It starts with a single legitimate buyer.
Course piracy almost always begins with a legitimate purchase, not a hack: a real student enrolls through your own sales page, downloads your videos, your workbooks, your slide decks, and saves everything locally. Once that zip file exists on a disk somewhere, your control over distribution is effectively gone. The pirate doesn't hack you, doesn't phish your team, and doesn't need to break anything. They just buy the course and start resharing it. Every DRM scheme course platforms offer was designed around this known-impossible problem. The only real defense is finding and removing copies after they appear.