Netflix sued for $105M after unencrypted DCP of unreleased movie is stolen

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Leo Enticknap
    Film God
    • Jan 2020
    • 3572
    • Loma Linda, CA

    #1

    Netflix sued for $105M after unencrypted DCP of unreleased movie is stolen

    Here

    Netflix Sued for $105 Million After Hard Drive of Unreleased Nicholas Cage Movie Stolen

    By Paul Bois | 31 Jul 2026

    The streaming conglomerate Netflix has been slapped with a $105 million lawsuit after the hard drive for an unreleased Nicholas Cage movie was stolen from his office.

    Filed Thursday in California federal court, the lawsuit from writer/producer Simon Afram and his company, Op-Fortitude, alleged that Netflix stifled “the sale of the World War II spy thriller by losing a copy of the movie that was shared for screening,” per The Hollywood Reporter (THR).

    Netflix executives first expressed interest in purchasing Fortitude after receiving promotional materials in December 2025, requesting a working cut in June. According to the lawsuit, Netflix instructed the filmmakers to provide the key to what’s called a digital cinema package — a vehicle through which films are delivered for screening that limits unauthorized access — so the company could internally test the movie.

    On June 15, a producer for Fortitude hand-delivered the drive to Netflix’s office at Sunset Bronson Studios. The producer allegedly told Netflix that the DCP was unencrypted and instructed the company to delete the files after the screening before notifying him when the drive was ready to be picked up.

    Ten days later, a Netflix executive disclosed that it was stolen, according to the complaint.

    A source confirmed to THR it was an unencrypted master copy of the film, titled Fortitude, that was one of several drives stolen from Netflix’s office last month.


    Netflix disputed the claim in a statement.

    “Netflix disputes any claim that it bears the risk of loss for a film delivered without the proper industry-standard safeguards,” a company spokesperson said in a statement. “While we do not own the rights to Fortitude, we take content security seriously and have taken extra measures to support the filmmaker and his team. This includes conducting a thorough investigation and offering to monitor known piracy sites for any unauthorized distribution or sale.”

    In an email dated June 25, Sean Berney, Netflix’s head of film acquisitions, said that that “someone stole a good amount of drives from our office desks this past week.”

    “We’ve been working through this with out security teams to no luck. Our piracy teams are on high alert with the breach and will monitor,” Berney added in the email.

    The lawsuit seeks $105 million in damages, alleging that Netflix did not disclosed if it filed a police report to investigate the alleged theft. Netflix, however, said it refused to share details of the investigation after Afram demanded $165 million for the movie in a “hostile attempt to extort money.”

    Due to the theft, the lawsuit claims that the sale of the film has been tampered since producers would have to disclose the theft to distributors.​
    I can imagine exactly how this happened. They'd had trouble with KDMs in the past (maybe the studio had the wrong certificates after a media block swap in the screening room, the person running the screening room wasn't well trained and didn't know how to handle KDMs, confusion over multiple CPL versions on the same drive, etc. etc.), the studio wanted the time suck to end, and so just shipped an unencrypted drive to make the nagging stop.

    The claim that there were multiple drive thefts says to me that this was a regular occurrence, and that probably quite a lot of content has leaked by this route.

    It'll be interesting to see how the lawsuit plays out. If the studio provided an unencrypted DCP drive without Netflix specifically having asked for it to be unencrypted, that is a significant mitigating factor in their defense in that it reduces the extent of primary assumption of the risk. If they did actually ask for an unencrypted copy, then they took on most if not all of that risk, and full responsibility for securing the content while it was in their facility. In other words, it'll come down to who actively made the decision not to use available content safeguarding technology (encrypting the DCP).

