Blog

Serialized, But Not Authenticated

August 13, 2026

Serialized, But Not AuthenticatedUnderstanding the Limits of the Anti-Counterfeiting System Pharma Spent a Decade Building

 

Summary:

Serialization does what it was built to do. It satisfies DSCSA and FMD, and it stops the crude fakes. What it can't do, by itself, is tell you whether the package in front of you is original, because it checks the visible credential printed on it. Counterfeiters have known that for years and found ways around it.

Brief: 

  • A widely cited Strategy& (PwC) analysis found that mass serialization catches only 35-50% of counterfeit drugs even at peak effectiveness, and that counterfeiters typically crack prevailing systems within two to three years.
  • Barcodes and unique identifiers can be copied straight off genuine product, so a fake package can carry a valid serial number, scan successfully, and reconcile cleanly across transaction records. A 2026 piece in Pharmaceutical Commerce similarly stated that serialization can't authenticate the physical product it's printed on.
  • That two-to-three-year cracking cycle puts brand protection teams on a reinvestment treadmill nobody budgeted for, just to hold the same ground. To authenticate packaging, they now need a covert layer that does not present counterfeiters with a visible, discrete credential  they can deliberately isolate and reproduce. 

Let's start by giving the pharmaceutical industry its due, because the story that follows isn't a story about failure of effort. Over the past decade, manufacturers, distributors, and dispensers have poured enormous resources into protecting medication using serialization—unique identifiers on every unit, 2D barcodes, transaction records at every handoff, all of it mandated under the U.S. Drug Supply Chain Security Act (DSCSA) and the EU Falsified Medicines Directive (FMD).  

Implementing serialization was a heavy lift, it was expensive, and it was the right thing to do. Serialization stops a whole class of crude counterfeits cold and gives the supply chain a level of traceability it never had before. So, make no mistake: this isn't a "serialization was a mistake" argument.  

It's a bit more uncomfortable: while serialization did its job, modern anti-counterfeiting threats have outgrown it anyway. The system is working as designed, but "working as designed" and sufficiently "secure against today's counterfeiter" are no longer the same thing.

That gap between "working" and "secure" is easy to miss precisely because the system looks healthy. Scans succeed. Records reconcile. Audits pass. By every internal metric, serialization programs are performing, which is exactly why a brand can feel well-protected right up until the moment a counterfeit that passes all those checks turns up in the legitimate chain. A defense that fails loudly gets fixed. A defense that succeeds at the wrong task fails silently, and silent failure is the more dangerous kind because nothing in the dashboard tells you it's happening. 

What does the data say about serialization's ceiling? 

You don't have to take our word for this. One of the most-cited independent assessments comes from Strategy&, the consulting arm of PwC, in a 2017 analysis of pharmaceutical counterfeiting. Two findings from that report are worth examining:

  • First: Even at peak effectiveness, conventional mass serialization captures only 35-50% of fake drugs, not 90-something. Roughly half, at best.
  • Second: Counterfeiters typically crack prevailing systems within two to three years, forcing companies into a recurring cycle of upgrades just to hold the same ground.

While this analysis is from 2017, it's still frequently cited because barcode-based verification hasn't been fundamentally redesigned since. For this reason, the figures hold up as a benchmark of what this approach can structurally do, rather than as a fresh measurement of this quarter's catch rate. The point is not "serialization catches 35–50% of fakes today, precisely," but rather, that the barcode-verification approach has been found to have an inherently low detection ceiling—one that you probably wouldn’t want to rely on.

Even with that caveat, consider the implication of this data. The central pillar of modern pharmaceutical anti-counterfeiting, operating at its best, was assessed as missing somewhere between half and two-thirds of fakes and being reverse-engineered on a two-to-three-year cycle. That's not a knock on the people who built it. It's the nature of any system whose security depends on a credential that can be cloned. 

Here’s why "serialized but not secure" is the actual problem.

The phrase captures it exactly. A product’s packaging can be fully serialized—meaning it carries a valid identifier, a scannable barcode, and a clean transaction record—and still be fake because all of those visible credentials can be reproduced by a counterfeiter who copies them from a genuine product. Serialization verifies that a credential is valid. It does not, by itself, verify that the physical packaging carrying the credential is original.

Brands are on an upgrade treadmill nobody budgeted for.

There's a cost dimension to the two to three-year cracking cycle for brand protection teams to consider as well. Serialization is not a one-time capital project because if counterfeiters reverse-engineer prevailing systems every few years, then staying even will require periodic reinvestment in new features, new identifiers, and new countermeasures—and that’s just to maintain the same level of protection. That treadmill is itself an argument for a different kind of anti-counterfeiting protection layer. A defense whose security depends on the counterfeiter not having figured it out yet has a built-in expiration date.  A covert digital watermark works differently: it’s carried within existing package artwork and does not present counterfeiters with an obvious, visible credential to target. A counterfeiter reproducing packaging from a photograph, scan, or observed sample may not know that the watermark is present, and a reproduction that fails to preserve the watermark will fail field authentication. 

So, where does this leave your brand team?

Serialization will remain the foundation, as it’s required for compliance, valuable for traceability, and effective against unsophisticated fakes. What’s key is to understand that it’s only a foundation—not a finished building. If the best independent benchmark of your primary defense puts its ceiling at roughly half of fakes caught, and the trade press confirms it can't authenticate the physical package by itself, then treating serialization as the whole of a brand protection strategy leaves a known, quantified gap wide open.

Put simply, serialization is necessary, but it was never built to answer, by itself, "Is this physical package original?" You need a covert, digital layer that supports package-level authentication by helping determine whether the packaging carries the expected embedded identity. That's the subject of our white paper, The Detection Gap: How Pharma Brand Protection Quietly Became a Liability Question. We invite you to download it to learn more. 

Sources:  

Strategy& (PwC), "Fighting Counterfeit Pharmaceuticals: New Defenses for an Underestimated — and Growing — Menace," 2017 (mass serialization catches 35–50% of fakes at peak effectiveness; systems typically cracked within two to three years). This is a 2017 benchmark of barcode-based verification limits, widely cited because the approach has not been fundamentally redesigned since; it is not a current point-in-time measurement. 

 

Please contact us for additional information about Digimarc products.

You May Also Like

Learn more
Compliance Is a Floor, Not a Comprehensive Anticounterfeiting Strategy
Blog

Compliance Is a Floor, Not a Comprehensive Anticounterfeiting Strategy

Learn more
Insider Risk: Types, Costs, and Your Risk Profile
Blog

Insider Risk: Types, Costs, and Your Risk Profile

leadership-team