Blog

Beyond Product Authentication: When Every Scan Becomes Risk Intelligence

August 18, 2026

How Digimarc Supports Diversion Detection and Continuous Risk Intelligence

Summary:
Product authentication is only part of the brand protection challenge. This blog explains how Digimarc's covert digital identifiers and Illuminate® platform transform authentication scans into actionable risk intelligence, helping pharmaceutical brands detect diversion, identify emerging threats, and gain real-time visibility across their supply chains.

Key Takeaways:

  • Brand protection teams need ways to detect diversion, not just counterfeits, so they can answer pressing questions such as: Where is our exposure concentrated?  Which markets and distributors show anomalous patterns?  And what leading indicators can we act on before a recall is triggered?
  • Digimarc's covert authentication layer for packaging works alongside DSCSA-compliant serialization and EPCIS data exchange systems to address product authentication gaps that serialization alone was not designed to detect, including cloned visible credentials and unauthorized market movement.
  • Brands can link our embedded, scannable, package-level identifiers to metadata in the Illuminate® platform, such as intended market and authorized channels.
  • Every time package identifiers are scanned to authenticate products across supply chains and in stores, data about location, timing, and verification data is captured and aggregated for faster, earlier detection of anomalous patterns, geographic hotspots, and indicators of potential counterfeiting or diversion.

Digimarc has been at the forefront of product authentication innovation for decades, offering a covert digital identification and authentication layer that embeds covert digital identifiers into packaging inks and varnishes that counterfeiters can’t re-originate. Implementation requires no visible change to the existing physical product packaging or manufacturing process—but it transforms the product authentication process. Brand inspectors simply scan packaging with a phone camera running Digimarc’s Validate app for instant, high-confidence verification against brand records, anytime and anywhere.

This digital authentication capability can complement and strengthen serialization and traditional, overt physical security features such as 2D bar codes, specialized inks, and holograms.  But the technology platform our solution runs on can also support other critical needs for brands. For example, in industries such as pharmaceuticals, we’re seeing an evolution that cybersecurity underwent a decade ago: what started as a compliance-and-enforcement function is increasingly becoming a source of much-needed risk intelligence. Pass/fail catch rates and periodic seizure reports are great, but today, executives, general counsel, and enterprise risk functions are asking harder questions such as:

  • Where is our exposure concentrated?
  • Which markets and distributors show anomalous scan patterns?
  • What leading indicators can we act on before a recall is triggered?  

Answering these types of questions requires data that does more work than authentication alone—or serialization or spot-checks—were ever designed to do.

The good news is that the same cloud architecture that Digimarc uses to help close the counterfeit-detection gap explored in our white paper, The Counterfeit Detection Gap: How Pharma Brand Protection Quietly Became a Liability Question, can also be the source of risk-intelligence data needed to answer these questions. When one of our covert, unique digital identifiers is embedded into the packaging of each unit as it’s manufactured in a supported implementation, it can be linked to a data record in our cloud-based Illuminate® platform, where brands can associate data such as production date, batch, intended market, authorized channel, distributor of record, and any other supported data field.

This means the same brand inspector, supply chain monitor, or in-store worker or customer scan that verifies the detected identifier and associated data in the field can also enable diversion detection and continuous risk intelligence across the distribution network. Scan data from the field can be aggregated centrally through the Illuminate platform, where it can be enriched with any product-level metadata the brand chooses to associate with metadata stored on the Illuminate platform, such as intended market, authorized channel, production date, batch, or distributor of record.

This turns authentication scans into a live risk view into geographic clustering of failed verifications, diversion patterns surfaced automatically when a unit is scanned outside its authorized market, and leading indicators of counterfeiting activity that surface weeks before conventional recall triggers would fire.

Let’s take a closer look at these opportunities.  

Monitoring and Detecting Product Diversion

A pure authentication check answers one question:  Does the detected identifier and associated data match brand records? It does not answer a second question that is often just as consequential: Is this package where it’s supposed to be?

The IMFINZI cases described earlier in this paper illustrate the point directly. Two of the falsified batches identified by the World Health Organization carried genuine lot numbers—lots that AstraZeneca had authorized for distribution only in India and Egypt. But they were reused on product diverted far outside those markets. A check that relies only on cloned or legitimate-looking lot-level data may not flag the issue, because the underlying  lot data may appear valid even when used on a counterfeit package. The failure mode is not counterfeiting in the strict sense. Rather, it is authorized product surfacing in the wrong market, sometimes with falsified packaging built around it, and sometimes not.