    I would be willing to bet as the reverberations from this incident spread, I will receive more calls for help from screening rooms that are having trouble unlocking encrypted DCPs, especially ones that don't play DCI content often (college campuses, residence theaters, etc.).
    Last edited by Leo Enticknap; 08-01-2026, 01:08 PM.
  • Marcel Birgelen
    Film God
    • Jan 2020
    • 3619
    • Maastricht, NL

    #2
    Maybe this is all just a setup to get some free media attention to a Nicolas Cage movie... just like those "AI horror stories" we hear lately, where Model X has inadvertently hacked company Y or where model Z is soooo powerful, it cannot be unleashed to the public...

    Comment

    • Frank Cox
      Film God
      • Jan 2020
      • 2314
      • Melville Saskatchewan

      #3
      Like Batgirl and whatnot, perhaps it's worth more as a write-off or a lawsuit.

      Comment

      • Marco Giustini
        Film God
        • Jan 2020
        • 1169
        • Reading, UK

        #4
        I cannot believe an unreleased version of a movie is made as unencrypted DCP and just shipped somewhere. I MIGHT understand if it's personally carried by someone who is also carrying it back to where it belongs.

        Comment

        • Misha Aranyshev
          Newbie
          • Jun 2026
          • 8
          • Santa Monica, California, USA

          #5
          It is unlikely a DCP. It is probably a QT movie. Watermarked QT on a password–locked hard drive is a normal practice for sending the screeners around. The issue is Netflix allegedly asked for an unlocked hard drive.

          Comment

          • Jim Cassedy
            Film God
            • Jan 2020
            • 1450
            • San Francisco

            #6
            There were a couple of times that I did advance industry screenings for an unreleased
            titles The (unencrypted) drive arrived with a security team, and there were strict instructions
            that no one aside from myself was allowed in the booth once the DCP was handed over to
            me. At first they wanted one of the security people to sit in the booth with me, but my boss
            managed to talk them out of that, however I was to leave the door unlocked and they had
            permission to pop in, unannounced, at any time. They also did a 'sweep' of the booth for any
            cameras, and asked me if I'd open my shoulder-bag so they could just see there wasn't a
            camera in there, and I was OK with that. After the screening, the same security team took
            the CRU with them, and gave me a receipt​. At Dolby, I did a couple of screenings from
            master DCDM drives. The DCDM files were huge because they were not compressed.
            They were also unecrypted. The CRU drives themselves looked like regular DCP drives,
            but the plastic 'end' was a bright orange~ish red color, if my memory is correct. They got
            put into a server that looked exactly like a DSS-200. except the face-plate on the front was
            the same odd color as the DCDM drives. I was told you couldn't put a regular DCP into the
            DCDM server, and vice-versa, but I never tried. The DCDM CRU drives had chain-of-custody
            paperwork to track everyone who handled the drive.

            Comment

            • Mark Gulbrandsen
              Film God
              • Jan 2020
              • 3093
              • Nashville, TN

              #7
              I age with Jim... It's very likely a copy used for test screenings...

              They are also often called "Screeners"...
              Last edited by Mark Gulbrandsen; 08-02-2026, 07:00 PM.

              Comment

              • Leo Enticknap
                Film God
                • Jan 2020
                • 3572
                • Loma Linda, CA

                #8
                Originally posted by Misha Aranyshev
                It is unlikely a DCP. It is probably a QT movie.
                The article contains enough correct use of the terminology (e.g. it makes the distinction between an encrypted and an unencrypted DCP) for me to believe it. It doesn't get any of the basic facts wrong, which movie critics with little technical knowledge writing about technical topics, combined with sources who don't fully understand the technology themselves, tend to do. Added to which, two points:

                - I have been in situations, both as a projectionist and later as a DCI cinema field tech, in which problems unlocking movies for special screenings were eventually resolved by the content owner providing an unencrypted copy, for me to believe that this account is plausible, and

                - This journalist who wrote the article (Paul Bois) appears to have good sources. A couple of years ago, he reported on a controversy in which an anniversary re-release of a 1970s classic was supplied as a DCP for a festival premiere, in which a scene containing some problematic dialogue (specifically, the n-word) had been cut. I know the projectionist who worked that show, discussed it with her, and was told that all the factual claims in Bois's article regarding that screening were correct.

