On January 19, 2012, the US Justice Department unsealed a criminal indictment against Megaupload Limited, seized the site's domains, and coordinated arrests across several countries within days. Kim Dotcom, the site's founder, was taken into custody outside Auckland, New Zealand, the next morning. Megaupload never reopened.
The indictment made two headline claims: Megaupload paid cash rewards for uploads that drew heavy traffic, and it tolerated repeat infringers its own terms of service promised to remove. Neither claim was ever proven against the principal defendants at trial, the case never got that far. Even so, the shutdown settled a decade-old argument about what DMCA safe harbor does not cover, and it permanently changed how file-hosting platforms are built. That gap between allegation and verdict is where the useful lessons sit, both for operators and for rights owners whose work ends up on lockers today.
What the Megaupload Indictment Alleged
A grand jury in the Eastern District of Virginia returned the charges; prosecutors anchored jurisdiction there partly because Megaupload leased servers from a Virginia hosting company. The indictment named seven individuals and two entities, reached the whole family of sites including Megavideo, and charged racketeering conspiracy, criminal copyright infringement, conspiracy to commit copyright infringement, and money laundering.
The Justice Department's announcement attached numbers: more than $175 million in alleged criminal proceeds and more than $500 million in alleged harm to copyright owners, with the site described, at its peak, as among the most-visited destinations on the internet. Treat those figures as the government's assertions. They were never tested at trial, and the defense disputed them from the start.
Three allegations carried the real weight. First, the rewards program. According to the indictment, Megaupload paid cash bonuses to users whose files drew heavy download traffic, and the government argued the biggest payouts tracked popular movies and television. The claim was about incentives: if you pay for popular uploads, you are paying for infringing ones, because that is what is popular.
Second, repeat infringers. The indictment alleged that Megaupload's terms promised termination for repeat infringement while the site, in practice, rarely cut off paying customers. Every operator of a user-generated platform should read that as a compliance item. A documented, enforced repeat infringer policy is now standard across the industry, and this filing is a large part of why.
Third, the takedown process. The indictment alleged that Megaupload's abuse tool removed a single link rather than the underlying file, so the same infringing file stayed reachable through other links. Prosecutors also quoted internal communications in which, they said, executives discussed infringing content and the traffic it drove. The defense never conceded any of it. As a public record, it stands as allegations, but allegations detailed enough to change an industry.
The Megaupload Raids and the Extradition Fight That Followed
This was not a DMCA notice. It was a law enforcement action run through treaties and local police, which is the single most consequential distinction in the story.
New Zealand officers arrested Dotcom on January 20, 2012, in a raid that, as widely reported, involved helicopters and dozens of armed police. New Zealand courts later found fault with parts of it: the warrants were called defective, and the transfer of cloned copies of Dotcom's hard drives to US authorities before local judicial review was ruled unlawful. The domains, including megaupload.com, pointed to federal seizure banners, one chapter in the longer history of ICE domain seizure actions. Bank accounts were frozen and luxury assets impounded, with reported values in the tens of millions. The money laundering and racketeering counts reframed the case as following the money in piracy, which gave prosecutors tools copyright law alone does not offer.
Then came the decade of aftermath. New Zealand's High Court ruled Dotcom eligible for extradition in 2015; per public reporting, the Court of Appeal and then the Supreme Court left that outcome standing by 2020. In 2024, media reported that New Zealand's justice minister had approved surrender for Dotcom and two co-defendants, and that further challenges followed. As of this writing, public reporting indicates Dotcom has remained in New Zealand, verify the current status before relying on it. One co-defendant, the programmer Andrus Nomm, pleaded guilty in the United States in 2015 and, per DOJ announcements, was sentenced to about a year in federal prison.
The enforcement lesson for anyone building an anti-piracy plan: the DMCA has no force outside US borders. Cross-border enforcement runs on extradition treaties, local courts, and local statutes. A plan that assumes US law applies overseas is a plan that will surprise you.
