Forgot your password?
typodupeerror
Movies Piracy The Almighty Buck The Courts

Netflix Sued For Losing 'Master Copy' of Unreleased Nicolas Cage Movie (cbsnews.com) 132

A production company and filmmaker are suing Netflix for $105 million, alleging the streamer lost a stolen drive containing an unencrypted master copy of the unreleased Nicolas Cage film Fortitude, which they claim damages its exclusivity and market value. Netflix denied responsibility for the lost film but said it takes content security seriously and has offered to monitor piracy sites for unauthorized copies. CBS News reports: The complaint filed on Wednesday in California district court alleges that the film's associate producer, Daniel Haido, hand-delivered an unencrypted master copy of the film to Netflix so the company could screen it as a potential buyer. Haido verbally instructed the employee to delete the files after the screening, according to the suit. A little over a week after the screening, Netflix emailed the filmmakers to say the drive had been stolen, the plaintiffs allege. "Someone stole a good amount of drives from our office desks this past week," a Netflix executive wrote in the email, according to the suit.

The complaint notes the movie, entitled "Fortitude," took over seven years to make and cost $45 million. It tells the story of a secret mission called Operation Fortitude during World War II that was orchestrated to mislead the Nazis about the Allied invasion of Europe. The film stars Nicolas Cage as Dusko Popov, a real-life spy during World War II, as well as Sir Ben Kingsley and Ron Perlman.

The plaintiffs said studios will now be dissuaded from buying the rights to the movie, knowing that a version of it could be released by a third party for free. "The film's value depended in significant part on its exclusivity as an unreleased, first-to-market work," the complaint states. "By losing control of the film, Netflix destroyed that exclusivity and materially, if not completely, impaired the film's marketability."

Netflix Sued For Losing 'Master Copy' of Unreleased Nicolas Cage Movie

Comments Filter:
  • Huh. (Score:4, Funny)

    by Black Parrot ( 19622 ) on Friday July 31, 2026 @05:13AM (#66265838)

    Sounds like a good strategy for a studio that expects their big movie to be a box office flop.

    • Re: (Score:2, Insightful)

      by geekmux ( 1040042 )

      Sounds like a good strategy for a studio that expects their big movie to be a box office flop.

      The Nic Cage financial strategy of funding your lifestyle fuckery with lawsuits, will meet the wall of Hollyweird reality when insurance pays out $30 million to the lawyers and hands Nicky a check for 37 cents and a coupon for two free movie tickets and a large popcorn.

      On a related note, $45 million over 7 years is a comparative bargain in Hollywood now. I’m shocked it was that cheap, but that probably didn’t include the $100 million needed for COVID PPP loans funding the great Hollywood Pause.

      • I can at least respect Cage's work ethic. He's a weirdo, but when he blew all his cash on absurd things, instead of just declaring bankruptcy and fading into the sunset he decided to take every possible job that came his way, in whatever quantity that entailed. Some good. some horrible. most meh.
        I've got "normal" friends who would shy away from that level of fix.

        I

    • A $45 million film with Nicholas Cage will almost certainly be profitable.
      • In reality, yes.

        According to Hollywood and its accounting practice, it loses more money than exists in the world at this time. In every jurisdiction, simultaneously.

        Adam's Starship Bistromath was right in the way that number alter reality. It was only wrong in the form that it took.

        • Re:Huh. (Score:5, Interesting)

          by UnknowingFool ( 672806 ) on Friday July 31, 2026 @09:57AM (#66266102)
          Remember kids, the reason we never got a Forrest Gump 2 is because the first one lost money according to Paramount. So they didn’t pay royalties to the author. The author sued and settled with Paramount for an undisclosed amount. Technically he never got royalties for Forrest Gump; Paramount paid him the money for rights to the unwritten sequel. The author then wrote Forrest Gump 2 with Forrest as the most unlikable character and put Forrest in bizarre and outlandish plot contrivances.
          • So you mean they cast Nicholas Cage as Forrest Gump?

          • Technically he never got royalties for Forrest Gump; Paramount paid him the money for rights to the unwritten sequel. The author then wrote Forrest Gump 2 with Forrest as the most unlikable character and put Forrest in bizarre and outlandish plot contrivances.

            Technically..that sounds like a fitting sequel. Not unlike the first one.

            Rife with stories of a 70-IQ man coming home with the Medal of Honor to start a multi-million dollar shrimping business under the navigational guidance of the god Poseidon, with those hurricane-riding reflexes honed during a stint as national ping-pong champion sponsored by the US Army..

            Was that subsequent script written in protest, or profit?

      • A $45 million film with Nicholas Cage will almost certainly be profitable.