                For both of these reasons, I'm inclined to believe that this likely was an unencrypted DCP.
                Last edited by Leo Enticknap; 08-02-2026, 10:05 PM.

                Comment

                • Stefan Scholz
                  Pro Film Handler
                  • Jan 2020
                  • 298
                  • Berlin Germany

                  #9
                  I saw this often enough, at least in the earlier times of DCP use. Festivals or non official pre screening came on as an unencrypted file set.
                  I have no pity for anyone. Similar case, when I share a photo online, I have in practice lost my right on it. Yes, you can sue, but, it's my personal fault.
                  Going back to the film disk. No need to steal it, just copy it from the IMS to your disk before deleting. So none notices.
                  Last edited by Stefan Scholz; 08-03-2026, 02:08 AM.

                  Comment

                  • Leo Enticknap
                    Film God
                    • Jan 2020
                    • 3572
                    • Loma Linda, CA

                    #10
                    Which would suggest that it isn't a criminal mastermind doing this, but rather an opportunist - maybe a janitor. Wouldn't be surprised if the drive appears on Ebay.

                    Comment

                    • Ryan Gallagher
                      Film God
                      • Nov 2022
                      • 2855
                      • Austin, Texas, USA

                      #11
                      Some intern probably thought it looked cool and snagged it to store their games or memes on, probably wiped it as soon as they got home being oblivious to it's original purpose.

                      Comment

                      • Frank Cox
                        Film God
                        • Jan 2020
                        • 2314
                        • Melville Saskatchewan

                        #12
                        Exactly that happened here in 2003.



                        Thousands of Canadians across the country are being cautioned that a computer hard drive missing for two weeks from a Regina office contains their personal data.
                        Saskatchewan government officials fear the data could be misused.

                        Among its files, the hard drive contained information on clients of the Co-operators Life Insurance Co. and the Saskatchewan Workers' Compensation Board.

                        The hard drive belonged to ISM Canada, a computer and management company that has a contract with the government of Saskatchewan. It was either lost or stolen from the company's Regina office on Jan. 16.​
                        The 32gb hard drive was recovered by the police a month later having been stolen by an employee who wanted to use the hardware for his own personal stuff. The data that was originally stored on it was actually of no interest to him.

                        Comment

                        • Leo Enticknap
                          Film God
                          • Jan 2020
                          • 3572
                          • Loma Linda, CA

                          #13
                          Originally posted by Ryan Gallagher
                          Some intern probably thought it looked cool and snagged it to store their games or memes on, probably wiped it as soon as they got home being oblivious to it's original purpose.
                          In which case the challenge for Netflix will be to prove that this is what happened, that the content was not exploited for financial gain, and that it now cannot be.

                          I don't know if this is the case in California law specifically, but in most civil tort systems, three things have to be proven in this sort of case (negligence):

                          - That the plaintiff owed the defendant a duty of care
                          - That the plaintiff failed in that duty
                          - That the defendant suffered loss or damage as a direct result.

                          This first of those is at the very least mitigated if it was the plaintiff's decision to supply the movie in an unencrypted form, and that there was no request by the defendant for this. The second depends on the first (the duty of care involved in protecting a $105m movie is somewhat higher than that of a $100 drive). If the thief made no attempt to monetize the content on the drive, then the third is limited to the loss of a $100 drive, which doesn't exactly justify a $105m claim.

                          Of course this'll almost certainly be settled by a bunch of lanyard-wearing attorneys making $1,500 an hour in a conference room full of plastic shrubs in a high rise in Beverly Hills long before it would have gone before a judge and jury, and we'll never get to read about any of the details. But it's an interesting scenario, at any rate.
                          Last edited by Leo Enticknap; 08-04-2026, 08:21 AM.

                          Comment

                          • Ryan Gallagher
                            Film God
                            • Nov 2022
                            • 2855
                            • Austin, Texas, USA

                            #14
                            Originally posted by Leo Enticknap

                            In which case the challenge for Netflix will be to prove that this is what happened, that the content was not exploited for financial gain, and that it now cannot be.

