A pirate storefront selling your work runs on card payments, and card acceptance is a privilege the networks can revoke. Copyright law will not make a processor act, US courts closed that door, but the card networks' own rulebooks will, because those rules bind every acquiring bank through license agreements. A documented report through the right channel can strip a rogue merchant of card processing within weeks, which for a subscription piracy site is often fatal.

This page walks through the whole machinery: how acquirer liability makes banks move, what the acceptable-use rules prohibit, where each of the majors accepts reports, what your evidence pack must contain, and the one case where none of it helps. It applies whether you are facing someone selling your content cheap or a full clone of your storefront.

How a Card-Network Rule Reaches a Pirate Merchant: The Liability Chain

Every card sale runs through a short chain: the merchant, its acquiring bank, the card network, and the bank that issued the customer's card. The network never contracts with the merchant directly. It licenses the acquirer; the acquirer signs the merchant; and the network's rulebook is written into both agreements. That structure is what makes payment-processor piracy cutoffs possible. A prohibition adopted at network level becomes a binding obligation at the acquirer, backed by non-compliance fines, fraud liability, and mandatory termination rights.

The economics finish the job. An acquirer that keeps a rogue merchant on after a credible infringement report risks network penalties that dwarf one account's processing volume. When you file, you are not asking a bank for a favor. You are handing it a reason to enforce a contract it already signed.

The chain does not care what kind of creator you are. Game developers see it in storefronts reselling their titles at a fraction of retail, the same merchants behind most DMCA actions by game developers. Podcasters find their feeds locked behind someone else's paywall, a companion problem to the one covered in DMCA takedowns for podcasters. The merchant category changes. The lever does not, because both merchants bill cards, and the enforcement world has a name for that seam: following the money.

Why Copyright Law Won't Move a Processor, but Card Rules Will

Be clear about what you are invoking, because it is not copyright law. Under US law, the Copyright Act does not reach payment processors. In Perfect 10, Inc. v. Visa International (9th Cir. 2007), the Ninth Circuit held that networks processing payments for websites selling infringing images were not liable for the infringement itself, facilitating a sale, the court reasoned, is not materially contributing to the copying. The inducement theory from MGM Studios v. Grokster (2005) did not stretch to payment pipes either. The suit was brought by the same plaintiff who had fought Amazon over thumbnail search results, and the processor case went nowhere.

The DMCA is no better a fit. Section 512's notice-and-takedown machinery applies to providers that host, cache, or link to material, and its safe harbor protects those providers when they comply. A processor never touches the content, so there is nothing to take down and no statutory duty to act. Abroad, some courts have ordered local gateways to stop serving named pirate sites, foreign law drives those outcomes, not the US Copyright Act.

So the hook that exists is contract. Network rules bind acquirers worldwide through their license agreements, and enforcement is a business discipline rather than a legal one. That changes what your report looks like: you are persuading a bank, not serving a statutory notice.

What the Acceptable-Use Rules Actually Prohibit

All four networks prohibit merchants from illegal activity generally, and the majors layer piracy-specific provisions on top. Visa's Integrity Risk Program, the successor to its Global Brand Protection Program, treats intellectual-property piracy as a prohibited business category and requires acquirers to monitor merchants flagged under it. Mastercard's rulebook expressly addresses merchants that facilitate infringement and defines the acquirer's obligations when a credible complaint surfaces. American Express and Discover prohibit illegal merchant activity under their own merchant agreements; their enforcement is less public, but the acquirer-side mechanics are the same.

None of this is statute. It is contract, written into the agreements that let banks issue and acquire network cards. The networks, not courts, decide what counts as a violation and what happens next, and they move at banking speed, not docket speed.

One threshold concept governs the whole exercise: primary purpose. Networks act against merchants whose central business is infringement, the storefront that sells nothing but stolen courses, cracked software, or resold catalogs. A lawful marketplace with one bad listing is a different problem, handled through that platform's own removal process. Much of this apparatus was originally built for counterfeit goods rather than copyright, which is why physical-goods and digital-piracy reports often travel the same rails.

Below the networks sit the payment-service providers. Stripe and PayPal mirror card rules in their acceptable-use policies, and both maintain public channels for reporting violations. When a pirate checkout routes through one of them, the PSP form is often the fastest cutoff of all.

