Between June 2010 and the mid-2010s, US Immigration and Customs Enforcement ran a campaign that seized internet domains accused of piracy and counterfeiting and replaced them with a federal banner page. Operation In Our Sites was executed by Homeland Security Investigations agents working with federal prosecutors, and over several years it swept up domain names by the hundreds. That is the ICE domain seizures history in its shortest form.

The details matter to two groups of readers. Site owners need to know how a forfeiture seizure works, because the mechanism still exists and still reaches any domain whose registry answers to US legal process. Rights holders need to know why the mass-seizure era ended, because its failure points directly at the enforcement tools that actually work today.

What Operation In Our Sites Actually Did

HSI executed the first nine warrants on June 30, 2010. The batch included NinjaVideo.net, a video streaming site, and TVShack.net, a UK-run site that linked to video files hosted elsewhere. Each seized domain began resolving to a government server displaying the ICE seal, a statement that the name had been seized pursuant to a federal warrant, and warnings about criminal penalties for willful copyright infringement and trafficking in counterfeit goods. The message was the point: the banner page was designed to be photographed, written about, and remembered.

The operation went public ahead of Cyber Monday in November 2010, when ICE announced 82 additional seizures. Most of those domains sold counterfeit jerseys, handbags, and accessories; a handful, like the torrent search engine Torrent-Finder.com, did not host anything at all. The sweeps repeated each shopping season, the next Cyber Monday round took roughly 150 domains, and continued at declining scale into the mid-2010s. Coordination ran through the ICE-led National Intellectual Property Rights Coordination Center, which took referrals from rights holders and industry groups.

How ICE Seized a Domain: The Civil Forfeiture Mechanic

The legal engine was asset forfeiture, the same body of law used to seize cars and bank accounts. An HSI special agent filed an affidavit with a federal magistrate judge asserting that the domain was property used to commit or facilitate a crime, typically criminal copyright infringement under 17 U.S.C. § 506 and 18 U.S.C. § 2319, or trafficking in counterfeit marks under 18 U.S.C. § 2320. Forfeiture authority came from 18 U.S.C. § 981 for civil actions and 18 U.S.C. § 2323 for IP cases, and counterfeit-merchandise seizures also leaned on customs authority under 19 U.S.C. § 1595a.

The warrants were ex parte, meaning the owner got no hearing before the domain went dark. The first notice was usually the banner itself. Because the registries for .com, .net, .org, .biz, and .info answered to US legal process, a magistrate's warrant reached a name no matter where the owner or the servers were located. After the seizure, the government had to initiate forfeiture, and an owner who wanted to fight had to file a claim under the CAFRA procedures in 18 U.S.C. § 983 and litigate in federal court. Most owners, often overseas, sometimes anonymous, never filed, and the domains were forfeited by default.

That structure is why a seizure feels nothing like private enforcement, and it is the practical difference between a DMCA notice and a court order. There is no safe harbor, no counter-notice, and no platform to negotiate with. One warrant, and the address belongs to the government.

The Sports-Streaming Crackdown

Live sports was the enforcement priority from the start, because an unauthorized restream does its damage in real time. A match pirated after the final whistle is worth almost nothing; the same match pirated in the first minute is worth everything. Leagues referred streaming sites to the government steadily, and ICE timed its biggest actions to Super Bowl weekends for maximum attention.

The defining seizure came in early February 2011, when ICE took rojadirecta.com and rojadirecta.org. Rojadirecta was a Spain-based index of links to live sports streams, and its owner, Puerto 80, told the courts that judges in Spain had already found the site lawful there. The seizure proceeded anyway. Puerto 80 challenged it in federal court in Manhattan, and in 2011 a judge declined to return the domains. The litigation ended without Rojadirecta ever coming back.

A year later, ahead of Super Bowl XLVI, ICE announced Operation Fake Sweep: 307 domains, of which 291 allegedly sold counterfeit merchandise and 16 allegedly streamed the game illegally. The NinjaVideo cases were the rare seizures that matured into prosecutions, several operators were convicted and sentenced in 2012, but sports piracy mostly stayed a seize-and-repeat exercise.

Sports is still the top target, and it is where enforcement remains most active, including the continuing work against IPTV piracy. In most of the world, though, blocking has replaced seizure as the tool of choice, and understanding how sports broadcast blocking orders work will matter more to a rights holder today than the old banner page.

Domain Hopping and the Limits of Seizure Deterrence

A seizure takes an address. It does not touch the servers, the files, the operator, or the audience, and that gap defined the whole era. Within days of a seizure, sometimes within hours, targeted sites reappeared under new names, and their traffic followed them. TVShack relaunched at a new address almost immediately after the June 2010 seizure.

The economics were lopsided. A replacement domain cost a few dollars; the warrant behind the original address cost a federal investigation, an affidavit, and a magistrate's signature. Enforcement paid retail while piracy paid pennies. Operators also learned which suffixes were safe. ICE's warrants worked against registries on US soil, so sites migrated to country-code domains whose registries sat beyond American reach. Outside analyses that tracked the sweeps found that most targeted services recovered their audiences, and the banner page produced a headline on announcement day and little else a month later.

Rights holders drew the obvious conclusion. Chasing addresses was a treadmill, while pressure on revenue, the flow of payments and ad money to pirate sites, produced durable results. That pivot toward following the money in piracy reshaped the enforcement field once the seizure era peaked.