                            I don't know if this is the case in California law specifically, but in most civil tort systems, three things have to be proven in this sort of case (negligence):

                            - That the plaintiff owed the defendant a duty of care
                            - That the plaintiff failed in that duty
                            - That the defendant suffered loss or damage as a direct result.

                            This first of those is at the very least mitigated if it was the plaintiff's decision to supply the movie in an unencrypted form, and that there was no request by the defendant for this. The second depends on the first (the duty of care involved in protecting a $105m movie is somewhat higher than that of a $100 drive). If the thief made no attempt to monetize the content on the drive, then the third is limited to the loss of a $100 drive, which doesn't exactly justify a $105m claim.

                            Of course this'll almost certainly be settled by a bunch of lanyard-wearing attorneys making $1,500 an hour in a conference room full of plastic shrubs in a high rise in Beverly Hills long before it would have gone before a judge and jury, and we'll never get to read about any of the details. But it's an interesting scenario, at any rate.
                            This is all an unspoken danger of moving to more and more "commodity/consumer" type drives... A CRU, even though the drive within is just a regular HDD, they give the appearance of less utility to the average consumer/passerby, lacking a system to plug them into. One we are passing around high capacity USB sticks or expensive high performing NVME/NAND type drives that are easily recognizable as the same as consumer ones... the risk of such unintentional major theft, by way of petty theft increases dramatically.

                            Comment

                            • Leo Enticknap
                              Film God
                              • Jan 2020
                              • 3572
                              • Loma Linda, CA

                              #15
                              Another report confirms that the media involved was an unencrypted DCP drive.

                              Billionaire suing Netflix for $105M over stolen Nicolas Cage movie hits streamer with bombshell defamation suit
                              Published Aug. 4, 2026, 5:14 p.m. ET

                              The case of the missing Nicolas Cage movie just took another twist.

                              The writer, producer and financier of the unreleased $45 million film that was stolen from Netflix’s Hollywood headquarters in June is now suing the streaming giant for defamation, too.

                              Writer-producer Simon Afram filed an amended complaint in federal court on Tuesday, citing a statement made to the press by Netflix that accused the law firms representing the Swiss billionaire of extortion.

                              Page Six Hollywood was first to tell you last week that Afram filed a bombshell breach-of-contract lawsuit against Netflix, claiming that the studio “recklessly, carelessly, and negligently [failed] to protect the confidentiality and security” of a master copy of the film “Fortitude” — which was stolen from its offices when some hard drives were swiped, court papers allege.

                              At the time, Netflix provided us with a lengthy statement that included the following sentence: “We have declined to share anything about our ongoing investigation with the law firm representing Simon Afram, given their hostile attempts to extort money from Netflix over this situation — including immediately demanding $165 million for the film rather than work with us in good faith.”

                              Neither Afram nor Netflix appear to disagree on the broad strokes of the bizarre circumstances surrounding the missing film, which has alarmed filmmakers around town.

                              On June 15, “Fortitude” associate producer Daniel Haido hand-delivered an unencrypted digital cinema package (DCP) of the Simon West-directed World War II thriller to Netflix at the streamer’s request — a standard transaction that takes place when distributors are interested in buying a film and ask for a version that is suitable for use in a commercial theater, court docs reveal.

                              Within 24 hours, Netflix executives screened the film.

                              But on June 25, a Netflix executive sent a shocking email to two members of the “Fortitude” film team. (The full email is contained as an exhibit in the lawsuit, filed in California’s Central District.)

                              “This is a first for us. Unfortunately, someone stole a good amount of drives from our office desks this past week,” the executive wrote, according to the filing. “We’ve been working through this with our security teams to no luck. Our piracy teams are on high alert with the breach and will monitor.”

                              A Netflix source previously insisted to us that the other drives were empty, and that no additional materials were lost.