        Almost certainly?

        Strong words for a career catalog in which two thirds never made it to $45 million. Not sure how many others weren't even profitable because it far exceeded the cost of this bargain. Cutting your paychecks tenfold in exchange for share-rolling the Dice of Profit, must be part of the excitement for him at this point. I guess any true artist, enjoys chasing the manufactured struggle.

        https://www.imdb.com/list/ls06... [imdb.com]

        • I bow to your superior research and data.

          A lot of the older ones should either be discounted or adjusted for inflation, but even if you only take the movies since 2001, most of them have not been profitable.
    • Sounds like a good strategy for a studio that expects their big movie to be a box office flop.

      Well, they couldn't be certain that the drive would be stolen unless the studio also hired the thief. Hell, that's actually a better story than this flick. Netflix should get on it.

      • Sounds like a good strategy for a studio that expects their big movie to be a box office flop.

        Well, they couldn't be certain that the drive would be stolen unless the studio also hired the thief. Hell, that's actually a better story than this flick. Netflix should get on it.

        * meanwhile at Netflix HQ *

        (Marketing Director) "Sir, about your idea for Gone in 60 Seconds 2; The Theft of Irony..well..I'm afraid it's been..stolen.."

    • Re:Huh. (Score:4, Insightful)

      by Cpt_Kirks ( 37296 ) on Friday July 31, 2026 @08:40AM (#66265954)

      If they were marketing the film to Netflix, they weren't planning on releasing it into theaters.

  • Unencrypted? (Score:3, Insightful)

    by 0xG ( 712423 ) on Friday July 31, 2026 @05:30AM (#66265842)

    This kind of stupidity has me strangely on the side of Netflix.
    Why would you put all of your IP on an easily-stolen drive?

    • Re:Unencrypted? (Score:5, Insightful)

      by AmiMoJo ( 196126 ) on Friday July 31, 2026 @06:46AM (#66265878) Homepage Journal

      I've work in technical industries, and they can't handle encryption. You try to send someone an encrypted file with clear instructions to decrypt it, and they will fail and demand you send it over unencrypted instead. I can only imagine that it's even worse in creative industries.

      Companies instead rely on contracts obliging the receiver to protect their property. When they don't, a lawsuit like this is the result. And it may even work out better for them, because a movie that might have been a flop instead nets them whatever they can convince a court to award.

      • Companies instead rely on contracts obliging the receiver to protect their property.

        Which makes sense, since if you give them instructions to decrypt it, they will have the decrypted version anyway.

        • by pla ( 258480 )
          It would still be encrypted at rest. This was someone opportunistically walking off with a milk-crate full of hard drives, not a sophisticated attack on their network.

          Of course, you could still be right - I've grown numb to how often people fail to communicate sensitive information over alternative secure channels. It wouldn't surprise me in the least to see the instructions, including the password, written on a post-it note slapped right on the drive itself.
          • It would still be encrypted at rest.

            That assumes that whatever you give them remains in the form or on the storage device you give them. I bet you a dollar it won't. The first thing that will happen is it gets loaded onto some corporate network drive or something where it very much will be subject to any hacking process.

          • by gweihir ( 88907 )

            Only if the Netflix "experts" do not post-it the password onto the drive. With the level of competence on display here, I think that would be a real possibility.

            • by dwywit ( 1109409 )

              If the producer had done their job, it wouldn't be a password.

              A Digital Cinema Package (DCP) has the film on an encrypted hard drive with a proprietary interface, i.e. not your run-of-the-mill SATA socket, and you get a decryption key that only works on your server, connected to your projector, for a set period of time. Every cinema gets a custom decryption key that will only work on their server and their projectors.

        • by dwywit ( 1109409 )

          It only gets decrypted by the proprietary decoder board inside the projector, you never have a decrypted data stream until the output of the decoder board. And guess what? If you so much as remove an access cover, the projector shuts down and won't power up again until a technician (wielding an access code that you don't have) re-activates it.

      • Encrypted USB drives exist, and have for a long damn time. It uses a password to unlock.

        There's no excuse here. They needed to buy a different device and not be complete chuds.

      • I've work in technical industries, and they can't handle encryption.

        lol wut? DCPs are usually heavily encrypted. Even the dumbest intern running their screening room could figure it out.

      • I have a solution for this.

        And by that I mean an idea that these idiots could use to protect media like that, and still be capable of using it themselves.

        • I have a solution for this.

          And by that I mean an idea that these idiots could use to protect media like that, and still be capable of using it themselves.

          Or use streaming. One-to-one from the studio to Netflix. The studio gives Netflix the app with trivial authentication. Cheaper and easier than sending drives through the mail.

