Back

Traceability & Supply Chain Transparency

Why Genuine Products Are Still Brand Protection Problem

Eugenia Vitali


28 Jul 2026

stone parallel

What authentication catches

Fakes and clones

  • Products made without brand authorisation
  • Chips generating invalid cryptographic responses
  • Cloned identifiers on replica packaging
  • Counterfeit formulations in fake containers

What authentication misses

Genuine product threats

  • Real products in unauthorised markets
  • Genuine bottles refilled with inferior content
  • Authentic items sold outside allocated channels
  • Products with no verifiable ownership history

The Blind Spot at the Centre of Most Brand Protection Programmes

Ask the head of brand protection at almost any luxury, spirits, or prestige beauty company what they are protecting against and the answer is, with minor variation, counterfeit goods. Fakes. Products manufactured without authorisation to deceive consumers into believing they are buying the genuine article. The brand protection budget, the legal team, the authentication infrastructure, the customs partnerships all of it is oriented toward detecting and removing products that are not real.

This orientation is not wrong. Counterfeiting causes significant and well-documented commercial damage: lost revenue, brand equity erosion, consumer safety risks in categories like cosmetics and spirits, and the operational and legal costs of enforcement. Fighting counterfeits is a legitimate and necessary investment.
What it misses is the class of threats that come from genuine products. A bottle of whisky that is real, distilled at the right distillery, bottled at the right abv, carrying the brand’s authentic label and closures, can still damage the brand if it was purchased in a duty-free market and resold in a premium domestic market at a price that undercuts the brand’s pricing architecture. It is genuine and it is a problem. A luxury perfume bottle that is authentic — manufactured by the brand’s authorised packaging supplier, filled with the correct formula, is still a problem if it was emptied, refilled with a cheaper fragrance oil, resealed, and put back on sale. A genuine limited-edition handbag is still a problem if it changes hands through a resale platform without any verified ownership history, because the brand has no visibility into secondary market dynamics and no direct relationship with the new owner.

 

The test that reveals the gap: Tap a grey market bottle of cognac with an NFC authentication system. It reads: genuine. Tap a refilled bottle whose closure has been resealed after filling with an inferior brandy. If the container is authentic and the chip is intact, it reads: genuine. Tap a handbag that was purchased in Seoul and resold in Paris outside the brand’s authorised distribution. It reads: genuine. In all three cases, authentication delivers the correct answer to the wrong question. The products are genuine. The brand protection problems are real.

Five Brand Protection Threats That Come from Genuine Products

1. Grey market diversion: genuine products in the wrong territory
Pricing architecture and distributor trust

A genuine product purchased in a lower-price market — through travel retail, an emerging market allocation, or a territory with a favourable currency position — and resold in a premium market at a price below the brand’s authorised regional pricing. The product is completely authentic. The damage is to the brand’s pricing architecture: sustained grey market availability establishes a lower consumer reference price in the premium market, erodes authorised distributor margins, and distorts the demand intelligence the brand uses to make allocation decisions.

Why authentication fails here: Authentication confirms the product is genuine. It says nothing about whether the product is where it is supposed to be, or whether it arrived through an authorised channel. A grey market product passes every authentication check because it is real.

What addresses it: Item-level serialisation with territory allocation at production. Real-time geographic scan event monitoring that flags units in territories inconsistent with their allocation. Chain-of-custody records that identify which distribution partner last held the unit before the anomaly.

2. Refill and reuse fraud: genuine container, fraudulent content
Consumer safety and product integrity

A genuine empty container — a premium spirits bottle, a prestige fragrance flacon, a luxury skincare jar — is acquired, filled with inferior, diluted, or counterfeit content, resealed, and resold as the genuine product. The container is authentic. The closure may be authentic. The visual presentation is indistinguishable from the real product. The contents are not. In premium spirits, this threatens consumer safety as well as brand equity — a consumer who purchases what they believe is a genuine aged whisky and experiences an inferior product, or worse a product containing harmful substitutes, represents a brand damage event regardless of whether the brand is legally culpable.

Why authentication fails here: If the NFC chip or authentication marker is on the genuine container, and the container is genuine, authentication returns a positive result. The chip does not know what is inside the bottle. Standard authentication evaluates the container, not the contents.

