Copyright Is Not the Only Risk on Piracy Sites: a Quarter of Ad Impressions Were Fraud or Malware
EUIPO monitored ads on 5,671 IPR-infringing websites through 2025. Fraud and malware ads accounted for 24.62% of estimated ad impressions, up from 14% the year before. Read alongside a WIPO committee paper and two Japanese government documents, here is what those numbers do and do not say.
On this page
- What each source counts
- A quarter of ad impressions were classified as fraud or malware
- The share rose while the total fell
- The look of a site fools automated checks too
- A "DOWNLOAD" button is not a required step
- What these four sources cannot tell you
- How one number changed between two government documents
- Where I land
- Sources

When a site offers films or comics for free, the first question is usually about copyright. For the person visiting, there is a second one: can the ads and buttons on that page be trusted? On 5 September 2026 I read four public sources on that question — one EU study, one WIPO committee paper, and two Japanese government documents.
What each source counts
The four overlap in subject and share nothing in method. They count different things, in different places, over different periods, so they cannot be added together or lined up as a trend.
| Source | What it counts | Period covered | What it cannot tell you |
|---|---|---|---|
| EUIPO ad monitoring | Ad types by estimated impressions on infringing sites | 1 Jan – 20 Nov 2025 | Infection rates, or anything outside the monitored countries |
| WIPO/ACE/18/34 | Types of malware seen on piracy services | Not stated | How often each type occurs |
| Japan, Agency for Cultural Affairs | Monthly visits to the top 20 pirate manga sites | Aug–Sep 2024 | Current traffic, or harm to visitors |
| Japan, National Police Agency | Phishing methods and countermeasures | Not stated | Anything specific to piracy sites |
A quarter of ad impressions were classified as fraud or malware
The EUIPO study Online Advertising on IPR-Infringing Websites and Apps 2025 (PDF, external site), published in June 2026, monitored 5,671 websites from 1 January to 20 November 2025 across 18 EU Member States, with the UK and US as control countries. Of those sites, 37% had been ruled illegal by judicial or administrative authorities; the other 63% are classed as high risk — confirmed as infringing and popular with EU consumers, but not (yet) designated illegal.
The wording matters more than the number.
The figure also moves depending on where you cut it.
| Group | Share of estimated ad impressions |
|---|---|
| KeyAll monitored websites | 24.62% |
| All monitored apps | 0.28% |
| Romania (highest) | 34% |
| EU median | 23% |
| US (control) | 29% |
| UK (control) | 19% |
| KeyHighest quarter (Q3) | 30% |
Websites and apps differ by a factor of about 88. Quarter to quarter, the share peaked at 30% in Q3 and fell back to 19% in Q4. A single yearly percentage hides both.
The share rose while the total fell
A rising share can come from a shrinking denominator, so it is worth checking. Estimated ad impressions across all monitored websites fell from 28.3 billion in 2024 to 23.7 billion in 2025 (both on the all-monitored-countries basis). The pool did shrink.
Multiplying the two together, though, the absolute volume rose as well: roughly 4.0 billion fraud and malware impressions in 2024 against roughly 5.8 billion in 2025. That multiplication is mine, not the report's. The report publishes shares and totals separately and does not state which impression total the ad-type percentages sit on, so I treat these as order-of-magnitude figures rather than findings.
The look of a site fools automated checks too
The same report contains a passage aimed at the advertising industry rather than at consumers. On the AI-driven brand-safety models now used to decide where ads may run:
Since these advanced models are trained to seek high-quality engagement and positive sentiment, they can be deceived by the sophisticated aesthetics of modern piracy platforms that mimic the layout and metadata of legitimate publishers.
It also describes operators running "clean" sites first to build a domain's reputation and search ranking, then switching them to piracy. This was the part I did not expect: the systems built to keep advertising away from these sites are being fooled by how the sites look, which is the same failure mode a visitor has.
Japan's National Police Agency reaches the same conclusion for a different case. Its phishing countermeasures page (external site, Japanese) states that links in email can be spoofed and that many phishing sites use domain names resembling the legitimate ones, so "judging whether a link is genuine by how it looks is extremely difficult." The same page notes that people are also lured through ads on search sites.