          • by PCM2 ( 4486 )

            Or use streaming. One-to-one from the studio to Netflix. The studio gives Netflix the app with trivial authentication. Cheaper and easier than sending drives through the mail.

            VFX studios are already doing this for their production pipelines. The processing happens in a data center; all the artists see is essentially a terminal window. Nobody can "walk off" with anything.

      • by gweihir ( 88907 )

        Yep, even basic skills like that are completely out of reach of supposedly "computer literate" people. I have often made the same experience. Also many "security features" completely suck. The most laughably insecure "encryption" I have seen so far was in MS Excel, where flipping a single bit in the file removed all protection. Probably another case of MS doing "it is not really an attempt at security" and just wanting a "feature" the customers like but which basically does nothing.

      • Still they didn't protect their IP. Don't send something and assume others will protect it. Unless Netflix specifically requested it be unencrypted it should not be their fault.

        • by PCM2 ( 4486 )

          I assume there was some form of contract. Generally speaking, any time you send somebody unsolicited copyrighted material, you can expect it to get summarily thrown in the trash, so whomever you sent it to can't fall for the old "you stole my idea" bugaboo.

      • by dwywit ( 1109409 )

        They don't need to "handle it". The Digital Cinema Initiative (DCI) has it all worked out.

        You want to screen movies, even just to execs and marketing people who will decide whether to take it on (as in this case) ? You buy a DCI-compliant projector, and a DCI-compliant server. The server that I was operating had a fedora kernel but no root access, only user-level access, and a customised GUI interface with controls that only operated the movie screening part, and nothing to do with the operating system*. Th

    • Exactly.

      If you think you have something worth $45M on a fucking USB drive, how about making sure that USB drive is worthless if it ends up in the wrong hands?

      These morons caused their own problem by not protecting themselves with ubiquitously available means that are not novel in any way. There are hardware encrypted devices out there specifically for this kind of thing. Like, you know, this thing. [kingston.com]

      This lawsuit should be thrown out for negligence on the part of the plaintiff.

      • Re:Unencrypted? (Score:4, Insightful)

        by thegarbz ( 1787294 ) on Friday July 31, 2026 @10:38AM (#66266190)

        How? You're still putting faith in the cyber security capabilities of the company you're dealing with. I've very much seen an encrypted drive laying on a desk with a post it note containing the password on it, because encryption is often seen as something relevant to transport, not to the data once it is sitting at a company.

        • Well, the company that signs an NDA has a duty to protect something once it's in their possession. If it was on an encrypted drive and someone was to do something that fucking dumb, they would certainly have made a case for negligence against themselves.

          The producers of this film may as well have put it on some shitbox web server and emailed a link for all the security they chose.

          It's just not that hard.

    • Daniel Haido, hand-delivered..

      Probably a valid question for the person who hired this person to hand-deliver the IT policy written by the moron in charge of cybersecurity..

      ..not that I'm pointing fingers at the shit rolling down a hill or anything.

      In all seriousness the human hand-delivering IP, was supposed to BE the fucking security. As in the same kind of security when Hollywood IP was sitting in an unencrypted film canister. If a CEO can't trust a human hand-off, they probably shouldn't be trusting their own HR with PII. Their mi

      • by gweihir ( 88907 )

        There is absolutely nothing wrong with hand-delivering stuff using a trusted person. It is simple, clear and reliable and everybody involved understands how it works. Security does not get any better than this.

        There is a lot wrong with the receiving end not making sure their people continue to protect what just went into their custody.

        • ..Security does not get any better than this.

          Sure it can. You can make those involved a very limited group. Make the works they create downright classified. Involve mens with guns. Lots of guns.

          Say for example if Hollywood decided to only release it to those pre-paying for that 90% freshness rating..

          • by gweihir ( 88907 )

            ..Security does not get any better than this.

            Sure it can. You can make those involved a very limited group.

            Insightless much? That is _exactly_ what this approach does.

            • ..Security does not get any better than this.

              Sure it can. You can make those involved a very limited group.

              Insightless much? That is _exactly_ what this approach does.

              Didn't they try and use the tactic of unique digital watermarks to reveal _exactly_ which person leaked the limited-pressing DVD screener back in the day? I seem to recall the underground community ironically revealing that when downloading the HD screener off USENET opening day weekend..back when Hollywood still wasn't smart enough to protect their IP.

              Humans gonna human. If you can't trust your meatsacks, hire better meatsacks. If screening is part and parcel of Hollywood, then a screening community st

    • by gweihir ( 88907 )

      Why would you not? Assuming sound practices, this is completely fine. Assuming blithering idiots at Netflix, any other option would be problematic too.