What addresses it: Tamper-evident NFC seals that register a permanent first-open event when the closure is broken for the first time. A bottle that has been opened, refilled, and resealed shows a first-open event at an unexpected time and location — a flag that the product has been interfered with. Combined with geographic anomaly detection, resealing patterns become visible in the scan event data.

3. Unauthorised channel: sale genuine products outside sanctioned distribution
Distribution control and exclusivity positioning

A genuine product reaches a consumer through a channel the brand has not authorised for that product’s sale. This may be a discounting platform that undermines the brand’s premium positioning, an online marketplace where the brand has not established a presence, or a territory where the brand sells through a selective distribution network and the product has been acquired outside that network. The consumer receives a genuine product. The brand’s exclusivity positioning, pricing discipline, and control over the consumer experience are compromised. Selective distribution is a legal mechanism brands use to protect quality and positioning — a genuine product sold outside the authorised network may constitute a violation of that system.

Why authentication fails here: The product is genuine. A consumer scanning it at a discounting platform receives confirmation of authenticity, which validates their confidence in the grey or unauthorised channel rather than directing them to authorised distribution.

What addresses it: Scan event logging that identifies the context of authentication interactions — geographic location, timing, and frequency patterns that indicate retail or resale contexts outside authorised channels. Backend rules that flag scan events inconsistent with authorised distribution patterns for that product and territory.

4. Resale without provenance: genuine products with unknown histories
Secondary market trust and brand equity

A genuine product changes hands through the secondary market with no verifiable history of ownership, storage, or condition. For categories where provenance matters commercially — fine wine, collector spirits, pre-owned luxury goods — the absence of a verifiable chain of custody affects resale value, consumer confidence, and the brand’s ability to participate in and benefit from secondary market activity. A brand that has no visibility into secondary market transactions for its products cannot understand the secondary market dynamics affecting its primary market pricing, cannot build certified pre-owned programmes at scale, and cannot develop a direct relationship with the new owners of its products after the first sale.

Why authentication fails here: Authentication at the point of resale confirms the product is genuine at that moment. It cannot confirm who owned it before, how it was stored, whether it was serviced, or how many times it changed hands. Provenance requires a persistent record, not a point-in-time authentication event.

What addresses it: Item-level digital identity that persists through ownership transfers, accumulating a timestamped record of each registered owner, each service event, and each authentication interaction across the product’s lifecycle. Ownership transfer functionality that allows each new owner to register against the product’s existing identity record, building a verifiable provenance chain accessible from the product itself.

5. Demand intelligence distortion: genuine over-ordering for diversion
Supply chain integrity and commercial planning

An authorised distributor over-orders product relative to genuine local consumer demand because the price differential between their market and another creates a diversion opportunity. The product is genuine, the entire ordering and delivery process is authorised. But the sell-in data the brand receives from that market overstates genuine local demand. Production and allocation decisions made on that basis, manufacturing more product for the source market, underallocating to genuine high-demand markets,compound the commercial damage of the diversion with supply chain misalignment that affects product availability, freshness, and sell-through across the range.

Why authentication fails here: Authentication is a consumer interaction at the end of the distribution chain. It does not observe ordering behaviour, cannot detect over-ordering at the distributor level, and arrives at the moment of consumer interaction rather than at the point in the supply chain where the distortion is introduced.

What addresses it: Item-level scan event data that reveals where products actually reach consumers, compared against the sell-in volumes reported for that market. When units ordered by a market are being authenticated by consumers in a different market, the discrepancy between reported local demand and actual consumer location is visible in the scan event record — earlier than any aggregate sell-through analysis would reveal it.

Why Brand Protection Needs to Cover the Full Product Lifecycle

The common thread across all five genuine product threats is that they occur after the point at which standard authentication is typically applied  at or after the first sale, in the distribution chain, or in secondary markets. A brand protection programme that focuses on detecting fakes at point of sale is protecting one moment in a product lifecycle that spans years and multiple ownership changes. The threats that come from genuine products unfold across the entire lifecycle.

