Skip to main content
Back to The Mesh

My Software Has Been Cracked and Posted Online: What Do I Do First?

Found a cracked copy of your software online? This first-response playbook shows how to preserve evidence, find the real host, send the right removal notice, delist search results and verify the outcome.

If you found your software cracked online, your first goal is not to understand every part of software piracy.

Your goal is to get this copy removed. Use this sequence:

Save the evidence -> find the actual file -> identify who controls it -> send the correct notice -> delist search separately -> verify what changed.

1. Save the evidence before anything changes

Create a simple case record.

Capture:

  • the exact piracy-page URL
  • screenshots
  • your product name and the version shown
  • the visible filename
  • the uploader or seller name, if shown
  • the download or file-host link, if it is visible
  • the Google or Bing result that led you there
  • the date and time

Do not run an unknown crack just to prove it exists. A fake crack can be malware. A counterfeit installer can also create a security and brand-abuse problem.

For a normal takedown, the public page, visible file link, product match, and your ownership evidence are usually the right place to start.

2. Work out whether the page hosts the file

This is the first important fork.

A warez page may host the file itself. Or it may send the visitor to:

  • Dropbox
  • MediaFire
  • another file host
  • cloud storage
  • GitHub
  • a torrent
  • a redirect or link shortener

If the actual file sits on another service, record that URL separately. Think of the case as two objects:

Piracy page

and

Underlying file

Removing the page does not prove the file disappeared.

3. Find the provider that can remove the file

Start with the URL itself.

If the download link clearly points to Dropbox, MediaFire, GitHub, Google, or another recognizable platform, use that provider's own copyright process. If the file is hosted directly on the piracy site, identify the site operator or hosting provider.

For domain-registration information, use ICANN Lookup. Since January 2025, ICANN uses RDAP as the definitive mechanism for gTLD registration data.

Important: RDAP tells you about domain registration. It does not tell you who hosts the site.

If Cloudflare appears in DNS or IP records, do not assume Cloudflare is the origin host. Cloudflare says millions of sites use its pass-through CDN. Its abuse process asks for specific asset URLs so it can identify which service it actually provides.

If the page exposes the specific file, image, video, iframe, or storage URL in the page source, record that asset URL. Cloudflare's own guidance recommends using the browser's Inspect Element tools to identify specific asset URLs when reporting abuse.

4. Use the provider's own form when it has one

A platform form is usually better than sending a generic email.

Examples:

If the provider accepts a free-form notice, use the template below.

5. Copyable DMCA notice template

This structure contains the core information required by Section 512(c)(3)(A). Replace every bracketed field.

Copyable text
Subject: DMCA Notice of Claimed Infringement - [SOFTWARE NAME]

To: [SERVICE PROVIDER / DESIGNATED DMCA AGENT]

I am [the copyright owner / authorized to act on behalf of the copyright owner] for the work identified below.

Copyrighted work:
[Software name and short description]

Authorized example or official product URL:
[URL]

Material claimed to infringe:
[Short description of the cracked, copied, or redistributed software]

Infringing URL(s):
[Exact URL 1]
[Exact URL 2]

I request that you remove or disable access to the material identified above.

I have a good-faith belief that use of the material in the manner complained of is not authorized by the copyright owner, its agent, or the law.

The information in this notice is accurate and, under penalty of perjury, I state that I am the copyright owner or am authorized to act on behalf of the owner of an exclusive right that is allegedly infringed.

Name:
Company:
Mailing address:
Telephone:
Email:

Electronic signature:
[Full legal name]

Before sending it, confirm that the reported copy is actually unauthorized.

Do not send notices against reviews, legitimate licensees, open-source uses, or other uses you have not checked.

A provider may forward your notice to the reported user.

6. If the crack is on GitHub, use GitHub's software-specific process

Do not send GitHub a generic "this is a crack" message.

GitHub asks copyright owners to identify the protected work and the exact material that infringes it. If only part of a repository is infringing, GitHub asks for the specific files or lines.

GitHub also does not automatically disable every fork when a parent repository is removed. If forks also infringe, you need to investigate and identify them.

If the repository is mainly a licensing bypass or circumvention tool, GitHub has an additional process. It asks for technical detail about:

  • the technological protection measure
  • how it controls access
  • how the accused project circumvents it

Use GitHub's current copyright form and guide.

7. Delist the search result separately

If the piracy page appears in Google or Bing, submit a search-removal request after you have the exact source URL. Google requires the specific URL and asks you to choose the Google product and legal basis.

Bing's form similarly asks for the exact page URL, copyright-owner information, the copyrighted work, and the required statements. Do this even if you are also pursuing source removal. Search delisting and source removal are different outcomes.

8. Follow up if the provider does not act

Keep the original ticket or reference number. Use a short follow-up:

Copyable text
Subject: Follow-up - Copyright Infringement Notice Submitted [DATE]

I am following up on the copyright notice submitted on [DATE] regarding:

[URL 1]
[URL 2]

Reference or ticket number:
[REFERENCE]

The reported material remains accessible as of [DATE / TIME], or I have not yet received a substantive response.

Please confirm the current status of the report and let me know whether you require any additional information.

Name:
Company:
Email:

Do not blindly resend the same complaint to every company connected to the domain. If the first route fails, identify the next party that actually controls the page or file.

9. Watch the next software release

A crack for version 4.2 can disappear and version 4.3 can appear a week later. That is why recurring software piracy is usually a product-level problem, not a URL-level problem.

If you want to handle this manually, keep a release-level watchlist and repeat the workflow when new copies appear.

If you do not want your team doing that repeatedly, WatchMesh handles discovery, matching, enforcement, escalation, verification, and recurrence around the protected software product.

Need a current-state view first? Start a Free Evidence Audit.

Official references