Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

I went to prison for internet piracy and hacking; my FBI profiler sent me a message on LinkedIn when I got out, and now we’re presenting at SLEUTHCON. I'm Josh Brody and I ran HeheStreams: AMA.

0
Medium
Security-newscybersecurityreddit
Published: Wed May 27 2026 (05/27/2026, 14:41:29 UTC)
Source: Reddit Cybersecurity

Description

This content is a personal account from Josh Brody, who ran a sports piracy streaming site called HeheStreams from 2016 to 2021. The site used officially licensed platforms' DRM and CDNs to deliver unauthorized streams. Brody was charged under the CFAA and other laws, served prison time, and has since connected with an FBI profiler involved in his case. They are now co-presenting at SLEUTHCON to discuss the characterization of operators like him and the broader implications of media and law enforcement narratives. The post does not describe a specific technical vulnerability or active threat but rather shares an experiential narrative related to cybercrime prosecution and media portrayal.

Reddit Discussion

r/cybersecurity·posted by u/joshdotmn
00

From 2016 to 2021 I ran HeheStreams, a sports piracy streaming site.

The technical model was unusual: it used officially licensed platforms' DRM and CDNs to power my site. I had unauthorized syndication rights from a couple different streaming platforms. All this ran on a $75 VPS, as a boring Ruby on Rails app.

Because the streams came from upstream providers, I lived or died by their API availability. To not get banned, my abuse detection had to be better than theirs—which conveniently also kept guys like me out of my own site. I'd already beaten their detection repeatedly, so I had a good idea of what to build. I was both cat and mouse.

It was good enough to bust a few people, including an executive-level security employee from one of the platforms I used. I feature-flagged the hell out of his account.

I wasn't pushing out ghetto-ass restreams, and I certainly wasn't piping OBS to Cloudflare like so many did then and still do now. That would have been easier.

Instead, the platforms' own CDNs delivered the streams; it was very nice of them. I'm grateful they let me use their Akamai, CloudFront, and Fastly contracts for five years.

SDNY charged me in October 2021 for running HeheStreams, three months after it was shut down by MPAA: CFAA, wire fraud, and illicit digital transmission (a law snuck into the CARES act). I was also charged with extortion and interstate threats based on my autistic-ass replying on brand when making a bug report.

I pleaded guilty under CFAA and served eighteen months at FCI Thomson: best known for four-point restraints applied for days at a time, and inmate deaths during 24/7 lockdowns that were never ruled suicides.

I was released from prison in August of 2025. Not long after, later I got a strange message on LinkedIn from a dude who said he worked on my case. In a panic, I consulted my therapist/PR/lawyer friend, ChatGPT.

In a few weeks, I'm co-presenting at SLEUTHCON with Tim Pappa—a former FBI agent of 16 years and a senior analyst in the Bureau's Behavioral Analysis Unit. He was assigned to build the profile used in the undercover operation against me. Not that they needed one—they could have just asked me what I did for a hobby. I would have opened with "well, I have this little streaming website."

The talk argues that characterizations of operators like me get built across a pipeline of analysts, reporters, and vendors that no one in the chain is incentivized to slow down.

I now call Tim my "FBI profiler friend."

Happy to talk about:

  • How CFAA cases get built and the role of media characterization
  • My boring-ass Ruby on Rails app
  • Working with my FBI profiler post-release
  • Platform abuse patterns in streaming and beyond
  • Federal prison, and what it looks like when you don't fit any of the boxes of the pre-determined political climate

Really, really not going to discuss:

  • Anything beyond what's already public
  • The specifics of the bugs I found
  • Recipes—you know, the technical ones
  • Anything that intersects with the terms of my supervised release

I'll be live from 10:30 AM Eastern through the evening.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/27/2026, 14:48:35 UTC

Technical Analysis

Josh Brody operated HeheStreams, a sports piracy site leveraging licensed platforms' DRM and CDN infrastructure, from 2016 until its shutdown in 2021. He was charged with CFAA violations, wire fraud, and illicit digital transmission, pleading guilty and serving 18 months in federal prison. Post-release, he connected with an FBI profiler who worked on his case, and they are jointly presenting at SLEUTHCON about the pipeline of characterization and profiling in cybercrime cases. The content is a retrospective personal narrative and does not detail any new or ongoing security vulnerabilities or exploits.

Potential Impact

There is no direct security impact or active vulnerability described. The content relates to past criminal activity involving unauthorized streaming and legal consequences. No ongoing threat or exploit is indicated.

Mitigation Recommendations

No mitigation or patching is applicable as this is not a technical vulnerability or active security threat. The content is informational and experiential in nature.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Source Type
reddit
Subreddit
cybersecurity
Reddit Score
0
Discussion Level
minimal
Content Source
reddit_link_post
Post Type
link
Domain
null
Newsworthiness Assessment
{"score":27,"reasons":["external_link","established_author","very_recent"],"isNewsworthy":true,"foundNewsworthy":[],"foundNonNewsworthy":[]}
Has External Source
true
Trusted Domain
false

Threat ID: 6a17043ae29bf47b50c51fbc

Added to database: 5/27/2026, 2:48:26 PM

Last enriched: 5/27/2026, 2:48:35 PM

Last updated: 5/27/2026, 9:38:10 PM

Views: 8

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses