leaks, illegal re-streaming, signal hijacking and content manipulation to name a few. As networks scale up, so too do potential vulnerabilities in the supply chain. Protecting content today means firming up those weak spots – and basic encryption is no longer enough. Lessons learned In 2017, HBO faced two simultaneous leaks, in which unreleased Game of Thrones episodes (the network’s flagship series, then at its peak popularity) became temporarily, publicly available. One leak stemmed from an external attack on HBO’s servers, where those responsible demanded millions of dollars in bitcoin; the other was a result of pure human error, where HBO Nordic and HBO España accidentally uploaded an episode of the show days ahead of schedule. Then, in 2024, the same thing happened with several Netflix, Crunchyroll and Amazon Prime Video series (including Squid Game , an international phenomenon, originally filmed in Korean). This time, there was no direct hack; the breach
occurred via Iyuno, a third-party localisation, subtitling and dubbing vendor that had been handling various streaming titles. While there are plenty of other examples out there, these alone demonstrate how a data breach happens – and how no two look the same. Modern attacks exploit whatever they can, whether it’s lodging ransomware on HBO’s media servers or targeting a third- party supplier. These events have served as learning experiences for cybersecurity specialists. “The worst-case scenario is no longer that someone breaks the encryption; it’s that a legitimate playback session is stolen and shared at scale,” states James Hynard, business development manager – content distribution and security at Castlabs. “That’s why the industry needs to think beyond traditional DRM” – short for digital rights management, which is designed to prevent piracy. “Protecting the encryption key remains essential, but we also need to protect the delivery session itself,” Hynard adds.
Powered by FlippingBook