Counterfeiting & IP Crime: Mission Domain Intelligence Guide
A counterfeit is not a bad copy. It is a parallel supply chain with real factories, freight forwarders, payment processors and warehouses. Find the logistics and a brand problem becomes an organised crime case.
A counterfeit is not a bad copy. It is a parallel supply chain with real factories, freight forwarders, payment processors and warehouses. Find the logistics and a brand problem becomes an organised crime case.
What Counterfeiting & IP Crime covers as a mission domain
Counterfeiting and IP crime intelligence covers the manufacture, transit, financing and sale of goods infringing trademarks, copyright, patents or designs, together with adjacent offences such as falsified medicines, unauthorised streaming and industrial design theft. Analysts work three planes simultaneously: production, meaning factories, component suppliers and packaging or hologram printers; distribution, meaning consolidators, transhipment hubs, free trade zones and fulfilment centres; and retail, meaning marketplaces, social commerce, standalone webstores and encrypted-app storefronts. The task is linking seizure data, corporate records, domain infrastructure and payment endpoints to the organisers behind interchangeable seller accounts.
Harm profiles differ sharply by category. Falsified medicines and counterfeit aerospace or automotive parts are safety-critical; apparel and consumer electronics are volume-driven; cracked software and unlicensed streaming sit closer to cybercrime. Actors range from licensed factories running unauthorised third shifts, to family trading networks operating through free zones, to platform-native dropshipping operations that never touch stock, to organised groups reinvesting proceeds across other illicit trade lines.
Why it matters
Trade in counterfeit and pirated goods is measured by the OECD in the hundreds of billions of dollars annually and has grown faster than legitimate trade in several categories. The harms are concrete: deaths from falsified medicines and failed components, lost tax revenue, funding for organised crime, and the displacement of compliant manufacturers and their workforces. Unregulated counterfeit production is also a recurring site of forced and child labour.
What analysts actually look for
These are the concrete, observable signals that carry weight in this area of work:
- Newly registered companies sharing one registered-agent address that begin importing packaging, holograms or blank labels rather than finished goods.
- Marketplace sellers with divergent brand catalogues but identical return addresses, bank beneficiaries or product photography metadata signatures.
- Storefront domains registered in bulk on a single day, sharing certificate subject names, analytics identifiers or payment gateway merchant references.
- Import declarations that undervalue or misdescribe goods, or that split one container across multiple consignees registered at the same address.
- Free-trade-zone transhipment where goods are relabelled and re-exported with a changed declared origin and no manufacturing value added.
- Component procurement inconsistent with declared output, such as a small firm buying authentic-spec chipsets, zips or blister foil in industrial volumes.
- Social-commerce accounts advertising mirror, replica or tiered quality grades and migrating buyers to encrypted messaging for checkout.
- Repeat customs seizures naming different consignees but the same freight forwarder, HS code and routing sequence.
Where the data comes from
Authoritative and openly available collection points. Always confirm licensing and terms before operational or commercial use:
- EUIPO Observatory — Studies, enforcement statistics and the IP Enforcement Portal supporting cross-border rights-holder cooperation.
- OECD illicit trade series — Quantitative analysis of counterfeit trade flows, provenance economies and systematic transit hub misuse.
- USTR Notorious Markets List — Annual named list of physical and online markets facilitating large-scale counterfeiting and piracy.
- US CBP IPR seizure statistics — Seizure volumes by commodity, origin economy and rights holder, providing a baseline for trend work.
- WCO Illicit Trade Report — Global customs seizure data and routing analysis across counterfeiting and other illicit flows.
- Europol and EUIPO IP Crime Threat Assessment — Actor structures, distribution models and documented links to other organised crime in the EU.
- TMview and USPTO trademark registers — Ownership, class and status of marks, plus evidence of bad-faith or squatting registrations.
- Companies House and OpenCorporates — Officer, address and shareholding links between apparently unrelated importers and storefront operators.
A working method
A repeatable sequence beats ad-hoc searching. This is a practical starting workflow:
- Establish the authentic baseline — Document genuine specification, authorised manufacturers, packaging security features and legitimate distribution so deviation can be evidenced rather than asserted.
- Harvest the marketplace layer — Systematically collect listings, seller identities, prices and shipping origins across platforms, preserving screenshots with timestamps and full URLs.
- Cluster the infrastructure — Pivot on domains, certificates, trackers, payment beneficiaries and return addresses to collapse hundreds of sellers into a handful of operators.
- Test purchase and examine — Run controlled buys under instruction from counsel, then document packaging, routing labels, invoices and payment endpoints alongside a technical authenticity assessment.
- Trace the physical chain — Work backwards from shipping documents and seizure records to consolidators, forwarders and the production or repackaging site itself.
- Corporate and financial attribution — Resolve operators to registered entities, directors and bank beneficiaries, identifying the profit-taking layer above disposable seller accounts.