Why DMCA Safe Harbor Could Not Save Megaupload
Safe harbor, Section 512 of the Copyright Act, shields qualifying providers from civil liability for material their users post, if they meet conditions such as registering an agent, acting on notices, and terminating repeat infringers. How DMCA safe harbor works is its own subject; the short version is that it is a defense in private civil litigation. This section describes US federal law. The raid side of the story ran on New Zealand law, which is why it produced its own line of New Zealand court decisions.
Criminal infringement is different. Under 17 U.S.C. § 506, with penalties under 18 U.S.C. § 2319, willful infringement done for commercial advantage is a federal crime. Safe harbor is not a permit the government must respect before filing charges, and the indictment aimed at the operators' own conduct: payments, decisions about what to keep, and an allegedly hollowed-out takedown process.
There is a contested layer, too. Prosecutors leaned partly on a theory of secondary criminal liability for user uploads, and legal commentators split on whether that stretched the statute. Nobody got an answer, because the principal defendants never stood trial. The civil analogue is clearer: even inside the safe harbor framework, a company that induces infringement loses protection, as the Supreme Court held in MGM v. Grokster.
One distinction worth internalizing before you file anything: Megaupload was not taken down by takedown notices. The difference between a DMCA notice and a court order is the difference between a private complaint and state power, and consequences like seizure, freezing, and arrest follow only from the second.
How Megaupload Differs From Napster and the RIAA's Early Cases
Megaupload was not the first big shutdown, and the earlier cases explain why this one felt new. Napster died in 2001 through private litigation: copyright owners sued, the Ninth Circuit affirmed an injunction, and filtering killed the service. The lessons from the Napster shutdown are lessons about civil secondary liability. The RIAA's lawsuits of the 2000s targeted individual uploaders, civilly, one defendant at a time.
Megaupload inverted the model. The state took the site, not the studios. The defendants were offshore. The charges were criminal. The nearest analogue is the Pirate Bay trial in Sweden, also criminal, but under Swedish law in Swedish courts. Here, US criminal law reached a foreign operation through Virginia servers and US users. Whether that reach was sound is still debated. That it was attempted is the fact that changed behavior worldwide.
Timing added heat. The shutdown landed two days after the January 18, 2012 blackout protests against SOPA and PIPA, and Anonymous claimed credit for retaliatory attacks on government and industry sites. Public sympathy for the enforcement action was never simple, and that controversy is part of the record too.
What Happened to Innocent Megaupload Users' Files
Collateral damage rarely makes the indictment. Megaupload also hosted legitimate material, business backups, personal video, family archives, and when the domains went dark, every user lost access at once, infringing or not.
The bulk of the data sat with Carpathia Hosting in Virginia, reported at roughly 25 petabytes. Nobody wanted to keep paying to preserve it. The parties fought over costs, and the Electronic Frontier Foundation ran an effort to help lawful users petition for their own files. The most prominent petitioner, per EFF filings, was an Ohio videographer whose business stored sports footage on the site. Recovery, where it happened at all, took years and court intervention.
Two practical takeaways. Keep your own backups: a platform can die by seizure as easily as by bankruptcy, and in neither case does anyone owe you your files. And notice what did not help these users, the DMCA itself. The counter-notice process settles disputes between private parties over takedown notices. A criminal seizure has no equivalent form to fill out.
How the Shutdown Reshaped File-Locker Design
The clearest measure of a case's impact is what competitors change afterward. Within a year, the visible conventions of file hosting had shifted.
Dotcom's successor service, Mega, launched in January 2013 built around client-side encryption, with no upload bounties. Across the wider industry, the pattern held. Cash-for-uploads programs disappeared. Public search and file browsing disappeared. Major hosts adopted content fingerprinting to block known infringing files at upload, and published DMCA strike policies backed by termination records. Retention shrank for files nobody downloaded. And as infringement flags piled up, payment processors showed themselves willing to cut file hosts off, a pressure point that needs no courtroom.
