Buenos días, fútbol ha bloqueado tu sitio web, la culpa es de LaLiga. It would be funnier if it weren't, on the evidence now published, roughly true for one Spanish network in fourteen.
On 30 June 2026, the Open Observatory of Network Interference published the first large-scale empirical account of what LaLiga's anti-piracy blocking regime actually does to the Spanish internet when nobody outside the league is checking. The headline number -- 554,507 domains blocked at some point between January and June 2026, out of 9.2 million tested -- has already done the rounds. What matters more is what's underneath it, and OONI have published enough working to let anyone check it.
Since December 2024, Spanish ISPs have operated under a Barcelona Commercial Court order to block IP addresses associated with unauthorised LaLiga streams during live broadcasts. LaLiga's president has previously put the figure at around 3,000 IPs blocked per weekend. OONI's contribution is to show what happens when a handful of those IPs sit behind shared infrastructure -- which, on the modern web, is most of the time.
The numbers are stark. Cloudflare alone accounts for 501,305 of the affected domains -- 90.4% of the total -- sitting behind just 2,218 blocked IP addresses. Squarespace shows the same pattern in more extreme form: 18,592 domains, one IP. Compare Amazon: 11,647 domains spread across 4,286 addresses. This isn't enforcement intensity varying by provider; it's architecture. Because reverse-proxy CDNs multiplex thousands of tenants behind a single anycast address using TLS SNI or HTTP Host headers, pulling the plug on the IP takes down the entire neighbourhood. IaaS providers, by contrast, hand out dedicated, single-tenant Elastic IPs, keeping the architectural blast radius small. OONI's report is explicit that this means their own methodology likely understates impact at providers with sparser IP allocation -- the true figure is a floor, not a ceiling.
In practice, blocking 4 to 20 IPs in a single one-hour match window was enough to knock out more than 400,000 domains at a time -- repeatedly, on a near-weekly cadence, on networks including Telefonica, Orange, Vodafone and Mas Movil. The named casualties read like a stress test of exactly the kind of infrastructure a "targeted, proportionate" blocking regime is supposed to leave alone: Amnesty International chapters across five countries, UNHCR and UNICEF national sites, the Australian Senate, a Bergamo court, Stanford Law Review, the Terraform registry, Linux Mint's download mirror, and -- droll touch -- the UK NCSC's cyberaware.gov.uk, blocked in the name of stopping people watching football for free.
The detail that elevates this from "overblocking is bad, more at eleven" to something worth a paragraph on its own: OONI's TLS measurements on Digi Mobil (AS57269) caught a Man-in-the-Middle interception, not merely a block. 7,334 unique IPs across 14 ASNs, hosting 10,759 domains, were served a self-signed certificate mid-connection instead of the real one.
The certificate itself is the tell. Subject and issuer both read CN=core1.netops.test, OU=Packetland, O=Widgits Pty Ltd, L=SOME-CITY, ST=SOME-ST, C=EU. The stock OpenSSL req default reads O=Internet Widgits Pty Ltd -- so whoever built this box didn't leave the boilerplate untouched; they edited it, and still left "Widgits Pty Ltd," "SOME-CITY" and "SOME-ST" standing. That's arguably funnier than leaving the default alone: someone opened the config, made a change, and still couldn't be bothered to clear the placeholder fields before pointing the box at live subscriber traffic. It's valid from 19 February 2026 to 18 September 2124 -- a 98-year certificate quietly intercepting TLS sessions on a national mobile network, half-configured. If you wanted a single artefact to illustrate the gap between "court-authorised enforcement measure" and "actual operational discipline at the point of implementation," this is it.
OONI is careful not to attribute responsibility for the interception; the report states the data point and steps away. That analytical restraint is doing heavy lifting; a MitM box on a national ISP's infrastructure, correlated with match-time blocking windows, invites more questions than OONI is in a position to answer from network measurements alone. Digi Mobil doesn't get to be the only quiet party here for long.
Buried in the conclusion rather than the headline: Telefonica -- one of the most consistently compliant operators in applying the blocks -- is both a broadcaster of LaLiga content through its own media arm and approximately 10% state-owned. OONI states plainly that this "raises questions about potential conflicts of interest and the independence of enforcement dynamics." That is about as pointed as a measurement-science nonprofit gets, and it lands squarely in the territory this publication has been mapping under the Theatre Pulldown thesis -- the pattern by which state-adjacent commercial actors get handed enforcement powers over infrastructure they also have a financial stake in: enforcement operated by a party with a direct commercial stake in the outcome, under a court order from a single seven-page 2024 judgment that nobody has meaningfully revisited since, with no published block list, no independent technical review before additions, and no redress mechanism for anyone caught in the crossfire.