- Package for the chosen remedy — Produce a referral pack sized to the action sought: platform delisting, customs recordation, civil proceedings or criminal referral.
How this connects across the intelligence taxonomy
Intelligence work does not respect neat boundaries. The mission domain you are working, the disciplines you practise, and the data points you pivot on are one connected system. These are the direct relationships for this entry — every link is also a tag, so you can follow any thread across the whole library.
Practised with these disciplines
- Criminal Intelligence — Intelligence Supporting Criminal Investigation
- Corporate Intelligence — Understanding Companies, Structure, and Control
- Logistics Intelligence — Cargo, Freight, and Physical Movement
- Legal Intelligence — Law, Litigation, and Regulatory Intelligence
- Patent Intelligence — Patents, Filings, and Innovation Signals
- Economic Intelligence — Economic Conditions, Trade, and Market Signals
Worked in these data points
- Company / Organization — A legal entity — corporation, LLC, NGO, or business.
- Shipment / Bill of Lading — A consignment record linking shipper, consignee, goods, and route.
- HS Commodity Code — The Harmonized System code classifying a traded good — the key to trade-flow analysis.
- Domain Name — Human-readable address that maps to IP infrastructure via DNS.
- URL — Uniform Resource Locator pointing to a web resource.
- Patent — An intellectual property filing granting invention rights.
- Court Case / Docket — A filed legal proceeding — the authoritative record of disputes, judgments, and enforcement.
Adjacent mission domains
- Supply Chain Security
- Organized Crime
- Fraud & Identity
- Economic Espionage
- Border Security & Migration
Inside the platform: where Counterfeiting & IP Crime lives
The Quantus platform is 204 pages behind a 147-item sidebar organised into six working groups: Command (24 items), Dashboards (15), Threat Theaters (14), Intelligence Domains (15), Investigate (34), and Administration (45). This entry is not a page in isolation — it is a thread running through several of them.
The modules that matter most here:
domain.php?d=counterfeit— Counterfeiting & IP Crime dashboardtheater.php?d=counterfeit— Threat theater viewsearch.php— Company / Organization profileurl-profile.php— Domain Name profilecorrelate.php— Correlation graphcases.php— Case management
Each dashboard is local-first: it renders from the platform’s own database rather than depending on a live third-party call, so it still works when an upstream API is unreachable or rate-limited. Heavy aggregates are cached with a hard query time cap and degrade to the last good value instead of hanging the page.
Automation, playbooks and AI skills
Analysis that only happens when someone remembers to run it is not a capability. The platform ships a 30-step automation pipeline (cron.php) that collects, ingests, resolves, enriches, correlates and scores on a schedule — 25 seeders, 11 resolvers and 7 enrichment runners, all idempotent and cursor-based so a run can be interrupted and resumed without duplicating or losing work.
Relevant playbooks
Of the 14 incident playbooks in playbooks.php, these apply directly to Counterfeiting & IP Crime:
- Phishing Investigation & Takedown — a step-checked workflow with the pivots, sources and handling rules already wired in.
- Sanctions Screening & Escalation — a step-checked workflow with the pivots, sources and handling rules already wired in.
AI skills that apply
The 16 one-click operations in ai-skills.php are deterministic jobs, not free-text generation. The ones that matter here:
- Threat Hunt
- Correlate Infrastructure
- Run Alert Rules
- Summarise (Copilot)
- Generate Report
Alerting closes the loop: rules in alerts.php fire on new indicators matching a saved query, so a first sighting in this area raises a notification rather than waiting to be noticed at the next review.
Feeds, data sources and the API
The collection layer runs a feed registry of free, machine-readable sources — bulk blocklists and trackers (Maltrail, IPsum, FireHOL, the full abuse.ch corpora, phishing databases, Emerging Threats, Spamhaus, DigitalSide, ThreatView), authoritative government feeds (CISA KEV, OFAC, UN and EU sanctions lists), and reference datasets (RIR allocations, ip-to-ASN and geolocation tables, MITRE ATT&CK, EPSS). collect.php pulls them server-side on a schedule; feeds.php and source-catalog.php show what is registered, what it covers and when it last ran.
Anything the platform holds is reachable programmatically. The REST API in api.php exposes 11 endpoints — status, stats, search, lookup, recent, export, bulk_check, top_threats, by_category, categories, check — and export.php streams 18 formats in bounded chunks, so a million-row export neither exhausts memory nor times out:
STIX 2.1, MISP, OpenIOC 1.1, CEF (ArcSight), LEEF 2.0 (QRadar), Zeek/Bro intel, Snort/Suricata rules, Palo Alto EDL, BIND RPZ, hosts blackhole, iptables, CSV, JSON, NDJSON/JSONL, XML.
That covers the CTI standards (STIX 2.1, MISP, OpenIOC), SIEM ingestion (CEF, LEEF, Zeek), detection engines (Snort/Suricata), and direct enforcement (Palo Alto EDL, BIND RPZ, hosts, iptables) — so intelligence developed here can be actioned in the tools you already run, without a manual reformatting step. A TAXII 2.1 server and a MISP/RSS feed are also served for pull-based sharing.
