Many brands add a QR code to their packaging and tell consumers to "scan to check it's genuine". It feels like a security feature. But a QR code is simply a pattern of printed squares, and anything printed can be copied. This article explains why a scan alone cannot prove a product is genuine — and what actually helps.
Copying is the easy part
A QR code stores data, usually a web address. Anyone with a phone can read that data, and anyone with a printer can print the same data in a new code. The copy is not a degraded imitation: it carries exactly the same content and scans exactly the same way.
So a counterfeiter does not need to break anything. They buy one genuine pack, photograph its code, and print it on a thousand fake packs. Every one of those fakes will open the same page as the original.
This applies equally to marketing QR codes, codes with a GS1 Digital Link and any other 2D barcode. The format describes what data is carried and how to read it; it is not a security mechanism.
What a scan actually tells you
It helps to separate three things a scan can establish, because they are often blurred:
| What is checked | What it shows | What it does not show |
|---|---|---|
| The code decodes | The printed pattern is readable | Anything about the product |
| The identifier is valid | The GTIN or serial exists and is correctly formed; it may be registered to the brand | That this physical item is the one that number was assigned to |
| The item is authentic | The physical product came from the brand | — this needs more than a scan |
Standards bodies are careful about this line. Verified by GS1 checks whether a number is properly structured, issued by GS1 and licensed to a particular company — it is about the number, not the item. The GS1 Web Vocabulary includes a link type, gs1:verificationService, that a resolver can point to; it is for verifying the status of an identifier, not the authenticity of a product. GS1 does not define a link type that proves authenticity.
We draw the full distinction between verification and authentication in product verification vs authentication.
What does help
No single control proves authenticity. What works is a set of layers, each making counterfeiting harder, riskier or easier to catch.
1. Unique, random serials
With serialization, every genuine unit carries its own serial number. That changes the counterfeiter's position: instead of copying one code that is legitimately printed on millions of packs, they must copy individual unit codes — and every copy is a duplicate of one real unit.
Serials should be random and non-sequential, so that valid ones cannot be guessed. Random serials do not stop copying; they stop invention. See what is product serialization?
2. Server-side scan rules
Because every scan reaches the brand's server, the server can apply rules to the scan history of each serial:
- First-scan logic. The first scan of a serial is recorded; later scans of the same serial can be shown a different message ("this code has been scanned before — where did you buy it?").
- Duplicate detection. One genuine pack is scanned a handful of times. A serial scanned hundreds of times is a strong sign it has been copied.
- Geographic and time anomalies. The same serial scanned in two distant cities within a short window cannot be one physical pack.
- Channel signals. Scans in markets a unit was never shipped to can reveal diversion. See how consumer scans can reveal channel and diversion signals.
Note the limit: these rules detect copies after they are scanned. The first scan of a copied code may look perfectly normal. That is why the response to a flagged scan matters as much as the flag.
3. A hidden second factor
Some programmes add something the counterfeiter cannot see by photographing the outside of the pack — for example, a second code under a scratch-off panel or inside the carton, which must match the outer code. A copied outer code without the matching hidden value fails. This raises the cost of copying; it does not make copying impossible, especially if hidden values are exposed at retail.
4. Physical packaging security
Tamper-evident seals, special inks, holograms and hard-to-reproduce printing can make the pack itself harder to fake. These are separate from the code, and they are often what inspectors and investigators check when a scan raises an alarm.
5. Investigation and enforcement
Data only matters if someone acts on it. Flagged scans should feed a process: review the pattern, test-purchase from the suspicious location, involve distributors or authorities. Many anti-counterfeit programmes succeed because they turn consumer scans into leads for investigators, not because any one scan is decisive.
A worked example
Maison Ardent, a fictional perfume house, prints a unique, random serial in a QR code on every bottle. A consumer in one city scans a bottle and sees the product page with "first verification of this code". Two days later, the same serial is scanned 140 times across three other cities.
The server flags the serial as a probable copy. Later scanners see a warning and are asked where they bought the product. Maison Ardent's brand-protection team sees most reports name one online seller, makes a test purchase, and confirms counterfeits.
Notice what happened. The QR code did not prove anything about any single bottle. The combination of a unique serial, a server watching the scan history, consumers reporting where they bought, and a team following up is what found the counterfeits. For how brands design these programmes, see how serialized QR codes support anti-counterfeit programmes.
How to talk about it honestly
What you tell consumers matters, both for trust and because overclaiming can backfire when a copied code shows "genuine".
- Describe what the check does: "This code is registered to us and this is its first scan."
- Explain what a warning means and what to do: where to report, how to get help.
- Avoid wording such as "100% authentic" or "guaranteed genuine" next to a scan result.