Technology

How Brands Can Spot Cloned and Photocopied QR Codes

When a counterfeiter copies a label and prints thousands of fakes, the right authentication platform catches it — here's what brands should look for.

AM
Aisha Mwangi
9 min read

Once a brand deploys cryptographically signed codes, the counterfeiter's options narrow sharply. Minting new valid codes is off the table without the private key. So they do the only thing left that works: they copy.

A counterfeiter buys a genuine unit, photographs the code, and prints that single code across an entire counterfeit production run. Every one of those codes carries a real signature and validates perfectly, because it is an exact copy of something genuinely issued.

Cloning cannot be prevented at the cryptographic layer — you cannot stop someone photographing a label. It is caught behaviourally, by noticing that the codes are doing things a physical object cannot do.

The physical constraint that gives clones away

A genuine unit is one object. It exists in one place at a time, is bought by one person, and is scanned a small number of times before it is consumed or discarded. Every clone-detection signal is a variation on catching codes that violate those physical facts.

1. Scan-count saturation

The bluntest signal. A single serial accumulating dozens or hundreds of verifications is not one bottle being checked repeatedly — it is many bottles carrying one code.

The threshold needs care. Genuine repeat scans do happen: a curious customer scans twice, a pharmacist checks stock, a shopper shows a friend. Setting the threshold at two produces constant false alarms. Effective thresholds are set per product category, informed by the observed baseline, and weighted by the other signals below rather than used alone.

2. Geographic impossibility

The strongest single indicator. If a serial is scanned in one city and then, ninety minutes later, six hundred kilometres away, no physical object made that journey. This is far more reliable than raw scan counts, because it does not depend on a tuned threshold — it depends on a physical impossibility.

It requires tolerance for location imprecision. IP-derived geolocation can be badly wrong, particularly on mobile networks where traffic may route through a gateway in another city entirely. The rule must be built with enough margin that ordinary network routing does not trigger it — which is why speed-of-travel checks work better than simple distance checks.

3. Device diversity on one serial

A genuine unit's small number of scans usually come from one or two devices. A cloned code scanned by forty distinct devices in a week is being carried by forty different physical items. Persistent per-browser identifiers make this measurable without collecting personal data — the platform needs to know that two scans came from different devices, not who owns them.

4. Region mismatch

When batches are tagged with an intended market, codes verifying consistently outside that market stand out. On its own this indicates diversion rather than cloning — but combined with high scan counts, it usually means the counterfeit operation is running in a different market from where it sourced its sample.

5. Temporal clustering

Genuine scans spread out as stock sells through. Counterfeit runs enter the market in bulk, so their scans arrive in a compressed burst. A batch that was quiet for months suddenly producing heavy first-time scan activity is a strong indicator that a counterfeit run using its codes has just hit shelves.

6. Scan-to-shipment mismatch

The most under-used signal. If a batch of 50,000 units has shipped and generated 140,000 first-time verifications, the excess is not a tuning question — it is arithmetic. Reconciling scan volume against known production volume catches cloning at the aggregate level even when individual codes look unremarkable.

Configuring detection without drowning in alerts

The failure mode of anomaly detection is not missing clones. It is generating so many low-quality alerts that the team stops reading them.

  • Establish a baseline before enabling alerts. Two to four weeks of normal traffic tells you what your product's genuine scan behaviour looks like. Thresholds set without this are guesses.
  • Tune per product category. A pharmaceutical scanned once at the counter and a consumer electronic scanned during setup, resale, and warranty registration have completely different normal profiles.
  • Alert on scored combinations, not individual signals. Route single-signal events to a dashboard for review; reserve notifications for multi-signal detections.
  • Separate consumer-facing warnings from internal alerts. The bar for telling a shopper something is wrong should be higher than the bar for flagging it to your brand-protection team.
  • Review false positives weekly at first. Early tuning is what determines whether the system is trusted in month three.

What the consumer should see

When a clone is detected mid-scan, the shopper is standing in a shop holding a product. The message needs to be accurate without being alarming, and it needs to tell them what to do.

Overstating certainty is a real risk. A confident "THIS IS FAKE" on what is actually a false positive damages a legitimate retailer's reputation and the brand's credibility. Language that conveys the actual finding — that this code has been verified an unusual number of times and the item should be checked with the seller — is both more honest and more useful.

The strategic point

Clone detection is not only a defensive measure. Every cloned-code detection carries a location and a timestamp, so a counterfeit operation that clones your codes is continuously reporting where it is selling.

That is the asymmetry worth internalising. Cryptographic signing forces counterfeiters into cloning, and cloning is the one attack that generates the evidence needed to find them. The counterfeiter's best remaining move is the one that gives them away.

Protect your products with VerifyGuard

Generate cryptographically signed QR codes, let customers verify in one scan, and see counterfeit activity as it happens.