ArcRoster logo
← Blog

What to do when your ARC leaks (a step-by-step guide)

9 min read

You searched your book title out of habit, or a reader tipped you off, and there it is: your unreleased manuscript sitting on a piracy site, days or weeks before launch. It's a gut-punch. Take a breath — this is fixable, and the steps below are the same ones a calm, experienced author would take. Work through them in order.

First: don't panic, and don't publicly accuse anyone

The single most common mistake is firing off an angry post naming a suspected reviewer before you have proof. If you're wrong, you've defamed an innocent reader and poisoned your own ARC community. Attribution first, action second. Everything below assumes you're gathering evidence, not guessing.

Step 1 — Capture the evidence before it disappears

Piracy listings vanish and change. Before you do anything else, preserve the proof:

  • Screenshot the listing, including the URL, upload date, and any username.
  • Save the page (or use an archive service) so you have a timestamped copy.
  • If you can safely download the leaked file itself, keep it — it's the key to identifying the source.

That file matters more than the listing. A leaked EPUB carries whatever identifying information was baked into it when you sent it — which is the whole point of the next step.

Step 2 — Identify who leaked it

This is where most authors get stuck, because a plain EPUB sent through a generic delivery tool looks identical no matter who received it. There's nothing in the file to trace.

If your copies were individually fingerprinted, this step is fast. Each reviewer's copy carries an invisible, per-recipient marker, so you upload the leaked file and get back the exact reviewer it was issued to, the time they downloaded it, and a confidence score. That's the difference between "someone on my ARC team leaked this" and "this specific copy was issued to this person." (This is exactly what ArcRoster's fingerprinting is built to do.)

If your copies weren't fingerprinted, you're limited to circumstantial signals: who downloaded and went silent, whether any visible watermark or personalization survived, and timing. It's weaker, but download logs can still narrow the field.

Step 3 — File a DMCA takedown notice

Whether or not you've identified the leaker, get the file removed. A DMCA takedown notice is a formal request to the host to remove infringing content, and most legitimate hosts and search engines honor them. A valid notice generally includes:

  • Identification of your copyrighted work (title, and that you're the author/rights holder).
  • The exact URL(s) where the infringing copy appears.
  • Your contact information.
  • A statement of good-faith belief that the use isn't authorized.
  • A statement, under penalty of perjury, that the information is accurate and you're the rights holder.
  • Your physical or electronic signature.

Send it to the host's designated DMCA agent (check the site footer or their abuse/legal page), and separately submit a removal request to Google so the page drops out of search results even if the host is slow. If the file is on a major platform, use their dedicated copyright reporting form.

Step 4 — Protect your Kindle Unlimited status

If your book is enrolled in KDP Select / Kindle Unlimited, a pirated copy circulating can be more than annoying — duplicate free copies can cannibalize page reads and, in bad cases, trigger questions about exclusivity. Document that you're actively issuing takedowns. If Amazon ever flags a duplicate, your evidence trail (screenshots, takedown notices, attribution report) shows you're the rights holder responding to piracy, not the source of it.

Step 5 — Close the door on the source

Once you've identified the leaker with confidence:

  • Remove them from your current campaign and block them from future ones.
  • Record it against their reviewer history so they can't quietly rejoin next launch.
  • Decide whether to contact them. Sometimes a leak is careless (a shared family device, a re-gifted file) rather than malicious — a firm, factual message can be enough.

With a reliability system, a confirmed leak drops the reviewer's score below zero and marks them Blocked automatically, so the accountability outlives your memory of this one bad launch.

How to make the next leak a non-event

The authors who stay calm about leaks are the ones who set up for them in advance. Three habits make the difference:

  • Fingerprint every copy. If each file is traceable to one recipient, a leak becomes a name instead of a mystery — and reviewers who know copies are traceable are far less likely to share them.
  • Use expiring, per-reviewer download links instead of one link forwarded to a group.
  • Keep a reliability record so the same person can't leak, disappear, and reappear on your next ARC team.

None of this requires DRM or punishing your honest readers. It's not about locking the book down — it's about making sure that if a copy walks, you know whose it was. That's the quiet deterrent, and it's why per-copy fingerprinting exists.

The short version

Preserve the evidence, identify the source (instantly if your copies were fingerprinted), file DMCA notices with the host and Google, protect your KU status with a documented paper trail, and block the leaker for good. Then set up so the next one is a shrug, not a crisis. Most authors who fingerprint their ARCs never need the leak-response page — they just sleep better knowing it's there.

Your next launch, reviewed

Run your next launch with ArcRoster.

Track every reviewer, score reliability automatically, and fingerprint every copy. Free during the beta.