Use cases
Three ways this entry earns its keep in day-to-day work:
- Triage under time pressure. An artifact or report lands and you need a defensible read in minutes, not days. Establish the authentic baseline is the first move; the platform pre-computes the enrichment so the analyst spends the time on judgement rather than lookups.
- Building the picture. A single indicator is rarely the story. Cluster the infrastructure turns one artifact into a network — shared infrastructure, repeated selectors, the same operator behind different names — via the correlation graph and the cross-entity link engine.
- Producing something actionable. Analysis that ends in a document nobody can use is wasted. Package for the chosen remedy feeds the case file, the detection rule, the block list or the referral — with sourcing attached so the recipient can verify it.
Case management (cases.php), watchlists, saved searches and scheduled reports mean the work persists between sessions and survives an analyst leaving the team.
How each sector uses Counterfeiting & IP Crime
The same entry is worked very differently depending on who you are, what authority you hold, and what you are ultimately producing. A military analyst is supporting a commander’s decision; a journalist is meeting a publication standard; an NGO caseworker is protecting a person. The underlying artifacts are shared — the constraints, outputs and thresholds are not.
🎖 Military and defence
Defence interest in counterfeiting is overwhelmingly about parts integrity. Counterfeit or falsified electronic components, fasteners, bearings and lubricants entering a defence supply chain create airworthiness, seaworthiness and ammunition-safety risk, and they arrive through legitimate distributors rather than through anything that looks criminal. The analytical product supports supplier qualification, counterfeit-avoidance requirements in contracts, and incident investigation when a part fails test. It also supports force protection where counterfeit medicines or vehicle parts are procured locally on deployment. Constraints are procurement law and contractual confidentiality: findings about a named supplier normally have to be routed through the contracting authority and the relevant defence quality assurance body rather than acted on unilaterally.
🕵 National intelligence
For national intelligence services the interest is threefold: revenue for organised crime and, in some corridors, for designated groups; the safety consequences of falsified medicines and aviation parts; and the state-tolerated production zones that indicate a broader governance picture. Requirements typically ask who organises rather than who sells. Fusion combines customs seizure data, financial intelligence, corporate registry work and platform-derived infrastructure indicators. Most of the material is unclassified or commercially sourced, which makes handling straightforward but raises questions about sharing back to industry. Dissemination usually runs to customs, law enforcement and, through sanitised channels, to affected rights holders and sector regulators.
👮 Law enforcement
Enforcement moves from seizure to organiser through documentary linkage. Evidential priorities are the consignment paperwork, the payment endpoint, the warehouse tenancy and the platform account registration data, each of which requires its own legal instrument. Expect production orders to platforms and payment processors, mutual legal assistance for foreign registry and hosting records, and search warrants timed against warehouse restock cycles. Rights-holder evidence of trademark validity and non-authorisation is required for most charges, so engage the brand early and formally. Charging decisions usually turn on control of the logistics node rather than on possession by a courier or seller, so build the tenancy, freight and payment chain deliberately.
🔍 Private investigation and corporate security
Brand protection and corporate security teams do test purchases, marketplace enforcement, supply-chain audit and litigation support. The core deliverable is a defensible chain from a purchased sample to a named operator: sample, invoice, packaging, shipping label, payment record and corporate registration, all preserved with continuity. Civil routes such as trademark actions, platform takedowns, customs recordation and freezing orders are usually faster than criminal referral. A private actor may not pretext to obtain communications data, hack a seller account, run covert surveillance in breach of local law, or misrepresent themselves as police. Overreach in a test purchase can also taint a later criminal case, so document the method precisely.
📰 Journalism and OSINT media
Investigations here reward physical verification: buy the product, test it, photograph the packaging codes, and trace the shipment. Verify factory attribution through more than a shipping label, since labels are routinely falsified and consolidators mix consignments. Corroborate any claim that a brand knew about a problem with documentary evidence rather than an anonymous account alone. Protect factory workers and warehouse insiders absolutely, as they face immediate dismissal and sometimes violence. Give named companies, platforms and regulators a genuine right of reply with enough specificity to respond. Where the story involves falsified medicines, weigh publication timing against the public-health value of prompt warning.
🌍 NGO, humanitarian and human rights
Public-health and consumer-protection organisations use this work to quantify harm from falsified medicines, unsafe electricals and adulterated food, and to press regulators and platforms for action. Do-no-harm means being careful that enforcement advocacy does not simply push informal livelihoods into more dangerous channels, particularly where counterfeit sale is a subsistence activity for vulnerable sellers. Documentation for accountability should record sampling method, chain of custody and laboratory results so findings survive industry challenge. Duty of care applies to field researchers doing test purchases in areas controlled by organised groups, and to informants inside production sites who carry the real risk.
