Most for-profit piracy runs on two rails: advertising served by ad networks and payments handled by processors. Cut those rails and the site stops covering its hosting bill, and operators rarely keep an unprofitable hobby alive for long. Deleting files, by contrast, buys you days. Mirrors come back because re-uploading costs the operator nothing.

Following the money means identifying who pays a pirate site, documenting that your copyrighted work is the content pulling its traffic, and reporting to those intermediaries under their own policies. It is not a DMCA takedown in the statutory sense, Section 512 of the Copyright Act binds hosts and platforms, not ad networks or merchant acquirers, and that is why it works on a different lever. You are not asking anyone to remove a file. You are showing a compliance team that it is paying for theft.

Why Revenue, Not Files, Is the Strategic Target

The record on file removals is not encouraging. When a court order shut Napster down in 2001, demand did not disappear, it moved to decentralized networks that were harder to sue. The lessons from the Napster shutdown are mostly lessons about displacement. The record industry's next approach, suing individual fans, fared no better; the history of RIAA piracy lawsuits matters here mainly for what it taught rights-holders about aim.

Aim improved when enforcement started targeting the business model. Sweden's Pirate Bay trial put the site's advertising revenue on the record in a criminal case, the money was the crime scene, not the torrent files. Piracy-for-profit operations have payroll, hosting costs, and ad operations, and that structure is their vulnerability.

There is a plain economic asymmetry at work. A takedown costs you an hour and costs the operator ten minutes to undo. Losing an ad network or a merchant account costs the operator weeks of re-onboarding, frozen payouts, and sometimes the balance sitting in the account. Files are infinite. Margins are not. A site that keeps every file but loses its monetization becomes a cost center, and cost centers get abandoned.

How Pirate Sites Get Paid: The Two Revenue Rails

Ad-supported sites rarely sell advertising directly. They sign with low-tier networks or brokers, unsold inventory gets resold into programmatic exchanges, and somewhere at the bottom of the chain a mainstream brand's creative appears next to a film its agency never heard of. Popunders, redirect scripts, and push-notification spam are common. Nobody at the top of the chain intends to fund piracy, and almost nobody checks, which is precisely how ad networks end up on pirate sites.

The payment rail is more direct: premium accounts, VIP tiers, donate buttons, crypto wallets. Subscription piracy, restreamed sports, IPTV packages, paid leak collections, is where the revenue is most visible. Creators know the pattern well from the OnlyFans leak economy: a site aggregates stolen content, monetizes the pages with ads, then sells "full pack" access through Telegram channels, which are themselves a takedown target under Telegram's copyright removal process.

Some sites add a third mini-rail: affiliate commissions for VPNs, betting sites, or crypto casinos. Treat affiliate programs like ad networks. They have terms of service, and most prohibit promoting infringing content.

Mapping a Pirate Site's Ad Networks

Mapping turns "this site runs ads" into named networks, publisher account IDs, and dated captures. You can do it from an ordinary browser, documenting as you go.

  1. Load the site with developer tools open and watch the Network tab. Note the domains delivering ad scripts and iframe tags, those are the networks serving the page.
  2. View the page source and copy the ad tag blocks, including account or publisher IDs. Save the HTML or screenshot the source view with the URL visible.
  3. Check the domain's /ads.txt file. Many pirate sites list their authorized sellers there, which saves you the guesswork.
  4. Follow popunders and redirects to their destination and record each hop.
  5. Repeat on different days. Placements rotate, and the pattern matters more than any single impression.
  6. Compare against archived snapshots to show the monetization is long-running rather than incidental.

Infrastructure comes next. Most pirate domains sit behind Cloudflare, which conceals the real host, a Cloudflare abuse report creates a paper trail and often surfaces the actual provider, and finding out who hosts a website is straightforward once you know the techniques. If you are working dozens of domains, scanning tools like a website detective automate the first pass.

Tracing the Payment Processors Behind the Site

Look for Premium, VIP, and Donate buttons, then click through and record what the checkout actually is: a Stripe payment link, a PayPal button, a crypto gateway, a card form naming a merchant. Screenshot every step with the URL and date visible. Capture the subscription tier pages too, a published price list is the best evidence that the infringement is a business, not a hobby. For subscription-piracy operations this rail is the whole business, which is why payment processor cutoffs hit harder than any single removal.

Identifying the operator is a separate problem, and WHOIS records are usually privacy-shielded. Where unmasking them becomes necessary, the lawful tool is a 512(h) subpoena under 17 U.S.C. § 512, directed at a service provider that stores information, courts have limited its reach against pure conduit providers, and that is work for counsel. Most campaigns never need it. The named intermediaries are enough, because the intermediaries are where the money lives.

Building the Documented Report That Gets Action

Ad networks and processors receive thousands of complaints. The ones that get read look like evidence files, not venting. Four layers:

  1. Ownership. Identify the work, when it was created or published, and its registration status. Proving content ownership follows recognizable formats: originals, registrations, publication records, and intermediaries act on what they can verify.
  2. Infringement. Exact URLs, dated screenshots with the address bar visible, archived copies of the pages. Timestamped evidence matters because pages change hourly and your claim is about a specific moment.
  3. Monetization. The ad tags, ads.txt captures, checkout pages, and processor names from your mapping work. This is what makes it a follow-the-money report rather than a routine notice.
  4. The connection. One short narrative paragraph: this site distributes my work at these URLs, is paid through these networks and processors, and here is proof of each link in that sentence.

Work from a takedown evidence checklist so nothing critical is missing, and keep the tone factual. You do not need to prove the site's revenue, only that pages carrying your work are monetized. Overstatement costs credibility, and credibility is what gets your next report read.

