Almost every large piracy site runs on advertising. The content is free; the page is the product. Its ad slots are auctioned in milliseconds through the same open exchanges that place ads for banks, streaming services, and car brands, and every visitor the stolen content attracts turns into billable impressions.

That revenue moves through a chain of identifiable intermediaries, supply-side platforms, exchanges, resellers, and every link in that chain has a complaint channel you can use. This article walks through how the money actually flows, which industry programs police it, exactly what a report to an ad network needs to contain, and why the leak keeps leaking anyway.

How Ad-Supported Piracy Gets Paid

The mechanics are ordinary programmatic advertising. A pirate site embeds ad tags, small scripts supplied by ad networks and supply-side platforms, in its pages. Each visit triggers a real-time auction. Demand-side platforms place bids on behalf of advertisers, the winning creative renders in a fraction of a second, and the site's account is credited per impression or per click. Nothing about the transaction differs from a legitimate publisher except what sits on the page.

The first wave of peer-to-peer piracy had no business model at all. The original Napster ran on zero revenue, which is part of why the lessons from its shutdown were about infrastructure rather than money. Modern piracy closed that gap. By the time of the 2009 Pirate Bay trial, the site's banner advertising was part of the case, and the defendants were convicted in Sweden of assisting copyright infringement. An ad-funded piracy site is, functionally, a small media business: free inventory, cheap traffic, and a payout at the end of the chain.

Distance is the critical feature. A media buyer sets a budget, an audience, and a price ceiling. The DSP places the bid. A reseller passes it along. By the time the ad renders, nobody who funded it has looked at the page. Your report has to collapse that distance.

Inside the Ad-Tech Chain: Exchanges, Resellers, and Arbitrage

Three layers of the chain deserve a closer look, because they explain how the money moves and why it is hard to interrupt.

Open exchanges. Programmatic advertising defaults to the open exchange: any buyer, any inventory, no page-level review. Some buying is private and vetted, through invitation-only marketplaces and direct deals where the publisher is known. Piracy inventory lives almost entirely in the open portion, priced low, sold by the thousand impressions, bought by algorithms looking for a bargain.

Resellers. Networks routinely resell inventory to other networks, which resell it again. Every hop takes a margin and adds obscurity. Unauthorized reselling became common enough that the IAB Tech Lab rolled out ads.txt in 2017, letting publishers publicly declare which sellers are authorized. Domain spoofing runs alongside it: inventory dressed up as a premium site and sold to buyers who believe they know what they bought. Long, murky supply paths are exactly where piracy pages hide.

Arbitrage. In ad-supported piracy, arbitrage means buying traffic for less than the traffic earns in ad impressions. The site purchases bulk popunder or redirect traffic, visitors who land involuntarily, then monetizes the resulting impressions at a higher rate. The spread is the profit. Pirate sites are natural arbitrage players. Their content costs nothing to produce, refreshes daily, and draws search traffic on its own. Thin CPMs sustain a business whose only real expenses are a domain and hosting.

The Piracy Verticals That Run on Ad Money

Ad-funded piracy concentrates in recognizable formats. Streaming mirrors and tube sites, including live sports restreams, stack banner and video ads several layers deep. Crack and keygen pages built around stolen software treat the download button itself as an ad slot, surrounding it with popunders, fake buttons, and redirect chains paid per click. Leak aggregators that trade in leaked creator content run some of the heaviest ad loads across those sites, because their content updates daily and search demand never cools. Gray storefronts selling stolen content cheap often layer ad revenue on top of direct sales. Ebook mirrors and course-dump sites follow the same pattern. Subscription IPTV is the exception that leans on recurring payments, though its promo and portal pages still run ads.

The common profile: zero production cost, high refresh rate, traffic arriving through search or social. That is a perfect programmatic publisher, except the inventory is stolen. Knowing the pattern tells you what to expect before you open the page source, and which networks to look for once you do.

Industry Trust Programs: TAG, ads.txt, and sellers.json

The ad industry's response to paying pirates is partly self-regulation, and it helps to know the moving parts.

The Trustworthy Accountability Group, or TAG, is an industry body launched by the major US advertising trade associations. It certifies companies against fraud, malware, and piracy. A certified network has committed to measures such as screening inventory against known pirate domains and acting on credible reports. If the network you are reporting holds TAG certification, say so in your report. Certification converts a polite request into a compliance question, and compliance questions get escalated internally.

The IAB Tech Lab's transparency standards attack the reseller problem from the other end. ads.txt is a public file at a site's root listing the sellers authorized to sell its inventory. sellers.json is the supply-side counterpart, where platforms disclose their sellers and payment relationships. Brand-safety vendors layer on top of this, maintaining piracy blocklists advertisers can apply as category exclusions.

Know the limits. ads.txt is self-declared. A pirate site publishes its own file, listing the networks it genuinely uses, and a valid-looking file certifies nothing about legality. Successive Notorious Markets reviews by the US Trade Representative have kept flagging advertising as a lifeline for listed piracy sites. The tools expose the money better than they stop it, which is precisely why they matter to you: an ads.txt file names who is paying the site, and your report tells them to stop.

How to Find Which Ad Network Is Paying a Pirate Site

A report is only as good as its address line. Identify the payers before you write it.

  1. Open the page source and search for script domains belonging to known networks and exchanges. Note any account or publisher IDs inside the tags.
  2. Hover the AdChoices or "Ads by" label on the rendered ad. Many networks identify themselves right on the unit.
  3. In a sandboxed browser profile, click an ad and record every redirect hop before the landing page. Each hop names an intermediary.
  4. Read the site's ads.txt. It is a self-submitted map of the site's monetization.
  5. While you are profiling the site, capture its hosting and registrar details with a tool like Website Detective. The ad complaint usually travels alongside a host takedown, and you will need both.

