In a significant escalation of its national anti-piracy strategy, Belgium’s Department for Combating Online Infringement (BAPO) has launched a sweeping judicial initiative aimed at the root of digital copyright theft rather than merely clipping its branches. For years, the standard playbook for combating rogue streaming platforms and pirate portals involved traditional site-blocking orders. While these measures—grounded in formal rulings by the Brussels Business Court—frequently succeeded in cutting off surface-level access for local internet subscribers, they suffered from a fatal flaw: the phenomenon of domain hopping. Operators of illegal sites routinely abandoned blocked URLs within hours, springing up on fresh domain names to frustrate rightsholders and enforcement agencies alike.
Recognizing the limitations of reactive domain-blocking, BAPO has pivoted toward a far more aggressive, forensic approach. Under a series of newly issued judicial decisions tied to orders from the French-speaking Business Court of Brussels, Belgian authorities are bypassing the whack-a-mole game of site blocking entirely. Instead, they are compelling domain name registrars and registries to unmask the individuals and entities operating illicit platforms.
The targets of these new legal maneuvers are facing an unprecedented dragnet. The courts have ordered intermediaries to hand over extensive dossiers containing not just basic contact details, but comprehensive financial footprints—including full International Bank Account Numbers (IBANs), credit card processing histories, and specific cryptocurrency wallet addresses linked to the transactions. Furthermore, registrars are being forced to scour their server logs for historical IP addresses, device fingerprints, and connection data spanning the preceding 12 months.
Yet, this massive expansion of investigative power is shrouded in legal secrecy. Backed by stringent judicial gag orders, the targeted intermediaries—which include prominent EU-based registrars like Hosting Concepts, Hostinger, and Key Systems—are strictly prohibited from notifying their customers or the public about the data handovers. While BAPO asserts that these actions are authorized under Article 10 of the European Union’s Digital Services Act (DSA) and broader Belgian civil procedure, the strategy raises profound questions about privacy, cross-border jurisdiction, transparency, and the balance between intellectual property enforcement and digital civil liberties.
Detailed Chronology: From Surface-Level Blocking to Deep De-Anonymization
To understand the weight of BAPO’s latest enforcement actions, one must examine the evolution of Belgium’s legal framework against digital piracy. Historically, rightsholders and anti-piracy bodies relied heavily on ISP-level blocking. Internet service providers were ordered to prevent their subscribers from reaching domains flagged by the Brussels Business Court. However, the operational agility of modern pirate syndicates rendered these measures largely superficial. As soon as one domain was blacklisted, automated scripts and mirror networks propagated identical content across dozens of alternative extensions.
Frustrated by this endless cycle, rightsholders—particularly those representing the lucrative sports entertainment sector—pushed for deeper, structural interventions. The turning point arrived this week with the issuance of five interconnected decisions by the French-speaking Business Court of Brussels, executed and managed by BAPO.
Rather than issuing injunctions against ISPs or Content Delivery Networks (CDNs) like Cloudflare, the court turned its attention upstream to the foundational infrastructure of the internet: domain name registrars and registries. Four of the newly released decisions are directed specifically at domain registrars, while the fifth targets a top-level domain registry that maintains direct registrant records.
Through accidental redaction oversights in the publicly released legal documents, investigators and researchers were able to identify three of the four targeted registrars:
Hosting Concepts (a major European registrar service)
Hostinger (a widely utilized international web hosting and domain registration provider)
Key Systems (a prominent domain infrastructure and registry services provider)
A fourth registrar and the primary domain name registry remain entirely redacted behind legal placeholders. Similarly, the specific domain names targeted by the court orders and the identity of the rightsholders who initiated the proceedings are strictly suppressed. BAPO has maintained that this cloak of secrecy was mandated directly by the court, explaining that the judge ordered the disclosure of information explicitly to enable the plaintiff to identify the infringers and conduct clandestine preliminary investigations without tipping off the suspects.
Despite the lack of public transparency regarding the exact targets, the legal reasoning embedded in the court orders leaves little room for interpretation. The documentation explicitly emphasizes the necessity of preserving "the sports economy and the European solidarity model"—a phrase that points directly at the multi-billion-dollar ecosystem of live sports broadcasting rights, which remains one of the primary targets for aggressive commercial piracy syndicates operating across Europe.
Supporting Context & Metrics: The Anatomy of a Comprehensive Data Sweep
The scope of information demanded by the Brussels Business Court is staggering in its depth and granularity. Far exceeding the standard parameters of civil discovery, the four registrar decisions mandate the immediate handover of seven distinct categories of customer data. This multi-layered demand is designed to eliminate any possibility of anonymity, mapping out both the digital footprint and the physical and financial existence of the site operators.
1. Identity and Contact Records
Intermediaries must compile and surrender every piece of identifying data ever associated with the target account. This includes:
The legal name or registered corporate identity of the account holder.
Every physical postal address linked to the profile, past and present.
All email addresses utilized for registration, communication, or billing.
Every telephone number recorded on the account.
2. Traditional Financial Instruments
Recognizing that commercial pirate operations are financially motivated enterprises, the court orders demand absolute transparency regarding fiat revenue streams. Registrars must provide:
Full International Bank Account Numbers (IBANs).
The exact legal names of the holders of all relevant bank accounts linked to subscription, hosting, or domain fees.
Comprehensive credit and debit card details, including the issuing bank, the country of origin, and the specific card type used.