Lifecycle Stage: Production
Genuine product threat: Over-commissioning creating surplus for grey market
Capability required: Serialised identity per unit with territory allocation

Lifecycle Stage: Distribution
Genuine product threat: Over-ordering by distributors, diversion at custody transfer
Capability required: Chain-of-custody event logging per unit identifier

Lifecycle Stage: First sale
Genuine product threat: Unauthorised channel sale undermining selective distribution
Capability required: Scan event context monitoring of channel and geographic pattern

Lifecycle Stage: Consumer Use
Genuine product threat: Refill and reuse fraud – genuine container, fraudulent content
Capability required: Tamper-evident first-open event registration via NFC seal

Lifecycle Stage: Secondary marke
Genuine product threat: Resale without provenance, grey market arbitrage chains
Capability required: Persistent ownership record with transfer event logging

Lifecycle Stage: End of life
Genuine product threat: Container reuse enabling refill fraud at scale
Capability required: Decommissioning event and disposal record in product identity

The infrastructure implication: Full-lifecycle brand protection requires a persistent product identity — not a one-time verification event. An NFC chip that generates a unique authentication response at point of sale is necessary. It is not sufficient. The same chip needs to log every subsequent interaction across the product’s life, accumulate a custody and ownership record, and surface anomalies at every lifecycle stage where genuine products can create brand damage. This is connected product infrastructure, not authentication infrastructure. The distinction matters commercially because the investment is the same but the protection coverage is fundamentally different.

How Genuine Product Threats Manifest Across Luxury Sectors

The five threat types above are universal. Their relative commercial significance differs by category: refill fraud is more prevalent and more dangerous in spirits than in fashion; grey market diversion is more damaging in fragrance than in watches where service relationships matter. Here is how the genuine product threat landscape looks in the categories where Selinko operates.

  1. Premium spirits and fine wine
    Refill fraud is the primary genuine product threat — genuine bottles of aged Scotch, cognac, or fine Bordeaux refilled with cheaper liquid and resealed. The consumer safety dimension makes this a regulatory risk as well as a brand risk. Grey market diversion from travel retail and duty-free channels is extensive, particularly for prestige expressions. Fine wine provenance — storage history, ownership chain — is a direct determinant of auction value, making resale-without-provenance a significant commercial issue for collector expressions. NFC tamper-evident seals that register first-open events address the refill threat directly; geographic scan monitoring addresses grey market diversion.
  2. Prestige beauty and fragrance
    Grey market diversion through travel retail and emerging market price differentials is the dominant genuine product threat — genuine fragrance and skincare flowing from lower-price markets to premium markets at prices that undercut regional pricing architecture. Refill fraud in fragrance — genuine bottles refilled with cheaper fragrance oil — is growing as premium fragrances reach higher resale values. The combination of small product size, high value-to-weight ratio, and persistent regional price differentials makes prestige beauty one of the most diversion-prone categories in any luxury portfolio.
  3. Luxury fashion and leather goods
    Resale without provenance is the primary genuine product threat — genuine luxury items changing hands in the secondary market without verifiable ownership history, service records, or brand-certified provenance. Grey market diversion through daigou buying networks — professional buyers purchasing in lower-price markets for resale in premium markets — is significant and growing. Unauthorised channel sale, particularly through online marketplaces operating outside selective distribution frameworks, undermines the brand positioning and consumer experience control that selective distribution is designed to protect.
  4. Watches and fine jewellery
    Resale provenance is commercially critical — a watch with a complete, verifiable service history and ownership chain commands a measurable premium over an equivalent reference without documentation. Grey market diversion, particularly of limited allocations from authorised dealers to resale markets, distorts pricing and undermines the allocation discipline that creates collectible value for specific references. Demand intelligence distortion through dealer over-ordering — acquiring allocation with the intent to sell to grey market buyers rather than genuine end consumers — is a structural feature of the category that affects brand supply planning.
  5. Premium footwear and limited editions
    Grey market diversion through professional buying — acquiring limited releases at retail for immediate resale at premium prices — is the dominant genuine product threat. The products are genuine; the issue is that they move through resale channels at prices and in volumes that distort the brand’s ability to manage allocation to genuine consumers, undermine the exclusivity positioning that justifies the premium, and generate grey market price references that affect primary market strategy. Resale without provenance, particularly for high-value collector expressions, is increasingly commercially significant as secondary market values rise.

What Connected Product Infrastructure Changes About Genuine Product Threats

The common requirement across all five genuine product threat types is a persistent, per-unit identity that accumulates data across the product’s lifecycle rather than providing a single verification event at point of sale. Connected product infrastructure, NFC chips generating unique identifiers, cloud records storing lifecycle events, real-time geographic anomaly detection, addresses this requirement in ways that authentication-only approaches cannot.