                              According to the lawsuit, Haido had given Netflix explicit instructions both verbally and in writing that, “the files be deleted after the screening.”

                              “For screening purposes, the files on the DCP containing the Film would be copied or ingested into the projector used to screen the Film. Thus, Mr. Haido was requesting that Netflix delete the files from its projector. Mr. Haido also asked to be notified ‘as soon as’ the drive was ready for pickup,” the lawsuit states. Haido made repeated attempts to schedule a pickup and was allegedly ignored or stalled until the June 25 email acknowledging a theft occurred.

                              It is unclear what transpired behind the scenes over the next five weeks, but on July 30, Afram sued Netflix for $105 million.

                              Afram’s suit claims that Netflix refused to confirm whether or not it had filed a police report, despite the fact that an executive acknowledged in writing that a theft had occurred.

                              The lawsuit claims that Netflix also rebuffed the filmmakers’ request that the studio involve the Los Angeles Police Department. For its part, Netflix says it “disputes any claim that it bears the risk of loss.”

                              But it was a subsequent sentence in the Netflix statement that included the word “extort” that prompted today’s amended complaint.

                              “Netflix’s statement that ‘the law firm representing Simon Afram’ made ‘hostile attempts to extort money from Netflix over this situation — including immediately demanding $165 million for the film’ is not loose, figurative, or hyperbolic. Extortion (and attempted extortion) is a crime with a legal definition,” the amended complaint states.

                              “Netflix is a very large, publicly traded company and is very sophisticated. It has a sizeable in-house legal department, as well as outside counsel. It has teams of professionals to handle its media and public relations. Netflix’s statement was not a spontaneous, knee-jerk reaction. It was a planned, crafted, and very intentional statement made by a sophisticated party that knowingly accused Mr. Afram and his law firm very publicly of committing the serious crime of attempted extortion.”

                              Afram is not asking for additional damages at this time, and hopes that an overall sum will be determined at trial, the papers state.

                              Netflix has painted the litigation as a money grab. But Afram is known in film finance circles to be a billionaire, and “Fortitude” represented a seven-year passion project for him.

                              The film marks a reteaming between Cage and West, who previously collaborated on the box-office hit “Con Air.” The film also stars Ben Kingsley and Ron Perlman and its supporting cast includes Matthew Goode, Michael Sheen, Art Malik, Jordi Mollà and Lukas Haas, as well as Ed Skrein, Alice Eve, Paul Anderson and Emilio Sakraya.

                              Afram’s legal team is citing the Serenity Investments v. Sun Hung Kai Strategic Capital case, which also occurred in Central California District, to demonstrate that strict liability should apply here. Afram and his company Op-Fortitude are being repped by attorneys Caroline Mankey and Christopher McAndrew at Akerman and Neville Johnson, and Hyura Choi at Johnson and Johnson.

                              Afram’s attorneys declined comment. We’ve reached out to Netflix for comment.​
                              Annoyingly, the statement "On June 15, “Fortitude” associate producer Daniel Haido hand-delivered an unencrypted digital cinema package (DCP) of the Simon West-directed World War II thriller to Netflix at the streamer’s request..." is ambiguous as to whether Netflix specifically asked for the DCP to be unencrypted. Setting that aspect aside, I find it very odd that Netflix refused to file a police report when not only is it very clear that a crime has taken place, but that crime is now the subject of a massive civil suit. The only reason I can think of is that a police investigation would likely uncover things that Netflix does not want uncovered. Presumably there is nothing to stop Afram himself from filing one, especially given that Netflix has admitted in writing that his drive was stolen from their property.

                              The claim that the other drives were empty doesn't pass the smell test, either. How many of us have a stack of truly empty drives sitting around in our booths? I suspect what is actually meant is that the other drives in the booth all contained encrypted DCPs, and therefore might as well be empty for anybody who nicks them.

                              All this says to me that there is rather more to this incident than has entered the public domain.

                              Comment

                              Working...