🎓 University and research
Research spans economics of illicit trade, public health impact of falsified medicines, platform governance and network analysis of supply chains. Methodology must confront severe measurement problems: seizure data measures enforcement effort as much as flow, and industry loss estimates are frequently constructed on substitution assumptions that do not hold. Ethics approval is required for test purchasing, worker interviews and any covert method. Reproducibility is served by publishing sampling frames, coding schemes and analytical code, with sensitive identifiers withheld. Data sharing with rights holders raises independence questions that should be declared, and funding from affected industries must be disclosed in every output.
Playbook: working Counterfeiting & IP Crime end to end
A repeatable sequence, from the moment the requirement lands to the moment a product is delivered and the case is closed out. Each phase states what you are trying to establish, not merely what to click — the point is a defensible chain of reasoning, not a checklist.
Phase 1 — Scope the product and harm class
Fix what is actually being investigated: a safety-critical category such as medicines, aviation parts or electricals, or a volume category such as apparel and accessories. The harm class determines the tempo, the partners and the legal instruments available. Establish the genuine article's manufacturing footprint, authorised distribution and authentication features first, because you cannot recognise a counterfeit chain without knowing the legitimate one in detail. Output is a one-page product profile with authorised channels named. Stop when you can state exactly what a legitimate unit's paperwork should look like.
Phase 2 — Acquire and characterise samples
Buy through the channel you are investigating, preserving the listing, the transaction record, the packaging, the shipping label and the payment trail as a single evidential bundle. Photograph before opening. Where safety matters, submit for laboratory analysis against the genuine specification. The characterisation tells you which factory tier you are dealing with: a crude copy, a competent copy with the right components, or an unauthorised run of genuine goods. Stop when you can describe the manufacturing capability implied by the sample, not merely that it is fake.
Phase 3 — Map the online storefront estate
Cluster seller accounts, webstores, social commerce profiles and messaging storefronts by shared indicators: contact numbers, registration emails, image reuse, template code, hosting, analytics identifiers, certificate history and payment endpoints. The output is a set of clusters, each hypothesised to be one operator behind many faces. This is where most investigations either scale or drown. Stop when adding new listings stops adding new clusters and only adds volume to existing ones.
Phase 4 — Identify logistics and consolidation nodes
Follow the physical goods. Warehouse addresses on returns labels, fulfilment centre identifiers, freight forwarder names on air waybills, and free trade zone consolidators are the durable infrastructure of the trade, far more so than seller accounts. Corroborate through corporate registries, tenancy records, satellite imagery of the site and, where available, bill of lading data. The output is a named logistics node with an occupier and a transport pattern. That node is what an enforcement action can actually seize.
Phase 5 — Trace the payment layer
Establish how money leaves the buyer and reaches the organiser: merchant accounts, payment service providers, aggregators, remittance channels, and increasingly stablecoin settlement between wholesalers. Merchant identifiers and acquiring banks are recoverable from transaction records and are a strong clustering signal in their own right. This layer supports both civil freezing action and the criminal case. Stop when you have the acquiring relationship and the beneficiary entity, not merely the checkout page.
Phase 6 — Resolve corporate ownership
Take the entities surfaced by tenancy, freight, merchant and registration data through company registries, beneficial ownership registers where available, litigation records and trade databases. Look for the recurring director, the shared registered office and the family group operating several apparently unconnected trading companies. The output is an ownership graph linking storefronts, logistics and payment to a small number of natural persons. Stop when further registry work stops changing who sits at the top.
Phase 7 — Reconstruct the production tier
Work upward to manufacturing: component suppliers, packaging and hologram printers, and the factories running unauthorised shifts. Print and packaging suppliers are frequently the weakest link because their output is bespoke, traceable and lawful to produce, so their records exist. Import data on specialist inputs, machinery purchases and industrial estate imagery all contribute. Stop at the point where attribution rests on inference alone; a named factory in a report needs documentary support, not a matching label.
Phase 8 — Quantify scale and harm
Estimate volume from listings velocity, seizure records, shipment counts and warehouse throughput rather than from retail-value multipliers, which inflate figures and damage credibility. For safety-critical categories, document actual injury, failure or treatment-failure evidence separately from economic loss. The output is a defensible scale statement with its assumptions written down. Stop when you can explain, on one page, how each number was derived and what would falsify it.
Phase 9 — Select the disruption instrument
Match findings to the mechanism that will actually bite: platform delisting and seller-account termination, customs recordation and border detention, payment processor termination, domain suspension, civil trademark action with freezing relief, criminal referral, or regulatory action against a licensed manufacturer. Sequence matters, because a takedown can warn an operator before the seizure that mattered. Output is a sequenced disruption plan with owners and timings for each step.
Phase 10 — Execute and preserve for follow-on
Coordinate the action, and preserve everything at the moment of execution: site imagery, seized documentation, device inventories, financial records. Most organisers rebuild within weeks, so the value of an action lies as much in the material recovered as in the goods destroyed. Register the new indicators, including any identifiers reused during the rebuild, in the monitoring set immediately.
