on intermediary RichAds, which the report describes as follows:

RichAds is an advertising company that touts its ability to capture new quality leads from premium sources through its productive ads. The company is listed as being based in Cyprus, with many of its employees listing Belarusian universities as their alma maters on LinkedIn. It promises to deliver the best traffic and claims, on its LinkedIn page, that “We block any bot or other fraudulent traffic.”

Researchers sent the ad shown here for approval and received a “no problem” message from RichAds. This was hardly surprising because, looking a bit further, it appears that this intermediary is not just turning a blind eye to malware campaigns but is promoting its services to facilitate malvertising on pirate sites. “In the case study [used to promote itself], RichAds highlights how the customer relied upon the company to generate and place ads that ‘warned’ users that a virus was detected on their devices and they needed to update their antivirus software,” the report states.

National Security Implications

With operators in countries like Russia and Belarus—and with more than half the malvertising revenue (measured in this report) being generated by American visits to pirate sites—questions about national security come to mind. No, I am not saying that some teenager in Indiana illegally streams Stranger Things, and the power grid shuts down—and neither is DCA. But with more telecommuting and connections between critical enterprise databases to personal networks, the vulnerabilities to the former have increased, and enterprises are big fish for ransomware hackers.

Whether there is any crossover between the private malvertising industry and state-directed hacking aimed at the U.S. is a matter of speculation, but as the DCA report puts it:

Russia, China, Iran, and North Korea make up half of [all ransomware attacks]. As their primary target is the United States, it’s a safe assumption that the motivations go beyond financial to geo-political with national security implications. Those concerns have some states reconsidering the protocols for dealing with an attack on government operations.

Hardly Victimless

Clearly, even if one does not give a RAT’s butt about creators’ works being illegally distributed, piracy is not a victimless crime. On the contrary, a substantial and growing revenue stream for the pirate site operators is, in fact, a trade in victims. Whether it’s slaving personal computers, identity theft, or delivering ransomware to a pharmaceutical company, malware is big business, and piracy sites continue to be an excellent super-spreader.

After about ten years of reading DCA’s reports, this recent one comes closest to at least implying that media piracy can be a vector for malware attacks on something larger than personal computers. Assuming that’s not an exaggeration, the “digital rights” groups may need to drop the false narrative that mitigating piracy comes at the cost of online “freedom.” Site blocking, technical measures, and other means to interdict the piracy trade become very different conversations, if we are indeed talking about critical supply chains and not just “Hollywood.”


[1] The report cites Paul Watters, who “found it typically takes just 42 seconds for an “advanced persistent threat” such as malware to infect a Windows device and 78 seconds to infect an Android device.”