The EUIPO's own 2023 discussion paper -- which LaLiga's order predates in spirit if not in citation -- recommended excluding known shared-hosting IP ranges from this kind of blocking specifically to avoid this outcome. Nobody appears to have followed that advice, and eighteen months in, half a million domains and a half-configured MitM certificate are the receipts.
A half-configured MitM box on a national network is what operational carelessness looks like when nobody's checking. The same week OONI published the evidence, Europe's ISPs put a figure on what that carelessness costs everyone else. EuroISPA -- the umbrella body for over 3,300 European ISPs -- submitted a position paper to the European Commission that, read alongside the OONI report, looks less like coincidence and more like the industry finally putting a figure to what its own members have been absorbing for eighteen months. Grounded in an April 2026 Centre for European Policy Studies study -- a separate research trail from OONI's, which is itself worth something -- EuroISPA is asking the Commission to make copyright holders financially liable for collateral damage caused by overbroad blocking orders, with compensation mechanisms that are "clearly defined and enforceable," so that, in the group's words, "the burden of enforcement errors does not fall on innocent intermediaries and their users."
Spain is not the cautionary tale here; it's the current example. EuroISPA's submission points to Italy's Piracy Shield system taking Google Drive offline for over twelve hours in October 2024 on an erroneous order, as the precedent that should have ended this approach before it reached Spain, France and Austria. It didn't. What it did instead was escalate. EuroISPA says it is "deeply concerned" that blocking measures in those four member states have moved "beyond local access providers to target global infrastructure providers with no direct relationship to the infringing content" -- and names the two intermediaries next in line: VPNs and DNS resolvers. France's football league has now obtained VPN-blocking court orders on three separate occasions, the most recent in January 2026; Italy is preparing to require VPN and DNS providers to block pirated content directly.
The technical objection EuroISPA raises against this is the one that matters most for anyone thinking about jurisdiction rather than just outages: VPN and DNS providers "lack the technical means to apply geographically restricted blocks and are frequently neither based in nor subject to the jurisdiction of the issuing Member State." That is not a complaint about inconvenience. It's a description of a national court trying to bind infrastructure that was built, deliberately, to not have a single point of national control -- the same design property that makes VPNs and public DNS resolvers useful for privacy in the first place is precisely what makes them structurally unable to comply with a geofenced blocking order without breaking that property for everyone, everywhere, not just in Spain.
Set aside the football. This is a case study in what happens when infrastructure-level enforcement is delegated to a private rights-holder, executed by ISPs with their own commercial incentives to comply quickly and cheaply, under a legal instrument that was never stress-tested against the shared-hosting reality of the modern CDN stack -- and then left to run for eighteen months with no independent measurement until a nonprofit crowdsourced one from probe volunteers. The proportionality question OONI raises in its conclusion is the right one, and it's not specific to Spain or to football: it's the general question of what oversight regime is owed whenever a court order authorises IP-level blocking against infrastructure nobody bothered to map first.
What EuroISPA's submission adds is the second half of that question: who bears the cost while the mapping doesn't happen. Right now the answer is nobody with skin in the outcome. LaLiga loses nothing when Amnesty International goes dark for an hour; the ISPs comply because non-compliance is a bigger legal risk than overblocking; and the court that issued a seven-page order in December 2024 has, on the evidence so far, never been asked to revisit it against half a million domains of collateral damage. Making rightsholders liable for the blocks they request would change precisely one incentive -- the one that currently costs them nothing to get wrong -- and it is difficult to see what other lever would.
The direction of travel matters more than the Spanish case on its own. If IP-level blocking escalates to DNS resolvers and VPN providers as EuroISPA warns, the jurisdictional question stops being "which Spanish ISP has to comply" and becomes "which infrastructure, anywhere, can a national court compel" -- a question this publication has been tracking under the Theatre Pulldown thesis for rather longer than this particular football season.
Cross-reference: The Theatre Pulldown
The Sovereign Auditor covers digital sovereignty, cybersecurity governance, and data protection policy—with particular focus on Isle of Man jurisdiction and Crown Dependency issues.
Payments via PayPal. Credentials delivered by email. No Substack. No Stripe. No middlemen.