Phase 11 — Monitor for reconstitution
Watch for the same operator returning under new seller identities, a new domain generation, a different fulfilment address and a fresh merchant account. Reconstitution signatures are strong: image reuse, phrasing, packaging suppliers and the same courier account persist even when everything customer-facing changes. A good output is detection of the rebuilt estate within weeks rather than rediscovery a year later as if it were a new case.
Phase 12 — Feed prevention back into the business
Convert findings into changes that reduce future exposure: authentication features that are actually checkable in the field, distributor contract terms, authorised-seller programmes, procurement controls against counterfeit components, and consumer warnings for safety-critical categories. Enforcement alone never closes a category. Stop when each recommendation has an owner inside the affected organisation and a date.
The platform ships this as a step-checked workflow in playbooks.php, so progress is recorded against a case rather than held in someone’s head.
Source register: what to collect from, and how
Sources are listed with their access model so you can plan around cost and licensing before you build a dependency on them. Open means no account required; registration means a free account or API key; licensed means paid or institutional access. Always confirm current terms — licensing changes, and a source that was free for research may not be free for commercial or evidential use.
| Source | Access | What it gives you | How it is used here |
|---|---|---|---|
| EUIPO enforcement portal and studies | Open | European IP office research on counterfeiting scale, sector impact and enforcement, plus rights-holder tools. | Provides sector baselines and EU enforcement context for scoping and for quantifying claimed harm defensibly. |
| OECD illicit trade research | Open | Quantitative studies of trade in counterfeit and pirated goods using customs seizure data by economy and sector. | Supplies the methodological benchmark for scale estimates and identifies main transit and provenance economies. |
| WCO enforcement and IPR programme | Open | World Customs Organization guidance, seizure reporting frameworks and border enforcement standards. | Frames customs recordation strategy and interpretation of national seizure statistics across jurisdictions. |
| US Customs and Border Protection IPR programme | Open | Recordation system for trademarks and copyrights, seizure statistics and border enforcement guidance. | Enables border detention of infringing consignments and provides US-side seizure evidence for a case. |
| WIPO global IP records | Open | International trademark, patent and design registration data and treaty framework documentation. | Establishes rights validity and ownership across jurisdictions before any enforcement step is taken. |
| USPTO trademark and assignment records | Open | US registration status, ownership history and assignment records for trademarks and patents. | Confirms the rights holder of record and identifies licensing relationships that complicate authorisation claims. |
| WHO substandard and falsified medical products work | Open | Global surveillance and alert system for falsified medicines, with prevalence studies and member state alerts. | Establishes public-health harm and provides the recognised definitional framework for falsified medical products. |
| Europol and EUIPO joint reporting | Open | European threat assessments on intellectual property crime, including organiser structures and distribution methods. | Identifies which criminal structures and corridors are active in Europe for the product category under study. |
| INTERPOL illicit goods programmes | Open | International operational coordination on counterfeit goods and pharmaceutical crime, with operation reporting. | Routes cross-border referrals and identifies partner agencies for coordinated action through national bureaus. |
| OpenCorporates | Registration | Aggregated company registry data across many jurisdictions with officers, addresses and filing history. | Resolves the entities behind warehouse tenancies, merchant accounts and freight bookings into an ownership graph. |
| Companies House | Open | UK statutory registry with filings, officers, persons of significant control and charge registrations. | Identifies UK-registered fronts used for merchant acquiring, warehousing and platform account registration. |
| crt.sh certificate transparency search | Open | Searchable log of issued TLS certificates showing domain and subdomain issuance history over time. | Clusters storefront domains by shared certificate patterns and reveals staging or successor sites before launch. |
| urlscan.io | Registration | Records page structure, resources, redirects and infrastructure for submitted URLs, with historical search. | Fingerprints storefront templates and analytics identifiers to link apparently independent shops to one operator. |
| Pharmaceutical Security Institute | Registration | Industry body collating incident data on pharmaceutical counterfeiting, diversion and theft by region. | Benchmarks pharmaceutical incident patterns and identifies whether a case fits a known distribution method. |
| International AntiCounterfeiting Coalition | Registration | Industry coalition running platform cooperation programmes and publishing enforcement practice guidance. | Provides route into platform enforcement channels and comparative practice for brand protection programmes. |
| UNODC illicit trade analysis | Open | Research and treaty framework material on transnational organised crime including counterfeit goods flows. | Positions the case within organised crime typologies and supports policy or capacity-building recommendations. |
Prefer sources that publish a methodology and a revision history. A dataset that changes silently is a liability in any product that has to survive challenge.
Tooling
Tools commonly used against Counterfeiting & IP Crime. None of these replace judgement, and each carries its own failure modes — know what a tool infers versus what it observes.
- Marketplace monitoring platforms — Automated listing detection, image matching and takedown submission across major marketplaces. Limitation: optimised for volume takedown, and rarely surfaces the operator behind the accounts.
