Case Study

How a Leading Pharma Brand Uncovered Counterfeit Networks in 30 Days

A look at how real-time scan intelligence helped a major manufacturer reveal organised counterfeit distribution across its markets.

KM
Kwabena Mensah
7 min read

The brand in question manufactures a widely used over-the-counter medication sold across several East African markets. They came to us with a familiar and frustrating problem: they were confident they had a counterfeit issue, and they could not prove where it originated.

Their evidence was circumstantial but persuasive. Reported sales volumes in one region had been flat for two years while the category grew. Customer complaints described packaging that was subtly wrong. Two pharmacists had independently returned product the brand's quality team confirmed it had not manufactured.

What they lacked was any way to determine where the fakes were entering. Their distribution chain had four tiers and more than two hundred downstream partners. Auditing all of them was neither affordable nor fast.

Week 1 — instrumenting a single production run

Rather than attempt a full rollout, we scoped the pilot narrowly: one SKU, one production run of roughly 180,000 units, distributed across the region in question through the brand's normal channels.

Each unit received a cryptographically signed code, tied to its batch and to the market that batch was intended for. The codes were printed by the brand's existing label supplier — no new production hardware, which is usually the biggest source of delay. A short verification prompt went on the carton in English and Swahili.

Critically, the batch was tagged with its intended distribution region. This turns out to be the single most valuable configuration decision, for reasons that became clear in week three.

Week 2 — establishing a baseline

The first weeks of scan data are not for catching counterfeiters. They are for learning what normal looks like, and resisting the urge to over-interpret early noise.

Genuine consumer scanning has a recognisable shape. Volume rises as stock reaches shelves. Most codes are scanned once, occasionally twice. Locations track population density and retail footprint. Times of day follow shopping hours.

Two apparent anomalies surfaced early and both were benign — a cluster of repeated scans traced to a distributor testing the system, and a geographic outlier that turned out to be a legitimate cross-border purchase by a traveller. Investigating these first mattered, because it calibrated the team's judgement before the real signal arrived.

Week 3 — the pattern separates

In the third week, two distinct anomaly types emerged, and distinguishing between them turned out to be the crux of the whole exercise.

Signal one: duplicate codes

A set of serials began accumulating scan counts far beyond what a single physical unit could produce — dozens of scans each, from many distinct devices, spread across an area far too wide for one package to have travelled.

This is the classic signature of a copied label: a counterfeiter had obtained genuine cartons, photographed the codes, and reprinted them across a production run of fakes. The signatures validated — they were real signatures — but the scan behaviour was physically impossible.

Signal two: region mismatch

Separately, a body of codes from the same batch was being scanned consistently in a market the batch had never been allocated to. These were single-scan, well-behaved codes. Nothing about them suggested duplication.

This was not counterfeiting at all. It was diversion — genuine product, made by the brand, being moved outside its intended channel, most likely to exploit a price differential between markets. A different problem, with a different remedy, and one the brand had not known it had.

Week 4 — narrowing to a source

With four weeks of data, the duplicate-code detections formed a clear geographic concentration. Mapping those clusters against the brand's own distribution records isolated a small number of downstream partners whose territories overlapped the affected areas.

The batch tagging narrowed it further. Because every duplicated serial belonged to a known batch, and every batch had a documented allocation, the brand could work backwards from the fakes to the specific consignments whose cartons had been harvested for copying. That pointed at one sub-wholesaler through which all the affected consignments had passed.

An audit that would have meant visiting two hundred partners became an audit of a handful.

What made this work

  • Narrow scope. One SKU and one production run produced a clean, interpretable signal. A simultaneous rollout across the full catalogue would have buried it.
  • Region-tagged batches. Without this, diversion and counterfeiting would have appeared as one undifferentiated mess of anomalies.
  • A baseline period. Resisting action for two weeks prevented the team from burning credibility chasing benign outliers.
  • Consumer-visible prompts. Scan volume is the raw material for the whole analysis; without a clear instruction on the pack, there is no data to analyse.
  • Existing print infrastructure. Using the current label supplier meant the pilot started in days rather than months.

Realistic expectations

Thirty days was enough to locate a probable entry point in a specific, well-defined distribution chain. It is not a universal timeline. Chains with more tiers, lower scan uptake, or counterfeit operations that copy from many sources rather than one take longer to resolve — and a low-volume product may simply not generate enough scans to reach statistical confidence quickly.

What is generalisable is the method: instrument narrowly, learn the baseline before acting, separate duplication from diversion, and use batch allocation to walk the evidence backwards through the chain. The counterfeit operation does the hard part itself — every fake it sells reports its own location.

Protect your products with VerifyGuard

Generate cryptographically signed QR codes, let customers verify in one scan, and see counterfeit activity as it happens.