3. Cryptocurrency Transactions
In response to the growing reliance of illicit streaming and downloading networks on decentralized finance, the orders explicitly sweep up digital asset trails. Intermediaries are compelled to disclose:
All means of payment executed via crypto-assets.
Specific public cryptocurrency wallet addresses used by the account holders.
The exact type of crypto-assets involved (e.g., Bitcoin, Monero, Ethereum).
Transaction identifiers, commonly known as hash IDs, enabling blockchain forensic tracing.
4. Technical Logs and Device Fingerprints
Beyond static registration data, the court demands dynamic operational histories. Registrars must review and export internal server logs to uncover:
The original IP addresses used when the account was created and accessed.
Device types, operating systems, and specific web browsers utilized by the operators.
All connection data and server logs retained by the intermediary concerning the use of the customer account over a mandatory lookback window of the last twelve (12) months.
In contrast to the exhaustive demands placed on the four registrars, the fifth decision—directed at the anonymous domain name registry—is slightly more focused. It requires the surrender of direct registrant records, the exact identity of the registrar managing the domain, active nameservers, and a complete historical timeline of all administrative changes made to the domain settings.
The Brussels Business Court concluded that these sweeping demands are fully proportionate under European legal standards, setting the stage for BAPO to enforce compliance across the board.
Official Statements and Legal Contradictions: The DSA and the Gag Order
One of the most legally contentious aspects of BAPO’s latest initiative is the enforcement of a strict gag order prohibiting the intermediaries from notifying their customers or the public about the information requests.
Under normal circumstances, the European Union’s Digital Services Act (DSA) establishes rigorous transparency and consumer rights safeguards. Specifically, the DSA generally mandates that online intermediaries notify affected users when their personal data or account records are handed over to law enforcement or private litigants. This notification requirement is designed to ensure due process, allowing individuals the opportunity to challenge unlawful overreaches of state or private investigative power.
However, BAPO has invoked a specialized exception embedded within the regulatory framework: provisions exempting notification requirements when criminal investigations, national security, or the prevention and prosecution of serious criminal offenses are actively at stake. By framing the unauthorized commercial exploitation of copyrighted material as an activity crossing into systemic organized criminality, authorities have justified bypassing the standard DSA user-notification protocols.
Consequently, the targeted site operators remain entirely oblivious to the fact that their identities, banking histories, and connection logs have been quietly vacuumed up and delivered to rightsholders.
The cross-border enforceability of these orders also enters uncharted legal territory. BAPO’s operational mandate is strictly rooted in Belgian national law. Yet, all the identified intermediaries—Hosting Concepts, Hostinger, and Key Systems—are based outside of Belgium within other member states of the European Union.
When questioned about potential jurisdictional hurdles, BAPO adopted an exceptionally aggressive legal stance. Representatives told TorrentFreak that the court orders are not even inherently restricted to the borders of the European Union. Citing a combination of Belgian civil procedure rules and the overarching principles of the DSA, BAPO asserted:
"Every intermediary whose service is being used to give access to illegal content within the Belgian territory can be ordered to disclose information regarding its customer."
This assertion represents a remarkably broad interpretation of extraterritorial jurisdiction. If upheld and successfully executed, it establishes a precedent where a national IP enforcement agency can command foreign technology companies to perform deep forensic audits on accounts worldwide, provided those accounts connect in any way to digital traffic crossing Belgian cyberspace. Legal scholars note that this expansive interpretation has yet to be thoroughly tested in higher European appellate courts, leaving its long-term viability uncertain.
Future Outlook: Implications for Privacy, Intermediaries, and Digital Enforcement
The implications of BAPO’s aggressive new strategy extend far beyond the borders of Belgium, signaling a potential shift in how European nations combat digital piracy. For years, rightsholders have argued that blocking a website is akin to locking a door while leaving the key in the ignition. By shifting the enforcement mechanism from domain blocking to deep de-anonymization, Belgian authorities are attempting to strike at the personal and financial incentives driving commercial piracy operations.
However, this strategy introduces significant systemic risks and legal friction points:
The Erosion of Intermediary Neutrality: Domain registrars and registries historically position themselves as neutral utility providers. Compelling them to act as forensic extensions of copyright enforcement bodies risks transforming them into policing agents, increasing operational compliance costs and exposing them to cross-border legal conflicts.
Privacy and Due Process Concerns: The combination of sweeping financial data harvesting (including cryptocurrency transaction tracing) and absolute secrecy via judicial gag orders strips individuals of basic due process rights. While exceptions exist for criminal investigations, applying these exemptions broadly in civil copyright enforcement cases sets a controversial precedent for digital privacy rights under the DSA.
Jurisdictional Friction within the EU: BAPO’s claim that Belgian courts hold universal jurisdiction over any EU-based registrar servicing traffic in Belgium will inevitably face pushback from data protection authorities and courts in other member states, particularly regarding conflicting national interpretations of the GDPR and the DSA.
As these five decisions move into the implementation phase, the public and the press remain locked out of the details due to the absolute gag orders imposed by the Brussels court. Whether Hosting Concepts, Hostinger, Key Systems, and the unnamed registry will fully comply, and whether those data handovers will successfully translate into actionable criminal prosecutions or civil lawsuits against pirate operators, remains to be seen.
What is certain, however, is that Belgium has raised the stakes in the war on digital piracy. The era of relying solely on whack-a-mole domain blocking is giving way to an era of aggressive, cross-border financial and digital forensics—forever altering the landscape of online copyright enforcement in Europe.