- urlscan.io and certificate transparency search — Fingerprints storefront infrastructure and issuance history to cluster shops. Limitation: shared hosting and commodity templates produce false clusters if used without corroboration.
- Bill of lading and trade data services — Shipment-level import records linking shipper, consignee and commodity. Limitation: coverage is strong for US imports and patchy elsewhere, and descriptions are routinely falsified.
- OpenCorporates and national registries — Resolves corporate entities, officers and addresses across jurisdictions. Limitation: beneficial ownership is frequently unavailable, and nominee directors defeat naive attribution.
- Maltego — Graphs relationships between domains, accounts, entities and phone numbers. Limitation: presentation makes weak links look strong, so link confidence must be recorded separately.
- Satellite imagery platforms — Confirms warehouse and factory activity, expansion and vehicle throughput at a suspected site. Limitation: revisit rates and cloud cover, and activity alone does not evidence infringement.
- Laboratory testing and spectroscopy — Establishes composition, dosage and material specification against the genuine article. Limitation: cost per sample, and accredited chain of custody is required for evidential use.
- Forensic sample and evidence management — Maintains continuity for test purchases, packaging and documents through to court. Limitation: entirely process-dependent, and a single undocumented handover can discredit the bundle.
- Image similarity and reverse search — Detects reuse of the same product photography across storefronts and platforms. Limitation: sellers now regenerate or perturb images specifically to break matching.
AI skills and automation in detail
These are deterministic jobs with defined inputs and outputs, not open-ended prompting. Each is idempotent and cursor-based: interrupt one and it resumes where it stopped rather than duplicating work or losing progress.
- Threat Hunt — Runs saved hypotheses against the corpus and surfaces what matches, with the query preserved as a versioned artifact.
- Correlate Infrastructure — Builds the cross-entity link graph: shared hosting, reused certificates, overlapping registrants, repeated selectors.
- Run Alert Rules — Evaluates saved rules against new data so a first sighting raises a notification rather than waiting for review.
- Summarise (Copilot) — Produces a narrative summary beside the underlying records. It explains; it never creates indicators or assigns attribution.
- Generate Report — Assembles a sourced product from the current case or query, with provenance attached to each element.
A note on the boundary: the only skill that involves a language model is Summarise (Copilot), and it writes prose about records that already exist. Nothing else on this list involves generation of any kind. No indicator, relationship or attribution in the platform originates from a model. See the full skill list.
Tradecraft notes
The distinctions that separate a competent analyst from a fast one:
- Chase the warehouse, not the listing. Seller accounts are disposable and cost nothing to replace, while a leased warehouse, a freight forwarder account and a merchant acquiring relationship are expensive, slow to rebuild and tied to real identities.
- Packaging and hologram printers are the softest node in the chain. Their work is bespoke, lawful to manufacture and therefore documented, and a single print order links a specific counterfeit run to a specific customer in a way no product sample can.
- Distinguish a competent copy from an unauthorised third shift. If components, tooling marks and materials match the genuine article, you are probably looking at a licensed factory producing off-books rather than a criminal workshop, and the response is contractual rather than criminal.
- Resist retail-value loss figures. Multiplying seized units by genuine retail price assumes every counterfeit buyer would otherwise have bought genuine, which is demonstrably false, and inflated numbers are the fastest way for a defence lawyer or a journalist to discredit an otherwise sound case.
- Reconstitution signatures beat detection signatures. Operators rebuild storefronts within weeks but keep couriers, packaging suppliers, product photography and phrasing, so monitor the durable artefacts rather than re-running detection against a fresh estate.
- Free trade zone consolidation is where attribution usually breaks. Goods arrive labelled one way and depart another, so treat any document generated inside a zone as an assertion to be corroborated against physical throughput and payment records rather than as provenance.
- In safety-critical categories, treat every case as a potential public-health incident from the first sample. The obligation to warn can arrive before your investigation is complete, and building the analysis in a form that can be split into an early warning and a later attribution product avoids an impossible choice later.
Measuring whether it is working
Capability claims should be falsifiable. These are the measures that show whether work on Counterfeiting & IP Crime is producing anything, and they are worth baselining before you change process or tooling.
- Proportion of enforcement actions that reach a logistics node or organiser rather than terminating at a seller account or courier.
- Median time from first detection of a new storefront cluster to identification of the payment endpoint and beneficiary entity.
- Reconstitution interval: how long an actioned operator takes to reappear, tracked over successive actions as a measure of real disruption.
- Share of safety-critical samples that reach accredited laboratory analysis with unbroken chain of custody.
- Reduction in verified consumer harm reports for a product category following a disruption campaign, rather than volume of listings removed.
- Percentage of scale estimates published with stated assumptions and a falsification test, as a measure of analytical credibility.
- Number of production or packaging suppliers identified and evidenced per campaign, since that tier determines whether supply is actually constrained.
