An unencrypted master copy of the World War II spy thriller Fortitude, starring Nicolas Cage, was stolen from Netflix’s Los Angeles office at Sunset Bronson Studios on June 15, 2026, according to court documents filed in California federal court. Writer-producer Simon Afram and his production company, Op-Fortitude, are suing Netflix for at least $105 million, alleging the security breach compromised the film’s commercial distribution, marketing strategy, and awards campaign.
The Mechanics of a High-Stakes Physical Data Breach
In digital asset management, physical drive handoffs remain a standard vector for transferring massive uncompressed files like Digital Cinema Packages (DCPs). Yet, security protocols demand strict adherence to hardware-level encryption and immediate sanitation protocols. According to reporting from The Hollywood Reporter, Op-Fortitude hand-delivered the drive on June 15, 2025, after Netflix executives expressed interest in purchasing the feature following promotional materials received in December 2025.
The core technical failure centers on encryption status and key management. Netflix allegedly instructed the filmmakers to provide the key to the digital cinema package so the company could internally test the movie, according to the lawsuit cited by Ars Technica. However, the production company’s representatives explicitly stated that the DCP was left unencrypted upon delivery and instructed Netflix to delete the files post-screening. Ten days later, on June 25, 2026, Netflix’s head of film acquisitions, Sean Berney, admitted via email that a “good amount of drives from our office desks this past week” had been stolen.
Security teams face an uphill battle when unencrypted high-value intellectual property rests on open office desks. While Netflix defended its position, stating that the company “disputes any claim that it bears the risk of loss for a film delivered without the proper industry-standard safeguards,” the physical vulnerability exposed a glaring gap in corporate asset handling. Berney reportedly claimed erroneously that thieves would still need a decryption key, despite the drive having been unencrypted per testing requirements.
Financial Exposure and Legal Fallout
Simon Afram, who invested $45 million to finance the Simon West-directed film, argues that the security lapse completely disrupted the commercial roadmap. The feature boasts an ensemble cast including Matthew Goode, Ed Skrein, Jordi Mollà, and Alice Eve, following British Intelligence operatives using novel strategic operations against Nazi leadership. Because prospective distributors must now be notified that an unencrypted copy was compromised before its official commercial release, the film faces severe valuation depreciation.

The lawsuit details mounting friction between the parties following the disclosure of the theft. After an initial demand letter from a law firm representing Afram requested $165 million, Netflix officials characterized the move as a “hostile attempt to extort money” rather than a good-faith negotiation. Netflix maintained that it declined to share granular details of its ongoing internal investigation due to this escalation. Furthermore, Netflix refused a request from the filmmakers to involve the Los Angeles Police Department after the producers filed their own report.
In its official statements, Netflix asserted that none of the other lost drives contained active media content and that Fortitude remains accessible elsewhere as it is not the sole copy in existence. The company also noted that no evidence of an online leak has surfaced as of August 2026. Nevertheless, the legal parameters of liability for physical data loss on corporate premises remain hotly contested, shifting focus onto how major streaming platforms manage incoming third-party master media.
The 30-Second Verdict on Digital Asset Security
- The Incident: Unencrypted master drive of the Nicolas Cage film Fortitude stolen from a Netflix desk at Sunset Bronson Studios in June 2026.
- The Financial Stakes: Producer Simon Afram is seeking at least $105 million in damages, citing compromised distribution negotiations and marketing plans.
- The Corporate Response: Netflix denies liability, stating the filmmakers delivered the asset without industry-standard encryption safeguards and alleging extortion attempts over subsequent financial demands.
- Current Status: Litigation is active in California federal court, with no verified public leaks of the film detected to date.
As streaming platforms increasingly ingest multi-million-dollar third-party assets, the reliance on loose physical workflows presents a critical vulnerability. Enterprise IT governance must bridge the gap between cloud-native security and physical desk management to prevent catastrophic intellectual property breaches.

Worth a look