None of this came from new legislation. These are platform policies, adopted because an indictment read incentives and process as proof of intent. Read the indictment next to those changes and the logic is plain. The design questions it raised, what do we reward, what do we keep, what does a takedown actually remove, are the same questions a platform lawyer or a plaintiff will ask any file host in 2026.
What the Megaupload Case Means for Operators and Rights Holders
If you operate a platform that hosts user files, the checklist is short and unforgiving. Reward engagement, never popular uploads. Terminate repeat infringers and document every termination. When you process a takedown, remove the file, not one link to it. Assume internal communications about infringing content are discoverable, the indictment read the way it did because prosecutors had the messages.
If you are a rights holder, the case calibrates expectations. Criminal prosecution is not a service you can order. It is prosecutorial discretion, reserved by historical practice for operations the government considers large-scale commercial infringement. Your levers are private: compliant notices first, then an escalation ladder that runs from the host to the registrar to the payment network to the courthouse, and knowing when to hire a copyright lawyer before the pattern outgrows you. File-locker infringement moves quickly, and the sites behind it rotate domains faster than most victims can track.
Frequently Asked Questions About the Megaupload Shutdown
Was Megaupload ever found guilty of criminal copyright infringement?
No. The core allegations, paid rewards, tolerated repeat infringers, a hollowed-out takedown tool, were never tested against the principal defendants, because the extradition fight kept them out of a US courtroom. One co-defendant pleaded guilty in 2015, per DOJ announcements. Everything else in the indictment stands as allegation, not verdict.
Why didn't safe harbor protect Megaupload from criminal charges?
Safe harbor under Section 512 of the Copyright Act is a defense in civil suits between private parties, not a shield against prosecution. Criminal infringement targets the operators' own willful conduct, here, allegedly paying for popular uploads and keeping infringing files reachable. The government's theory was never tested at trial, so the boundary remains drawn by the indictment, not by a verdict.
What was the Megaupload uploader rewards program?
According to the indictment, Megaupload paid cash bonuses to users whose uploads drew heavy download traffic, and prosecutors argued the largest payouts tracked popular movies and television. The program mattered because it converted passive hosting into alleged inducement, a financial incentive to upload infringing material. Paying for popular uploads largely vanished as a business model at major hosts afterward.
Can a copyright owner trigger a criminal shutdown of a pirate site?
You can refer conduct to federal authorities, but the charging decision belongs entirely to prosecutors, and criminal actions at Megaupload's scale remain rare. Your working remedies are civil: compliant takedown notices, platform escalation, search delisting, and private litigation where the numbers justify it. Build your enforcement plan on the tools you control.
What happened to innocent users' files when the domains were seized?
Access ended overnight. The bulk of the data sat with a Virginia hosting company, reported at roughly 25 petabytes, while the parties fought over who paid to preserve it. With EFF help, some lawful users petitioned for their files, most prominently an Ohio videographer whose business footage was stranded. Most users recovered nothing directly. Keep independent backups.
What to Do If Your Content Sits on a File Locker Today
The Megaupload story is over a decade old, but the workflow it teaches still applies.
- Identify where the copy lives: the host, the domain, and the registrar behind it. You cannot enforce against what you cannot locate.
- Preserve evidence the same week you find the copy: URLs, checksums or hashes of your files, creation dates, and proof that you own the original.
- Send a compliant DMCA notice to the host. If the host hides behind anonymity or ignores valid notices, use a professional takedown service rather than filing into a void.
- Escalate in order of cost: registrar, search delisting, payment processors, ad networks, then court.
- Document repeat infringement as it happens, so that if the pattern ever justifies a referral or a lawsuit, your record already exists.
When a notice alone is not enough, choosing a DMCA takedown service that works the hosting and registrar layers is the step most people take too late.