Beware of measuring volume alone. Indicator counts and report counts rise easily and say little; time-to-attribution, proportion of findings that survive review, and how often a product changed a decision say a great deal.
Common pitfalls
- Confusing grey-market parallel imports with counterfeits; both irritate rights holders but only one is an intellectual property crime.
- Counting listings as sellers, when a single operator routinely runs dozens of storefronts and inflates apparent market size.
- Inferring manufacturing origin from shipping origin, when transhipment hubs exist precisely to break that link.
- Relying on product photographs, which are frequently scraped from genuine catalogues and prove nothing about the goods actually shipped.
- Prioritising high-volume apparel because the seizure metrics look impressive, while safety-critical categories go unworked.
Legal and ethical considerations
Test purchases, undercover accounts and platform scraping raise contract, computer-misuse and entrapment questions that vary by jurisdiction, so run them under instruction from counsel with a documented evidence-handling protocol. Rights-holder authentication opinions must be attributable to a named, qualified examiner if they are to survive challenge. Avoid defaming legitimate distributors with unverified counterfeit allegations, and remember that individual sellers and factory workers may themselves be exploited rather than principals worth pursuing.
Data integrity: no fabrication, no drift, no hallucination
Intelligence that cannot be traced back to a source is not intelligence, it is assertion. Everything in this entry — and everything in the platform behind it — is built on a small number of non-negotiable rules.
Provenance on every record
Every indicator carries the source that supplied it, a first-seen and last-seen timestamp, and a sighting count. Where several feeds report the same artifact, each contribution is recorded separately rather than collapsed, so you can see whether a finding rests on one source or twelve. Source attribution travels with the data into every export, so a recipient can audit a claim without asking you for the working.
Nothing is invented to fill a gap
If the platform has no data for Counterfeiting & IP Crime, it says so. Empty is displayed as empty — never padded with plausible-looking placeholder values, sample records or illustrative examples that a reader might mistake for observations. A dashboard with no rows is a true statement about collection coverage, and it is treated as a gap to close, not a blemish to hide.
Scoring is deterministic and reproducible
Threat scores, reputation grades and risk tiers are computed from stated inputs with fixed weights, not estimated. The same inputs always produce the same output, and the formula is visible rather than a black box. Aggregates are cached with an explicit time-to-live so a figure on screen is never silently stale — and when a heavy query exceeds its time budget the platform serves the last known-good value and labels it, rather than inventing a fresh number or hanging.
Where AI is used, and where it is not
Language models summarise and explain. They do not create indicators, assign attribution or manufacture relationships. No IP address, wallet, hash or identity in the platform originates from a model — every one is ingested from a named feed, resolved from a reference dataset, or entered by an analyst with a source recorded. Copilot output is presented as narrative alongside the underlying records, never in place of them, so a reader can always check the summary against the evidence.
Guarding against drift
Enrichment is additive and timestamped rather than overwriting. Reference data — sanctions lists, allocations, taxonomies — is re-synchronised from the authority on a schedule instead of being edited in place, so local copies cannot quietly diverge from the source of truth. Attribution is recorded with a confidence level and the reporting it rests on, and inferred relationships are labelled as inferred. When a source retracts or corrects, the correction propagates rather than leaving a stale assertion behind.
What this means for you
You can put a finding from this platform in front of a regulator, a court, a board or a partner agency and show where each element came from. That is the standard the tooling is built to — because in this work, being confidently wrong is more damaging than being usefully uncertain.
By the numbers
The taxonomy this entry belongs to is not a marketing list — it is the actual structure of the platform: 52 mission domains, 52 intelligence disciplines and 65 data points, each with a live dashboard behind it. Supporting that: 18 indicator types, 14 playbooks, 16 AI skills, 18 export formats and a 30-step automated pipeline.
This particular entry connects directly to 6 intelligence disciplines, 7 data points, 5 closely related entries — every one of them a tag you can follow, and a dashboard you can open.
Questions analysts actually ask
Why is takedown volume a poor measure of success?
Because listing removal is cheap for the operator and expensive for you. A serious seller replaces a terminated account within hours using pre-aged identities purchased for a few pounds, and the stock never moved. Volume metrics reward chasing the cheapest part of the adversary's cost base while leaving the warehouse, the freight account and the payment relationship untouched. Measure instead how often you reach a logistics or payment node, how long an actioned operator stays down, and whether verified consumer harm falls. Those numbers are smaller, harder to move and far more honest about whether anything has changed.
How do you tell counterfeit from grey-market parallel import?
Parallel imports are genuine goods sold outside authorised channels, which is a contractual and sometimes trademark issue but not a forgery. Check batch and serial codes against the manufacturer's records, examine whether packaging and language variants match a real production run for another market, and look for evidence of removed or obscured tracking codes, which is a strong grey-market indicator. Getting this wrong is expensive: pursuing a parallel importer as a counterfeiter invites a well-funded counterclaim, while dismissing counterfeits as grey market lets a safety problem persist. Test the goods before you characterise the channel.