Keep the raw material. Networks ask for specifics, and specifics separate a processed report from a deleted one.

What a Report to an Ad Network Needs

Get the legal frame right first, because it shapes the document. A report to an ad network is a publisher-policy complaint, not a DMCA takedown notice. Under 17 U.S.C. § 512, takedown notices go to providers that host or store infringing material. An ad network delivering ads onto someone else's page is not hosting your content, so the notice-and-takedown machinery does not apply to it directly. You are invoking the network's own publisher policies. The prominent exception is Google, which accepts copyright complaints against AdSense publisher sites and may disable ad serving on a site named in a valid notice, with enough notices endangering the publisher's entire account. That route is platform policy driving the process, so use Google's own channel for it.

For every other network, include these elements:

  1. The exact page URLs where the ads appeared, full URLs, not the homepage.
  2. Dated screenshots showing ads rendered on those pages, with your timezone stated.
  3. Identification of the infringing content: which work of yours appears, and where, with proof you own the work.
  4. The network identifiers you captured, script domains, account IDs, redirect chains.
  5. The advertiser and creative, if visible, so the network can trace the campaign.
  6. A specific ask: stop serving on the domain, and review the publisher's account standing.
  7. Your contact details and your relationship to the rights holder.

Two cautions. Accuracy matters even without the teeth of Section 512(f), which penalizes knowing misrepresentation in DMCA notices. Networks quietly stop processing reports from unreliable filers. And the network complaint does not remove the content. File the host or platform takedown in parallel. The ad cutoff and the content removal are separate wins, and you want both.

Why Revenue Leakage Persists

Reports do work. Pirate sites lose accounts, and domains get demonetized. The leak persists for structural reasons, and knowing them will save you some frustration.

Nobody owns the problem. Every hop in the supply chain earns margin on volume, and no participant sees the full path from brand to piracy page. The buyer who funded the ad cannot see it. The network that served it sees only its own segment. Enforcement happens where someone is watching, and nobody is paid to watch.

Incentives point at fraud, not piracy. Ad fraud takes money from advertisers, so advertisers fund detection for it. Piracy takes money from creators. To the advertiser, a conversion on a piracy page costs the same as a conversion anywhere else. The industry polices what its customers pay to police.

Infrastructure is disposable. Domains rotate, and court-ordered site blocking has trained operators to keep dozens of lookalike mirrors warm, re-pointing their ad tags within hours. By the time your report is processed, the campaign has ended and the traffic has moved. Search-side pressure helps, Google has downranked sites that accumulate valid takedown notices since 2012 through its piracy demotion signal, but demotion slows discovery. It does not stop it.

Part of the chain sits offshore. Networks that knowingly serve piracy often operate in jurisdictions where US policy pressure carries little weight, and outcomes there turn on foreign law and each platform's own rules rather than anything in the DMCA. Meanwhile the arbitrage economics keep the floor low: as long as traffic costs less than the impressions it generates, a piracy site survives on margins a legitimate publisher could not.

This is why enforcement strategy keeps shifting from removing files to following piracy's money, advertising first, then payment processing. Money leaves records that files do not.

Frequently Asked Questions About Ad Networks and Pirate Sites

Can I file a DMCA notice directly against an ad network?

Generally, no. Section 512 takedown notices are aimed at providers that host or store infringing material, and an ad network delivers ads rather than hosting your work. The practical exception is Google, which accepts copyright complaints about AdSense publisher sites and may disable ads on them in response. For every other network, the effective document is a publisher-policy complaint, not a statutory notice.

What is ads.txt, and does it stop piracy?

ads.txt is an IAB Tech Lab standard: a public file at a site's root listing the sellers authorized to sell its ad inventory. It was built to expose unauthorized reselling, and it does that job well. It does not certify that a site is legal, pirate sites publish their own valid-looking files. For rights holders, its real value is reconnaissance: it names the companies paying the site.

Do ad networks lose money when they cut off a pirate site?

They lose that site's inventory and their margin on it, which is usually small next to overall network revenue. That is why enforcement stays complaint-driven rather than proactive. The cumulative picture is different: a network that repeatedly ignores credible piracy reports risks its TAG certification status, its advertiser relationships, and the platform policies that let it operate at scale.

How long does an ad network report take to work?

Timelines vary, and no major network publishes a binding one. Individual campaigns end quickly, so a specific ad can vanish before your report is even read. The durable result is account-level: a terminated publisher account or a demonetized domain. Expect faster action from large self-service networks and slow or no response from offshore resellers. Report each new mirror as it appears.

Should I report the advertiser whose ads appear on a pirate site?

Yes, whenever you can identify the brand. Most advertisers buy programmatically and genuinely do not know where their ads render; a dated screenshot of their creative beside stolen content is exactly what their brand-safety team needs. Brands frequently move faster than networks, and an advertiser's pressure on its exchange or DSP can produce results that a lone complaint will not.

What to Do Next

  1. Run a proper evidence checklist before anything else: page URLs, dated screenshots with the ads visible, captured redirect chains, and the site's ads.txt contents.
  2. Report to every network you identified, using the elements above. Cite TAG certification where the network holds it.
  3. File the host or platform takedown in parallel. The ad cutoff and the content removal are separate wins.
  4. If a clean report goes ignored, climb the escalation ladder, exchange, DSP, advertiser, trade association, in that order.
  5. If piracy keeps recurring rather than resolving, hand monitoring and reporting to a professional takedown service that tracks mirror domains as they appear.

A single report rarely ends an ad-funded piracy operation. A steady stream of accurate reports, filed at every link in the chain, ends the profitability that keeps it alive.