When Digimarc’s covert identifier is embedded into a product’s packaging during production and associated with metadata on the Illuminate platform (for example, about its intended market and authorized channel), brands can use the data captured in the field (from scans carried out by inspectors, supply chain players, and even pharmacists) to compare this data against where and when the scan is actually happening.

So, a unit authorized for Egypt, scanned by a distributor in Uzbekistan, can flag immediately — even where a serialization or lot-level check, taken in isolation, may not reveal the market mismatch. This is the diversion-detection capability that lot-and-batch data alone cannot deliver, because lot-and-batch records were never designed to encode geographic authorization at the unit level.

Want to learn more about how Digimarc can help your brand extend covert, package-level authentication for diversion and real-time risk intelligence?

Turning Every Scan as a Data Point for Risk Intelligence

A single scan verifies the detected identifier and associated data for a single unit. Ten thousand scans across markets, distributors, and time reveal patterns that no individual verification can. When every scan, not only the failed ones, is logged to a central platform with its location, timestamp, device, and result, the aggregate becomes a live view of a brand's real-world exposure. 
Think of it like weather sensors. A single sensor tells the temperature in one place. A network of connected sensors tells you where the storm is forming, which direction it is moving, and how fast. Individual authentication scans are single sensors; the analytics layer is the network view that lets a brand see the storm. 

Digimarc enables this network view that supports investigations that would otherwise be impossible. This is possible because:

  • The same unit-level identifier  producing a valid scan result in two different countries within the same week is a signal no field agent could catch on their own. But a centralized data system of record surfaces it instantly.
  • Clusters of failed or anomalous verification results in a specific ZIP code, by a specific distributor, or within a specific time window can become leading indicators of counterfeiting or diversion activity, weeks before conventional recall triggers would fire.
  • Risk scoring improves as scan volume grows, as the reference distribution of normal scan patterns becomes more precisely known.

These insights can help companies take informed actions that protect their revenues, their brand, and their customers.

Complementing DSCSA and EPCIS-Based Serialization

And finally, Digimarc’s approach to enabling package-level authentication can complement DSCSA and EPCIS-based serialization through its interoperability with these standards. Specifically, our covert authentication layer can sit on top of DSCSA-compliant serialization and the EPCIS trading-partner data exchange those systems rely on, enabling Digimarc to help address the specific failure mode neither was designed to catch: cloned or legitimate-looking lot-level data may not, by itself, reveal falsified packaging or unauthorized market movement.

How Brands Can Ensure Success

Two conditions turn these “art-of-the-possible" examples  into a real-world operational capability businesses need today:

  • The metadata must be populated consistently. The solution that’s used to operationalize covert, package-level authentication must run on a cloud platform that can carry data fields brands conventionally associated with each unit, and the data must be populated consistently. Diversion detection is only as good as the intended-market and authorized-channel records the brand maintains. This is a governance decision that must be operationalized during production.
  • The scanner network must be built broadly. Field inspectors alone likely will not generate the density of scan data required to make the analytics layer meaningful. Reaching that density is a rollout choice about which channel partners, dispensers, and downstream stakeholders are equipped and authorized to verify. A pharmaceutical network, for instance, that’s limited to a small team of licensed field inspectors will produce a thin signal. But a network that also includes pharmacists at dispense, distributor spot-checks, customs officers at ports, and, where appropriate, patients using a consumer-facing verification app, can produce a signal that’s dense enough to reliably detect diversion and counterfeiting patterns in something close to real time. And every additional class of authorized scanner becomes a new sensor in the brand's risk-intelligence network.

Both conditions are within every brand's control. Together, they turn covert authentication from a defensive feature into an intelligence system that empowers brand protection teams and protects their customers.

You May Also Like

Learn more
Serialized, But Not Authenticated
Blog

Serialized, But Not Authenticated

Learn more
Compliance Is a Floor, Not a Comprehensive Anticounterfeiting Strategy
Blog

Compliance Is a Floor, Not a Comprehensive Anticounterfeiting Strategy

leadership-team