The transition from authentication to connected product infrastructure is not a replacement of the authentication function — it is an extension of it. A product that has a connected identity is still authenticated every time a consumer taps it. But the tap also generates a scan event that is compared against the product’s territory allocation, logged in the custody chain, evaluated for first-open tamper evidence, and accumulated into a provenance record that grows more valuable with every interaction.

For the brand, this means that the commercial returns from connected product infrastructure compound over time in a way that static authentication does not. After three months, the brand has a map of where its products reach consumers. After one year, it has a picture of grey market route patterns, refill fraud clusters, and secondary market activity for individual product lines. After three years, it has a data asset, behavioural intelligence on genuine product flows across its entire portfolio that cannot be purchased, cannot be replicated retrospectively, and that informs pricing architecture, distribution strategy, and allocation decisions with an evidence base that did not previously exist.

The brand protection argument for connected products that goes beyond counterfeiting: A brand that deploys NFC authentication to fight fakes has built infrastructure that catches one category of threat. A brand that deploys connected product identity — with territorial allocation, custody chain logging, first-open event recording, and ownership transfer capability — has built infrastructure that catches fakes as a by-product while simultaneously addressing the genuine product threats that authentication alone cannot reach. The infrastructure cost is similar. The coverage is fundamentally different. For brands where grey market diversion, refill fraud, or secondary market opacity is a material commercial problem, the capability gap is the more commercially significant investment argument.

Protect what authentication cannot.

Selinko’s connected product platform gives brands item-level visibility across the full product lifecycle — genuine product threats included. Grey market detection, refill fraud prevention, ownership provenance, and post-sale intelligence from the same NFC infrastructure.

Brand protection is not just a counterfeiting problem. Genuine products — real, legally manufactured, fully authentic — create brand equity damage through grey market diversion, refill fraud, product diversion, and resale without provenance. Here is the full picture of why authenticity alone is not enough.

FAQs

Why are genuine products a brand protection problem?

Genuine products create brand protection problems when they appear in the wrong context: the wrong market, the wrong channel, the wrong condition, or without a verifiable history. Grey market diversion sends genuine products to territories where the brand has not authorised their sale, undermining regional pricing. Refill fraud uses genuine containers filled with inferior content that passes authentication because the container is real. Territorial allocation violations damage distributor relationships. Resale without provenance exposes buyers to risk. In all of these cases, a standard authentication check returns “genuine” — because the product is. The problem is not what the product is, but where it is, how it got there, and what has happened to it.

How does item-level product tracking address threats from genuine products?

Item-level connected product tracking addresses genuine product threats by monitoring where products are and what has happened to them — not just whether they are authentic. A unique digital identity per unit, geographic scan event logging on every consumer interaction, chain-of-custody records, tamper-event registration, and ownership transfer capability together create a real-time picture of product location and history that authentication alone cannot provide. When a genuine product appears in a territory it was not allocated to, or its first-open event is logged at an unexpected time, or it changes ownership without a formal transfer record, the anomaly is visible in the connected product data — even though the product would pass any authentication check

Why does brand protection need to cover the full product lifecycle?

Authentication at point of sale confirms a product is genuine at one moment. It says nothing about what happens after — whether the product is diverted to an unauthorised market, whether the bottle is refilled, whether it is resold without provenance, or whether it enters a grey market channel that undercuts authorised pricing. Brand protection covering the full lifecycle — from production through first sale, use, service, resale, and end of life — captures threats at every stage where genuine products create commercial damage. This requires connected product infrastructure: an NFC identity that persists through every ownership change and logs every interaction, not a one-time verification event at retail.

What is refill fraud in luxury goods and spirits?

Refill fraud is the practice of acquiring a genuine empty container — a luxury fragrance bottle, a premium spirit bottle, a prestige cosmetic jar — filling it with inferior or counterfeit content, and resealing it for resale as the genuine article. The container is authentic and passes visual inspection and NFC authentication. The contents are not what they claim to be. NFC tamper-evident seals that register a permanent first-open event when the closure is broken for the first time detect refill fraud: a resealed bottle shows a first-open event at an unexpected time and location, flagging that the product has been interfered with after its original closure.

Get in Touch

Blog

Discover more articles

All our articles