Dear suppliers, somebody is filing fake DMCA takedowns in your names
As fraudulent DMCA strikes become more prevalent in the affiliate space, Hassan Boussalem, founder and CEO of MoveUp Media, recounts his story of identifying fake complaints filed in the names of B2B suppliers who certainly never sent them and urges the industry to act on them.
In June, Google started removing our pages from search. Not a core update, not a manual action, not a mistake on our side. Someone had filled in a web form.
I run a group doing 150 million monthly visits across sport and iGaming in 25 markets. I have seen algorithm updates wipe out categories overnight. But this was worse, because there was no algorithm to blame and nothing to fix.
So we pulled our own file from the Lumen Database, the public archive of the notices Google receives, and built a tracker. What came back was not an incident. It was a campaign, running under the names of companies you deal with every week.
One notice, in full
A complaint arrived against /it/betsson-app, our Italian review of the Betsson app. It stated that "multiple pages on your platform reproduce copyrighted material belonging to SOFTSWISS, an iGaming technology provider" and demanded immediate removal.
SOFTSWISS powers hundreds of brands. If SOFTSWISS thought we had copied its material, that would be a conversation worth having.
It was not filed by SOFTSWISS. It was filed by an individual named "Nathan Pena" from Iraq. He had no stated organisation and no connection to the company whose rights he claimed to defend. The compliant identified no specific work, which alone marked it as fraudulent: a real rights holder can always point at the thing they own.
We were not singled out. We were collateral in an industrial operation, and the only reason it reached us is that we ranked
Then we looked at what else was bundled into the same complaint. Alongside our page, it asked Google to remove www.betsson.com, Betsson's own official website, in a notice filed in the name of a platform provider who serves operators exactly like Betsson. Also listed were Betsson’s app pages on Softonic and Uptodown. Whoever sent this was not protecting copyright. They were clearing every result on the search page for "betsson app", and our review happened to be one of them.
We were not singled out. We were collateral in an industrial operation, and the only reason it reached us is that we ranked.
What 17 notices look like
Our tracker now holds 17 notices, of which 16 were filed against theplayoffs.news, one was filed against toffeeweb.com, and 13 were actioned on 20 June.
The pattern stuck out. Each was filed by an individual with an anglophone name from a jurisdiction with no plausible link to the claimed rights holder: Iraq, Zimbabwe, Algeria, Turks and Caicos, Saint Vincent. Each invoked a real B2B supplier in our industry: SOFTSWISS, Thunderkick, Spinomenal, EveryMatrix, Ezugi, Hub88, Pronet Gaming, Sirplay, Aristocrat Interactive, Innosoft Group, Four Leaf Gaming, GR8 Tech. Each targeted commercial pages across every locale we ran, from casino and app reviews to promo codes and match predictions.
Each targeted commercial pages across every locale we ran, from casino and app reviews to promo codes and match predictions
And each bundled our URL with unrelated domains, which is where the fraud became visible. The notice filed for Thunderkick, a Swedish slot studio, also targeted a Chilean spa and theatlantic.com. The one filed for Four Leaf Gaming targeted Deadspin and an Indian state government domain. The one filed for GR8 Tech targets paypal.com. A generic complaint written in Polish lists AccuWeather and kick.com, which the same notice also names as the original work being infringed.
A slot studio asserting copyright over The Atlantic. A notice where one domain was simultaneously the victim and the thief. A betting software supplier claiming ownership of an Everton match report on our football site. This is what is currently sufficient to remove a page from Google.
One more piece of proof. Instead of assuming, we went to Crown Coins Casino directly to verify the notice filed on behalf of Four Leaf Gaming against our review. The team confirmed it did not partner with Four Leaf Gaming at all, meaning the relationship the complaint depended on did not exist.
The suppliers are victims too
I want to be unambiguous, because it matters.
I do not believe for a second that SOFTSWISS, Thunderkick, EveryMatrix, GR8 Tech or any other supplier named in these notices sent them. Every sign says the opposite: fabricated senders in unrelated countries, targets that make no commercial sense for the companies named and demands to remove their own clients' websites. A coordinated fake DMCA campaign impersonating B2B iGaming providers was reported publicly in Google's own Search Central community in April.
These companies are being impersonated because a takedown carrying a recognised industry name gets processed with less friction than one from nobody. Their reputations are being spent without their knowledge.