      Encryption is a non-issue, as the data itself was transported securely.

    • by gweihir ( 88907 )

      Encryption is immaterial here. What encryption does is that instead of the data, you protect the key. If the receiving party is incompetent, that will just get botched instead.

      Crying "Encryption!" here is a sure sign of incompetence. Encryption is a ritual with limited power and specific applicability. It is not something you mindlessly require for the gods of IT Security being satisfied with your service. It requires _understanding_, something that is sorely lacking in the IT space these days. And in many

  • Netflix should at least encrypt the content so if somebody lifts the drives it's no good outside of the machine it came from. e.g. encrypted partition / files with a key protected with TPM.
    • by DrXym ( 126579 )
      And if the supplier gave it on the hard drive to Netflix, then really they should have encrypted it and given a key to use the drive by some other channel like email
      • Or just used an Ironkey, and sent them a password / combo separately as you say.

        They don't even need to be technical folk - there are retail products available for at least 15 years that solve this exact problem.

    • by gweihir ( 88907 )

      So you advocate delivering a whole computer? That sounds a bit like overkill to me.

      • Still overkill but not remotely impractical. Sending a "whole computer" would be no more difficult than shipping tiny PCs to Ebay buyers who often buy several at once for our "home lab" style setups.

        A typical tiny PC plus power brick and its cord easily fits in a flat rate box (though for Important Stuff best sent next day air).

  • Looks like he wants their face⦠off.

    Those memes are still great.

  • Nicolas must be going through some though times...

  • by encrypted ( 614135 ) on Friday July 31, 2026 @07:22AM (#66265896) Homepage
    Nic cage movie gets stolen AND it's his first movie worth more than $9.99? If they were suing Netflix for like $50 and a monthly bus pass maybe I would believe it.
    • by necro81 ( 917438 )

      Nic cage movie gets stolen AND it's his first movie worth more than $9.99? If they were suing Netflix for like $50 and a monthly bus pass maybe I would believe it.

      Jeeze, why all the hate for Nic Cage on this thread? IMDb lists 120 actor credits [imdb.com]. There's crap in there, for sure. There's also a decent measure of so-bad-it's-good-at-least-for-entertainment-purposes. But there's also Leaving Las Vegas (oscar for best actor), Adaptation (oscar nominee for best actor), Moonstruck, Raising Arizona, Pig, Lord of War, .... You can't find anything worthwhile in there?

    • by gweihir ( 88907 )

      Especially as what the movie was is totally immaterial for this story. But haters obviously cannot help themselves. They always have to push their hate.

  • by geek ( 5680 ) on Friday July 31, 2026 @07:41AM (#66265904)

    The way this is being described is asinine. You lose a master and you're fucked, lose a copy and you still have the master. It's like words don't mean anything to these people. Additionally, fuck the studio for not encrypting it or exercising any sort of security on it at all.

    Pretty much everyone in this story is a moron

    • Netflix: We lost the master of the Nick Cage movie.
      Also Netflix: We deny responsibility for losing the movie.
    • by jbmartin6 ( 1232050 ) on Friday July 31, 2026 @08:55AM (#66265968)
      The point was that losing the copy means the film will wind up on torrent sites and they production company will lose revenue due to lost viewership. They company wasn't claiming they could not release the film.
    • You seem to be under the impression that the "master" these days is on analog film. It ain't. It's a digital computer file. There is no difference between "master" and "copy of the master". And as someone else has said, the problem isn't that they don't have other copies of the master, it's that somebody who's not them has a copy of the master and can churn out perfect pirate copies.

    • I think the problem here is you think you know the terms when you don't. "Master copy" is a standard industry term in the multimedia industry. Also copy doesn't explicitly imply that something has necessarily been copied from something. It can also be used to denote something is one of many. The "master copy" is the an original copy that subsequent copies are made from. It does not denote a single item. Multiple master copies can exist.

    • The way this is being described is asinine. You lose a master and you're fucked, lose a copy and you still have the master. It's like words don't mean anything to these people. Additionally, fuck the studio for not encrypting it or exercising any sort of security on it at all.

      Pretty much everyone in this story is a moron

      Screeners, are the morons who need the end product dumbed down. If they're going to act that way, then they should understand physical security shouldn't be anything less than the era of $100 million+ dollars worth of IP being handed around in an "unencrypted" film canister. Did we have actual security guards with guns back in the Casablanca era of screening, or was Hollywood IP stolen and Gone in 60 Seconds back then too?