Reporting a Pirate Merchant at Visa, Mastercard, Amex, and Discover

You do not need to know which bank acquires the merchant. That is the quiet advantage of this lever: the network identifies the acquirer and routes your complaint into the bank's compliance queue. Your job is to file in the right places with a pack that survives an investigator's first read.

  • Visa. The network accepts merchant-violation reports through a public form on its corporate site, and complaints naming prohibited categories, piracy included, route into the Integrity Risk Program process and on to the acquirer.
  • Mastercard. Reports of rule-violating merchants go through its corporate brand-protection channel, and the network also acts on referrals from law enforcement and industry groups.
  • American Express and Discover. Public channels are thinner here. Complaints reach their merchant-review teams directly, or faster through the association route below.
  • IACC RogueBlock. The International AntiCounterfeiting Coalition runs a single intake point that forwards member reports to the major networks and to PayPal, one filing, many rails.
  • PSP abuse forms. If the checkout shows Stripe or PayPal, file their acceptable-use forms at the same time. PSPs can kill an account without waiting on anyone upstream, and the result shows up on the payment page within days.

Before filing, run your recon. Identify the storefront's host, registrar, and payment rails in one pass with a website detective tool; the general mechanics of assembling a report are the same ones covered in how to report a website.

The DMCA is a US statute whose practical force fades at the border, see does DMCA work internationally for why. Card rules are global by construction. The same report reaches an acquirer in Singapore, Cyprus, or São Paulo, which for offshore pirate merchants often makes this the only enforcement path that travels with you.

What Happens After You File: Registration, Fines, or Termination

Once a network accepts your report, it routes the complaint to the acquiring bank, and the bank investigates its merchant. Three outcomes are common. The best is termination: the account closes and the storefront's card options die. The second is high-risk registration, the merchant keeps processing but pays heavy fees, absorbs fraud liability it cannot contest, and lives under monitoring that the next complaint will trip. The third is silence, which usually means the pack was too thin to survive the acquirer's first pass.

Registration travels. A merchant flagged at network level cannot escape by re-banking elsewhere, because the registration follows it. Operators respond with transaction laundering instead, reapplying under a front company and a benign business category while selling the same stolen catalog. That is why your checkout screenshots and descriptors matter as much as your copyright proof: they tie the storefront to the payment account even when the paperwork points somewhere else.

Expect no status updates. Networks and acquirers handle these complaints internally and will not confirm outcomes to you. Read the checkout page instead. Card logos disappearing, a descriptor changing, or a sudden crypto pivot is your receipt. Buyers help too: disputes from people who realized they paid for pirated goods push a merchant's chargeback ratio up, and networks mandate action once ratios breach their thresholds.

History shows what total success looks like. Megaupload had already lost its mainstream payment processing before US prosecutors seized it in January 2012. The billing engine collapsed before the business did.

What Your Evidence Pack Must Contain

A network report is a business complaint, not a legal pleading, but it shares DNA with any takedown evidence file. Build the pack once and use it everywhere, processors, hosts, ad networks. Include these elements:

  1. Proof of ownership. Identify yourself or your company, list the infringed works, and attach dated originals plus any US registration certificates. Registration is not required to report a merchant, but it strengthens the file, and if the dispute ever reaches court, timely registration is what makes statutory damages and attorney's fees available. Timestamped creation records carry most of the weight with investigators.
  2. Exact merchant URLs. The product page for your work, the subscription or pricing page, and the checkout itself. A homepage screenshot alone gets ignored.
  3. Payment-flow evidence. Screenshots of the checkout showing which card brands appear and whether billing recurs. If you or a colleague make a small purchase, record the exact descriptor from the statement and keep your purchase records intact.
  4. A primary-purpose survey. Show that infringement is the business model: categories, bestseller lists, request boards. If the operator copied your whole site, document that too, cloning is strong proof of intent.
  5. Prior notices. Copies of any takedown or cease-and-desist you sent, with proof of delivery. A merchant that ignored notice is a merchant the acquirer cannot defend.
  6. A good-faith statement with contact details. State your authority over the works, confirm accuracy, and give the investigator a direct line to you.

Keep the file to a handful of PDF pages with a one-page summary on top: merchant URL, the rule category you believe applies, your ownership claim, and the outcome you are requesting. Do not paste a DMCA notice verbatim. The formalities of 17 U.S.C. § 512(c)(3) are for hosts. An acquirer wants a business memo.