A "DOWNLOAD" button is not a required step
For the shape of the actual traps, the reference is The Nexus Between Malware and Piracy (PDF, external site), a paper dated 19 May 2026 for the eighteenth session of WIPO's Advisory Committee on Enforcement. Among the types it lists:
- Ransomware delivered through deceptive pop-ups, pop-unders, click-to-play, or fake download buttons on streaming and torrent sites
- Scareware that mimics system warnings to get a malicious program installed
- Trojans distributed as fake updates, media players, or installers
- Fake login and payment pages that harvest usernames, passwords, and two-factor codes
The same paper quotes figures — 12% of ads on piracy sites being malvertising, close to 80% of investigated sites serving malware-laden ads — from a separate industry report. I could not check those against the original, so they are not used here.
What these four sources cannot tell you
- Whether piracy sites are more dangerous than ordinary sites. None of the four measures a control group of mainstream sites with the same method
- The odds that a given visit ends badly. A share of ad impressions is not an infection rate
- Anything about ads on sites outside the monitored countries. The EUIPO figures cover 18 EU states plus the UK and US
- How the traffic figures below stand today. The 2026 government document gives a direction, not a number
How one number changed between two government documents
Japan's Agency for Cultural Affairs described the scale of manga piracy in a 2024 budget briefing document (PDF, external site, Japanese): visits to the top 20 pirate manga sites reached 550 million per month for Japanese-language sites and 590 million for English-language ones in September 2024, 1.14 billion combined, with estimated annual damage of JPY 2 trillion. The chart carries two data points, August and September 2024, and credits ABJ — an industry association — as the source of the counts.
Fifteen months later, the same department wrote it differently. In material for a Cabinet Secretariat working meeting (PDF, external site, Japanese) dated March 2026, the sentence became past tense — access "at one point" reached 1.14 billion per month — followed by: traffic had fallen back after a large site closed, then began rising again from the summer of 2025. No new figure is given.
The JPY 2 trillion is also narrower than it looks in the first document, where it sits directly after the manga traffic. The policy plan quoted in the second document defines it as the estimated damage across Japanese content as a whole — games, music, publishing, and video — for 2022, about five times the 2019 level. It is not an annual figure for manga piracy.
Where I land
That is the end of what the sources say. What follows is my own reading, as someone who builds small checking tools.
What stays with me after four documents is one line: what a page displays is not necessarily a step that page requires. The large DOWNLOAD button, the sudden security warning, the browser notification prompt, the extension install request, the field asking for an email address or a card number. EUIPO counts ads, so not all of those fall inside its category. Fake buttons and fake warnings, though, are the category's own description.
So when an unfamiliar screen appears, I do not click, type, or install. I close the tab, and if something needs checking, I check it through a separate route — an official site or a public agency, reached on my own rather than through a link or phone number on the page. That is the same shape of advice the National Police Agency gives for phishing.
We publish small extensions for checking links and site operators. They do not judge whether a site is safe. Finding operator details does not make a site trustworthy, and one odd signal does not make it a scam. What they can do is add a little material to look at before going ahead.
Sources
All retrieved on 5 September 2026, with every figure in this article checked against the original.
- EUIPO, "Online Advertising on IPR-Infringing Websites and Apps 2025" — Published by the European Union Intellectual Property Office, June 2026. Period: 1 January – 20 November 2025. ISBN 978-92-9156-374-6. PDF, external site. The 24.62% appears in sections 3.3.3 and 6; impression totals in section 3.1.2. © EUIPO 2026, CC BY 4.0
- WIPO/ACE/18/34, "The Nexus Between Malware and Piracy — Enforcement Tools and Opportunities for Government to Take Action" — Contribution by Dr. Elena Blobel, International Federation of the Phonographic Industry, for the eighteenth session of WIPO's Advisory Committee on Enforcement (Geneva, 2–4 June 2026). Dated 19 May 2026. PDF, external site. The views are the author's, not necessarily those of WIPO or its Member States
- Agency for Cultural Affairs, "Demonstration project for AI-based detection and analysis of pirate sites" — Reference material 8 for the second meeting of the legal systems working team, Copyright Subcommittee, 24 December 2024. Traffic counts credited to ABJ, 2024. PDF, external site, Japanese
- Agency for Cultural Affairs Copyright Division, budget briefing material, March 2026 — Document 3 for the fourth meeting of the public–private working-level liaison conference on piracy countermeasures, Cabinet Secretariat, 26 March 2026. PDF, external site, Japanese
- National Police Agency, "Phishing countermeasures" — Published by the Cyber Police Bureau. No publication or update date shown on the page. External site, Japanese
The roughly 4.0 billion and 5.8 billion impression figures are my own multiplication of published shares and totals, not values printed in the report. Translations of Japanese-language material are mine.
None of the organisations cited here endorses or guarantees any particular company's products or services. The same applies to the tools mentioned in this article.