What legal instruments actually stop goods at the border?
Customs recordation of the relevant trademarks and copyrights in each destination market, supported by a rights-holder training pack that lets officers recognise the genuine article quickly. Recordation is what allows detention on suspicion without a court order. Beyond that, a specific application for action naming shipment indicators, consignee names and routes will substantially raise detection rates. Border action is a filter, not a solution, since detection rates on parcel traffic are low by volume, but it generates the seizure evidence that supports later criminal and civil proceedings, and the consignee data is often the best route into the logistics layer.
Can private investigators lawfully make test purchases?
Generally yes, and it is standard brand-protection practice, but method matters. Purchase openly through the normal channel, record the listing and transaction, and avoid inducing the seller to produce something they were not already offering, which can taint the evidence and in some jurisdictions raises entrapment arguments. Do not misrepresent yourself as a law enforcement officer, do not pretext to obtain communications or account data, and do not access seller systems. Where the purchase crosses a border, check import legality for the product class, particularly for medicines and controlled electronics, before ordering anything.
How much does organised crime really overlap with counterfeiting?
More at the logistics and financing layers than at the production layer. Factories are often ordinary manufacturers taking unauthorised orders, while the movement, consolidation, payment and warehousing infrastructure is frequently shared with other illicit trade lines, because the same freight relationships and merchant accounts serve any high-margin contraband. That is why logistics-focused investigation frequently surfaces links to unrelated commodity flows. Claims that counterfeiting funds terrorism should be evidenced case by case rather than asserted, since the general claim is often made and rarely documented to a standard that survives scrutiny.
What is the fastest way to link many storefronts to one operator?
Look for artefacts the operator does not think of as identifying. Reused product photography including background and lighting, identical error strings or template comments in page source, shared analytics or advertising identifiers, certificate issuance patterns, the same returns address on packaging, the same courier account number on labels, and identical phrasing in customer service messages. Any one of these is weak; three or more converging is strong. Record the confidence of each link separately rather than merging everything into a single graph, because you will be asked in court which link carries the weight.
Standards, frameworks and further reading
Work that references a recognised framework is easier to defend, easier to hand over, and easier for a partner to consume:
- TRIPS Agreement, which sets minimum standards for intellectual property enforcement including border measures and criminal procedures for wilful trademark counterfeiting on a commercial scale.
- WHO member state mechanism on substandard and falsified medical products, which defines terminology and coordinates surveillance and alerts.
- EU Regulation on customs enforcement of intellectual property rights, which governs applications for action and detention procedures at the EU border.
- US Customs and Border Protection recordation framework under the Lanham Act and Copyright Act, which enables border detention of infringing goods.
- AS6081 and related aerospace standards on counterfeit electronic parts avoidance, which set supplier and testing requirements for defence and aviation procurement.
- ISO 12931 and the ISO 22380 series on product fraud countermeasures and authentication solution performance criteria.
- UNTOC, the UN Convention against Transnational Organized Crime, which provides the mutual legal assistance and extradition framework for cross-border cases.
- OECD due diligence guidance for responsible business conduct, which frames buyer obligations where counterfeit or unauthorised production is found in a supply chain.
References
Primary sources and authoritative references for this entry. Publishers revise and retire material, so treat the retrieval date as part of the citation and re-check before relying on any of it in a formal product.
- Global Trade in Fakes research series — OECD and EUIPO. Quantitative studies of counterfeit trade flows built from customs seizure data.
- Intellectual Property Crime Threat Assessment — Europol and EUIPO. European assessment of IP crime structures, distribution and enforcement priorities.
- Substandard and falsified medical products programme — World Health Organization. Global surveillance framework and prevalence research on falsified medicines.
- IPR seizure statistics and recordation guidance — US Customs and Border Protection. Annual border seizure data and the mechanism for rights-holder recordation.
- Illicit trade and IPR enforcement guidance — World Customs Organization. International customs standards and reporting frameworks for counterfeit goods.
- Illicit goods and pharmaceutical crime operations — INTERPOL. Coordinated international operations against counterfeit and falsified products.
- Global IP registration systems — World Intellectual Property Organization. International registration and treaty framework establishing rights across jurisdictions.
- Transnational organized crime conventions and analysis — UN Office on Drugs and Crime. Legal framework and typology research underpinning cross-border enforcement cooperation.
Link integrity: every reference above was verified with a live request when this page was generated. Where a publisher had moved or withdrawn a document, the link was repointed at a preserved copy in the Internet Archive and marked as archived. Anything with no reachable copy anywhere had its link removed rather than left to rot — the source is still credited, it simply cannot be linked.
Put it into practice
The Quantus Intel threat intelligence platform operationalises this entry: collapses thousands of interchangeable sellers into the few operators and factories actually worth pursuing. Explore the platform, or browse the rest of the library by following any tag above.