Impersonated suppliers have an identifiable brand being misused, lawyers already on retainer and standing that does not depend on copyright
However, suppliers have unique leverage that most others do not possess. Affiliates chasing an anonymous filer through §512(f) are wasting their time – the bar is high, almost no claim has ever succeeded, and good luck serving "Nathan Pena" in Iraq. But impersonated suppliers have an identifiable brand being misused, lawyers already on retainer and standing that does not depend on copyright.
So log every name you see abused, and tell the company concerned. That is worth more than filing your counter-notice quietly and moving on.
67 days
This is the number of days that changed how we work.
The claim against our Swiss casino review is dated 20 April. Google acted on it and told us on 26 June. There were only 67 days between the accusation and the consequence.
Google's notification did not pretend otherwise. It said the site "allegedly infringes", that Google's policy is to remove content when a rights holder "alleges that a use is infringing" and that it was therefore "in the process of removing the reported content from Google Search results for users globally". An allegation is the entire standard. The same email added that it could take several weeks for the notice to appear on Lumen.
That tells you exactly what Search Console is and is not. Google did email us, so this is not a story about it staying silent. It is a story about when the email arrived: at the execution, not at the indictment. By then, the page was already disappearing. Add the gap Pedro Dias has documented, where attackers file against URL variants and parameterised versions that Search Console never surfaces, and the alerting is both late and incomplete.
Google did email us, so this is not a story about it staying silent. It is a story about when the email arrived: at the execution, not at the indictment
The counter-notice does not close that gap either. Restoration takes 10 to 14 business days by statute, and filing means consenting to the jurisdiction of a US federal court and handing your name and address to the person who attacked you. Plenty of smaller operators look at that and quietly write the page off. The attack works because of that decision, not in spite of it.
So the whole game lies in the window between the claim reaching Google and Google acting on it. In our case, that window lasted more than two months, and the claim remained public the entire time.
What we are building
We stopped treating this as a legal nuisance and started treating it as an attack surface. With over 40 sites, manual checking was never an option, so we are building the monitoring in-house. The components matter more than our implementation, and you can put all of them in place this quarter.
Daily Lumen scanning on every domain, capturing the notice ID and every targeted URL automatically, because you need both to appeal and you do not want to transcribe them by hand. Start manually today: search lumendatabase.org for your domains before you finish reading this.
Coverage of URL variants, not just canonical URLs. One of the URLs filed against us carried a utm_source=chatgpt.com parameter, which only existed because an AI assistant cited the page and someone clicked through. Whoever did this appears to be harvesting the URLs that AI assistants surface. In a year, the whole industry will be optimising for AI citations, so this is important.
Deindexation as a daily KPI, not traffic. Traffic dashboards are lagging and they blend the signal into ordinary volatility. A page is either indexed or it is not.
Alerts into Slack and a pre-filled appeal. A detection nobody reads is not a detection, and detection speed is worthless if the response still takes a week to assemble.
Proof of authorship at publish time, plus a page snapshot before anyone edits anything. Attackers are known to republish an article, backdate it, then claim your original is the copy. On paper, they have a timestamp, and you do not.
A notice log with a memory: claimant, date, URLs, outcome, restoration date, then keep watching that URL for 60 days, because repeat counter-notices often get rejected as duplicates and stacked complaints turn a two-week problem into a two-month one.
One honest note. We are building the system because owning over 40 sites makes it essential. But most people reading this do not need to monitor so many portals. The market has caught up: DMCABoss, founded by Ivana Flynn and Daniel Lux, for example, offers a service close to this specification. While I have no commercial relationship with the company, I am telling you this type of product exists, because the failure I want you to avoid is deciding there is too much engineering involved and doing nothing. If you have three sites, buy something. If you have three hundred, build it.
The question is not whether you have been hit. It is whether you would know and how long you have
The uncomfortable part
What stays with me is not that we were attacked. It is what the attack was wearing.
Somebody worked out that the fastest way to remove a competitor from Google was to borrow the name of a company the competitor’s entire industry respected, file from a country nobody would check and let a system built to protect creators do the rest. Our pages were collateral. A dozen suppliers’ reputations were the instrument.
So the question is not whether you have been hit. It is whether you would know and how long you have. Search the Lumen Database for your domains. It is free and takes an afternoon. We found 17 notices across two of our assets, filed under names that had nothing to do with them, and every one had been sitting in public for two months before Google acted on it.