Why Crypto-Only Pirate Sites Sit Outside This Lever

A merchant that accepts only cryptocurrency has no acquirer, no descriptor, and no network contract. The lever does not attach. No amount of documentation changes that, because there is no bank standing between the customer and the merchant to lean on. Network authority ends where the rails end.

Read that checkout as a signal, not just a dead end. Crypto-only acceptance usually means the site already lost its cards. The Pirate Bay's donation flow, for instance, turned to crypto once card acceptance disappeared. Losing rails is what pushes pirates toward crypto in the first place, evidence that this lever worked on someone before you.

On-chain tracing and exchange KYC exist, but they belong to criminal investigators and anti-money-laundering regulators, not to a civil rights holder. Your practical options run through the other channels: host and registrar abuse reports, including Cloudflare when it sits in front of the site; search demotion, since Google has lowered the rankings of sites that accumulate valid takedown notices since 2012; site-blocking orders in jurisdictions that grant them; and, for criminal-scale operations, domain seizures like the ICE actions documented elsewhere on this site.

Check the checkout again in a month, too. Plenty of self-described crypto-only sites quietly keep gift-card redemption, reseller-code storefronts, or a stray PSP button for customers who balk at wallets. Those are card rails. They are reportable.

Realistic Expectations and Where This Fits Your Enforcement Plan

Set expectations frankly. A single report with a thin pack usually produces silence. A thorough pack filed at every visible rail, network channels, PSP forms, the acquirer if you can identify it, produces motion more often than most rights holders expect, because you are offering a bank an exit from a problem it did not know it had.

This lever also compounds with the rest of an enforcement program. Subscription pirates monetize directly, so processor reports cut revenue at the source. Free-hosting pirates monetize through ads, so ad-network complaints are the parallel channel. Every valid takedown notice you file meanwhile feeds Google's demotion signal in search. Run the channels as a sequence rather than a lottery. The escalation ladder exists so your effort lands where the next dollar of damage actually flows.

Frequently Asked Questions

Can a rights holder force a card network to cut off a pirate site?

Not directly, and no US court will do it for you. After the Ninth Circuit's 2007 Perfect 10 decision, copyright claims against processors are dead ends. What you can do is invoke the network's own rules through its reporting channels. The network decides, but acquirer liability gives it strong reasons to move when your evidence is solid.

Is a network report the same thing as a DMCA takedown?

No. A DMCA notice invokes Section 512 of the Copyright Act and targets whoever hosts or links to the material. A network report invokes card-network rules and targets the merchant's ability to collect money. Different audience, different requirements, different timeline, and the same ownership evidence powers both, so the two complaints run well in parallel.

How long does a payment cutoff usually take?

Weeks to a few months, most often. Networks route your report to the acquiring bank, which investigates on its own schedule, and neither will send you status updates. Watch the merchant's checkout page instead, card logos disappearing, descriptors changing, or a sudden pivot to crypto are your confirmations. If nothing moves after six to eight weeks, refile with better evidence.

Do I need to register my copyright before reporting a merchant?

No. Network rules do not require a US registration; dated originals and proof of ownership carry most of the weight. Registration still helps. It signals seriousness to an acquirer's investigator, and if the dispute ever reaches court, timely registration is what makes statutory damages and attorney's fees available. For a catalog worth real money, register first, see whether copyright registration is worth it for your situation.

What if the pirate site only accepts cryptocurrency?

Then the payment-network lever does not attach, there is no acquirer, no descriptor, and no contract to enforce. Shift to the levers that do work: host and registrar abuse reports, search demotion, ad-network cutoffs, and site blocking where courts allow it. Check the checkout page over time, too. Many crypto-only sites quietly keep gift-card or reseller-code rails, and those are reportable.

Do This Next

  1. Capture the storefront today: product URLs, pricing page, checkout with card logos, timestamped screenshots.
  2. Build the evidence pack to the checklist above, and register your worst-hit works if US litigation might ever be in play.
  3. File at every rail you can see, the network channels, plus any PSP abuse form the checkout exposes.
  4. File the parallel complaints while you wait: host, registrar, search engines, ad networks.
  5. Watch the checkout page weekly for six to eight weeks. Change is your confirmation; silence is a cue to refile with sharper evidence.
  6. If the merchant rotates faster than you can file, bring in help. ProtectionPro pairs monitoring with escalation for ongoing infringement, our managed commercial takedown service runs campaigns end to end, and when the numbers justify it, know when to hire a copyright lawyer rather than filing forever.