      (Because the movie is yet unreleased, the damage is the same whether or not a "mast

    • by gweihir ( 88907 )

      The studio people are only morons for not understanding that the people at Netflix are morons. They basically did this right, but they assumed some skills, insights and competencies at Netflix that are obviously missing.

      The one time I did something similar to this, I later sent pictures of the physically destroyed device with serial number still readable. And, of course, it was encrypted.(USB drive, some secret banking data on it.)

    • by gweihir ( 88907 )

      You realize this is all digital and a "master" and a "copy of the master" are the same thing today? That used to be very different when stuff was still analog and the terminology has persisted. These days a "master" is just the final edit in non-compressed form or lossless-compressed form, i.e. at maximum quality and resolution.

  • Wikipedia has some great examples [wikipedia.org] of what happens when someone that's been promised "points" (a share of the net profit) on a movie has enough money to sue the studios that try to rip them off.

    They scurry under the fridge like cockroaches and settle for big amounts to avoid having their accounting practices further scrutinized. I don't see why they're so afraid of it, everyone knows they do it.

    My expectation is that the mechanism that puts an end to it will be the IRS or similar. Like Al Capone learned, t

  • Haido verbally instructed the employee to delete the files after the screening

    Or just, I don't know, return the drive??

    • by gweihir ( 88907 )

      Especially as most people have no clue how to actually delete data. Current state of things is that for SSD, not even a complete overwrite with random data is reliable. (Unless the SSD is pretty full and you do not mind partial data still being on it.) Physical destruction or full-disk-encryption with the key not on the disk is all that works.

  • You left a drive containing someone else's proprietary information lying out on a desk? That indicates a lack of security that boggles the mind. They should just pay up before even more embarrassing information comes out. Also, hire some people who can write a gramatical sentence.
  • Come on, a master copy would be the original final cut of the movie - is the blogger sure about their use of the word?

    "Copy of the master" I would believe, but this wreaks of blogger quality journalism.
    • A master copy can also mean a copy of the original final cut. The word copy denotes one of many. Many master copies can exist, and are usually used as a source prior to compression.

      Also this isn't the traditional movie industry we're talking about. It's netflix. They could very much have sent the actual master copy ahead of time. But yes the journalism leaves a lot of guess work. What is a drive? A HDD? A USB thumbstick?

    • I think "screener" means specifically a copy that clearly displays that it is not the release version. For example text appearing the entire movie that say "This is a screener and property of [company]". Other aspects like the movie becomes black in white randomly. Time markings appear randomly in the frame.
  • Just put a simple password encryption on it (e.g. - with a zip program) and give it to them verbally. I'm pretty sure Netflix could handle that level of complexity.

    • by gweihir ( 88907 )

      Yep. Next step: Employee, being exceptionally competent about security, writes the password on a post-it and puts that on the drive...

      • Sure. And then you might actually be able to win a negligence claim against them.

        • by gweihir ( 88907 )

          That is nonsense. Leaving critical data knowingly unprotected is what matters. The way it was done is pretty irrelevant.

  • And some things that should not have been forgotten were lost. History became legend. Legend became myth. And for two and a half thousand years, the film passed out of all knowledge. Until, when chance came, it ensnared another bearer...

  • Shouldn't only a copyright-infringer be punished here?
    • by gweihir ( 88907 )

      If you can find them. Available evidence suggests that is often not possible, especially when the crime is done non-commercially. No money-trail to follow, you know.

  • I mean, _physical_ drives with unencrypted valuable data getting stolen? That is soo last century. That employee would probably have "deleted" it by dragging it onto the Recycle Bin and maybe emptying that as well.

  • Sorry, but whoever decided that is the one that should get sued.

    • It was A copy, they misused the term master copy in a digital age where every copy can be the same as a master.
  • ... they could find some adventurous guy to go on an epic journey to recover the lost hard drive?

  • The attorneys for Op-Fortitude do not seem to know the difference between encryption keys and encrypted content.

    "If the DCP is encrypted, please have the keys open from the time the asset lands through EOD on 6/16. This timing allows us to test the content and ensure a streamlined screening." In other words, Netflix expressly requested that the Film's DCP be either unencrypted or unlocked.

    A request that keys be valid for a given time period is very different from a request that content be a-priori un
  • Handing over an unencrypted version, and asking "please delete after watching" is simply poor practice.

    Every commercial video suite - Premiere Pro, DaVinci Resolve, etc, has output options for DCP format, with encryption, and generate a decryption key with a time window. It's not an expensive add-on that costs big bucks every time you use it.

    Then leaving it to someone else to delete after watching. Sure.

Bell Labs Unix -- Reach out and grep someone.

Working...