Due-Process Challenges: Dajaz1, Rojadirecta, and TVShack

The harshest criticism came from cases that fell apart. Dajaz1, a hip-hop blog, was seized in November 2010 on allegations of music piracy, much of it music that labels and promoters had sent the blog for publicity. The domain spent about a year under seizure while the government obtained extensions of its deadlines under seal, filings the owner's lawyers were not allowed to see, before being returned in December 2011 with no charges ever filed.

Torrent-Finder.com, seized in the first publicized wave, hosted no files; it searched other sites. Its affidavit rested on a facilitation theory that critics found thin. The Rojadirecta litigation added First Amendment arguments, on the theory that the government was holding a domain used for lawful speech alongside infringing links, and lost at the district court level.

International reach caused the loudest fights. Richard O'Dwyer, the UK student behind TVShack, had no servers or assets in the United States, yet faced extradition over a linking site whose domain happened to be a .com. That case ended in 2012 with a deferred prosecution agreement and roughly £20,000 in compensation. Taken together, the record, ex parte warrants, sealed extensions, jurisdiction stretched through the registry system, became a central exhibit in the 2011–2012 fight over SOPA and PIPA, the bills that would have made domain-level remedies routine. When those bills collapsed, the political appetite for mass seizures went with them.

US Domain Seizures Today

The scheduled sweeps wound down by the mid-2010s. Seizures themselves did not disappear; they changed shape. Today a US domain seizure usually rides along with a criminal case, where the domain is one asset among many. The 2022 takedown of Z-Library paired the seizure of its domains with arrests and criminal charges, and that pattern is the modern norm for major targets. HSI's IPR Center still runs targeted actions, and counterfeit-domain seizures still surface around major sporting events. One thing has not changed: if your domain's registry answers to US legal process, the old seizure lever still reaches you.

The enforcement energy that Operation In Our Sites once carried has moved to private channels and revenue-side pressure. Payment processors now cut off pirate sites under the payment processor cutoff playbook, and ad networks pulling pirate inventory attack the revenue side directly. Outside the US, courts order blocking at the ISP level, and how site-blocking orders work describes that regime, which American courts have not generally adopted. When the US government goes big now, it goes criminal, as in the Megaupload shutdown, where servers, bank accounts, and domains all went at once.

If Your Domain Was Seized, or Your Content Is Being Pirated

If you own the domain: the banner means registry-level control of your name is now with the government pending forfeiture. Your hosting account and files are untouched, the address is what was taken. Screenshot the banner, record the agency and any case number, and gather your registration records and every complaint you ever received. Once formal notice arrives, the CAFRA deadlines are short, and missing them ends in default forfeiture. Do not relaunch the same content at a new address without legal review; that can compound exposure rather than cure it.

Be realistic about the odds, too. Most seized domains stayed seized, and even Rojadirecta's well-resourced challenge failed. Dajaz1 is the counterexample that matters: a seizure built on weak evidence collapsed when competent counsel pushed on it. Evidence and speed decide these disputes, which is why when to hire a copyright lawyer is a days-not-weeks decision.

If you are the rights holder, the era's lessons are practical. Government referrals are slow and case-driven; private enforcement starts faster and scales better. Work an escalation ladder for copyright removals, notice first, platform escalation second, commercial remedies after that. If someone registered a domain that trades on your brand, the UDRP process for domain trademark disputes moves faster than any government lane. And if counterfeits are the problem, seizures complement private counterfeit goods takedowns rather than replace them.

ICE Domain Seizure FAQ

Can ICE seize a domain that is registered abroad?

Yes, if the registry is American. A .com, .net, or .org name is controlled by a US-based registry, so a federal warrant reaches it regardless of where the registrant or servers sit. That reach is why foreign operators could lose .com domains without ever setting foot in the United States. Country-code registries outside the US were the escape hatch, which is exactly where seized sites moved.

Does a domain seizure mean the owner was convicted of a crime?

No. The seizure is a civil forfeiture action against property, not a judgment against a person. The government alleges crime as the basis for taking the domain, but only a small share of cases, NinjaVideo being the clearest example, matured into prosecutions and sentences. Most seized domains were forfeited by default with no charges at all.

How long can the government hold a seized domain?

Until forfeiture completes or a court orders the domain returned. Once formal notice arrives, CAFRA sets deadlines for contesting, and the government can seek extensions. Dajaz1 spent about a year under seizure while sealed extensions ran before being returned without charges. Uncontested domains end in default forfeiture, which can take months.

Is a domain seizure the same as a DMCA takedown?

No. A DMCA takedown is a private notice to a host or platform asking it to remove specific material, backed by statutory safe-harbor procedures. A seizure is a government forfeiture action under a court warrant that takes the entire address with no prior notice. Different law, different remedies, different timelines.

Do ICE domain seizures still happen today?

Yes, at a smaller scale. The scheduled mass sweeps ended, but HSI still seizes domains, usually alongside criminal investigations or counterfeit operations, and the 2022 Z-Library action followed that pattern. Everyday anti-piracy work now runs mostly through payment cutoffs, ad-network enforcement, and private takedown programs.

What To Do Next

  1. If your domain shows a seizure banner, screenshot everything and record the agency, district, and any case number before the page changes.
  2. Collect ownership records, registration history, and any infringement complaints into one organized file, our takedown evidence checklist works for defense too.
  3. Get legal review before relaunching at a new address or filing a claim for return; in these cases, timing and evidence decide the outcome.
  4. If you are a rights holder facing persistent piracy or counterfeiting, a managed program beats one-off notices. Our commercial takedown service handles recurring infringement at scale.
  5. Know your costs up front, see our pricing for flat-fee takedown and protection plans.