What Legitimately Moves the Ad Rail

Ad networks' publisher policies almost universally prohibit serving ads against infringing content. A documented report to a network's trust-and-safety or publisher-compliance team can trigger a review, a payout hold, or termination. Response quality varies, some networks investigate within days, others ignore everything, so log every submission and reply.

The advertiser side moves too, legitimately. Brands and agencies do not want their budgets funding piracy, and brand-safety vendors sell detection on exactly this point. Telling an advertiser precisely where its ads ran converts a bystander into a caller, and calls from advertisers get answered.

Industry programs add weight. The IAB's ads.txt standard makes unauthorized reselling traceable, and bodies like the Trustworthy Accountability Group run programs under which ad companies commit to cutting off known piracy inventory.

Google deserves a separate note because two of its policies compound. AdSense prohibits ads on infringing pages, and Google has stated that sites accumulating many valid takedown requests are demoted in search results. The piracy demotion algorithm is why your routine notices and this strategy reinforce each other, every valid takedown also starves the site's discovery.

What Legitimately Moves the Payment Rail

Processors' acceptable-use policies prohibit commerce in infringing material, and their brand-risk teams act on documentation the same way ad compliance teams do. A report with your evidence pack can trigger a merchant review, a reserve on funds, or account termination.

The card networks are the heavier lever. Visa's Global Brand Protection Program and Mastercard's BRAM framework push acquiring banks to police merchant categories that include sites trafficking infringing content. This is card-network policy, not US statute, and that is an advantage: the rules follow the rails worldwide, which matters when the operator sits offshore and outside the practical reach of a US court.

The Megaupload prosecution made the point vividly. The 2012 indictment did not merely list infringing files; it described the subscription and advertising business the files existed to feed. Documented well enough, the money trail stops being a pressure point and becomes evidence.

Expect rotation. Terminated merchants re-apply elsewhere under new names, and each re-onboarding costs setup time, reserve deposits, and the risk of a second freeze. The goal is not a single permanent kill. The goal is making the operation structurally unprofitable until someone abandons it.

The Adjacent Rails: Hosting, Blocking, and Escalation

Revenue work does not replace file removal, the two run in parallel. Keep sending standard notices to the host, because removing stolen content from a website is still the fastest way to kill an individual copy. When a host rejects or ignores a valid notice, learn what to do after a DMCA takedown is rejected instead of re-sending the same email louder, and follow a structured copyright removal escalation ladder so the pressure rises in the right order.

Site blocking is the third-party analog, with a jurisdictional caveat. Blocking orders are overwhelmingly a non-US remedy, courts in the UK, Australia, and across the EU have ordered ISPs to block piracy domains, while the closest US equivalent has been criminal domain seizures rather than civil blocking. How site-blocking orders work depends on where you can sue, so identify your jurisdiction's rails early and stop spending effort on one it does not offer.

Common Questions About Following the Money

Does the DMCA require ad networks and payment processors to stop serving a pirate site?

No. Section 512's notice-and-takedown mechanism applies to service providers that host or transmit infringing material, and ad networks and acquirers do not hold the files. They act because their own publisher and merchant policies prohibit monetizing infringing content. Your report therefore has to persuade a compliance team under contract policy, not satisfy a statutory form.

How do I find out which ad network is funding a pirate site?

Open the site with your browser's developer tools and watch the Network tab as the page loads, ad tag domains appear there. View the page source for ad script blocks and their account IDs, check the domain's /ads.txt file, which lists authorized sellers, and record any popunder redirect chains. Reload on different days, since placements rotate, and screenshot everything with URLs and dates visible.

Can payment processors really cut off a piracy site's account?

Yes, and it happens regularly. Acceptable-use policies prohibit selling infringing content, and card-network risk programs, Visa's Global Brand Protection Program and Mastercard's BRAM among them, push acquiring banks to police those categories. A documented report with URLs, dated screenshots, and captured checkout pages gives a risk team what it needs to terminate the merchant or hold its funds.

Is following the money better than filing standard DMCA takedowns?

They do different jobs. A takedown removes a specific file from a specific host; revenue work attacks the operator's reason to exist. The methods compound: notice volume feeds search demotion, and monetization reports make every re-upload less profitable. If you can only do one today, file the takedown, but sites that re-upload endlessly rarely stop until the money stops.

Do I need a lawyer to run a follow-the-money campaign?

Not for the reports themselves. Anyone can send a documented abuse or policy-compliance report, and no legal representation is required. Counsel becomes necessary for a subpoena under 17 U.S.C. § 512(h), for litigation, or for blocking orders in foreign courts. Recognizing when to hire a copyright lawyer is mostly about spotting the moment do-it-yourself tools stop being enough.

What to do today

  1. Confirm the site is actually monetized before spending effort, ads visible, checkout pages live.
  2. Map the rails: ad tags, ads.txt, popunder destinations, processor names, checkout captures.
  3. Prove ownership of the work and gather dated evidence of the infringing pages.
  4. Assemble the four-layer report: ownership, infringement, monetization, connection.
  5. File standard takedowns in parallel, so copies keep dying while the money work proceeds.
  6. Report to each rail's compliance team, and log every submission and response with dates.
  7. Repeat as the site rotates networks and processors, persistence is the strategy, not a bonus step.

If the mapping alone would eat a weekend you do not have, that is the signal to hand the file off. First-time, single-site situations fit the DIY takedown path. At scale, dozens of mirrors, rotating processors, rights-holders typically run a commercial takedown program, compare pricing against the leak rate, and vet providers with a guide to choosing a DMCA takedown service, because real monitoring looks very different from badges and bluster.