FMCG Packaging Authentication: One Scan, Two Problems Solved

Brand Protection Best Practices for FMCG CMOs 2026

FMCG brands face a packaging security problem that is different in character from pharmaceutical or automotive counterfeiting. In pharma, the primary threat is falsified medicine entering a regulated supply chain. In automotive, it is safety-critical components failing in the field. In FMCG — fast-moving consumer goods — the threat is more distributed, more varied, and in some ways harder to contain because of the economics involved.

But FMCG also has something the other categories do not: a direct consumer touchpoint at the moment that matters most. And that changes what packaging authentication can do.

For a full breakdown of the technology, see our complete guide to tamper proof stickers.


The FMCG Counterfeiting Landscape

Scale

The global market for counterfeit consumer goods — personal care, beauty, household products, food and beverages — is substantial. OECD analysis identifies these as among the most-counterfeited categories globally, with premium subcategories (luxury personal care, specialist food, premium spirits) particularly targeted. In some markets, counterfeit presence in general trade can reach 20–30% of product on shelf for specific high-value categories.

The attack vectors are different

FMCG counterfeiting is not primarily a case of high-quality fake products manufactured from scratch (though this exists in premium categories). The dominant attack vectors are:

Refill attack: Genuine containers — particularly premium bottles, jars, and tubes — collected post-consumer use, cleaned, and refilled with diluted, substituted, or inferior product. The container is genuine. The label may be genuine. The tamper seal may be genuine or a convincing copy. The product is not.

Dilution: Genuine product diluted with cheaper substitute ingredients and repacked. The product is technically present but at a fraction of the claimed concentration. Difficult to detect without laboratory testing.

Counterfeit packs: In high-volume categories, manufactured fake packs that replicate the artwork, container design, and label. Quality varies significantly; in markets with sophisticated counterfeiting capability, these can be visually indistinguishable on shelf.

Marketplace and online channel fakes: A fake or refilled product listed under a genuine brand's ASIN or product listing on an e-commerce marketplace, benefiting from the brand's reviews and search ranking while delivering counterfeit product.

Why tamper labels don't solve this

For the refill attack — the dominant vector in FMCG — tamper labels are irrelevant. The attacker performs the sealing. There is no tamper event to detect. For marketplace fakes, the consumer receives the product; they don't inspect a seal before purchase. For dilution, the product appears normal until use.

FMCG counterfeiting is primarily an authentication problem, not a tamper detection problem.


The First-Party Data Problem

Separately from counterfeiting, FMCG brands face a structural problem with consumer data that has been intensifying for years.

The general trade gap

The majority of FMCG volume in most markets flows through general trade — independent stores, wet markets, convenience retail, traditional grocery. In markets across South and Southeast Asia, Africa, and Latin America, general trade accounts for 60–80% of FMCG sales by volume.

In general trade, there is no transaction data. The brand knows how many units they shipped to a distributor. They do not know who bought them, where, when, or why. There is no loyalty programme data, no purchase history, no consumer profile. The consumer is anonymous at the point of transaction.

Brands compensate through consumer research — surveys, panels, ethnography — which is expensive, slow, and produces aggregate insight rather than individual data. And through media spend, which reaches consumers before and after purchase but not at the moment of purchase or use.

Why this matters beyond analytics

The strategic consequence of holding no first-party consumer data from general trade goes beyond analytics:

No direct relationship: The brand cannot reach the consumer outside of media. There is no channel for a recall notification, a product safety alert, or a loyalty communication to reach a specific consumer who bought a specific product.

No verification that purchased product is genuine: In markets where counterfeiting is prevalent, the brand has no mechanism to know whether a consumer complaint relates to genuine or counterfeit product. Care costs accumulate without the ability to distinguish origin.

No loyalty architecture: In a general trade environment, repeat purchase is driven by habit, price, and availability — not by a relationship with the brand. Building loyalty requires a touchpoint, and there isn't one.


The Authentication Opportunity: One Scan, Two Problems

Here is the structural insight that makes FMCG packaging authentication different from any other category.

In FMCG, the consumer physically holds the pack. Millions of consumers, holding millions of packs, every day. In general trade, they hold the pack and then put it away without any digital interaction with the brand.

That moment — consumer holding the pack — is the only moment when the brand and the consumer share the same physical object. It is the only moment when a direct interaction is possible without a media intermediary. And it is the moment when authentication is most useful: the consumer wants to know if the product is genuine; the brand wants to know the consumer exists.

The scan that verifies the pack is genuine is the same scan that introduces the consumer to the brand.

This is not true in any other category at comparable scale. In pharma, the consumer doesn't usually scan the pack — the pharmacist or the healthcare system does. In automotive, the end consumer doesn't typically verify their own spare parts. In FMCG, the consumer is the verifier, and the verification moment is the engagement moment.

What a single pack scan can deliver

A consumer who scans a pack to verify it is genuine generates, in a single interaction:

For brand protection: A verification result (genuine or not genuine), a geographic location, a timestamp, and a device identifier. Aggregated, this is real-time intelligence on where genuine product is being consumed, where not-genuine results are clustering, and which SKUs or markets are experiencing counterfeiting.

For consumer engagement: A digital touchpoint. With appropriate consent capture, the brand receives a relationship — an opted-in consumer who has interacted with the brand in a moment of positive intent (they wanted to confirm the product was real). This is qualitatively different from a consumer who clicked an ad.

For first-party data: Scan location, product, frequency — the building blocks of consumer profile data from general trade, where none exists today. The data is generated by the consumer's own verification behaviour, not purchased from a third party or inferred from media analytics.

For loyalty: The scan is the entry point. A verified genuine product can trigger a loyalty reward — points, a discount, content, a competition entry. The consumer is already holding the product. The reward is immediate. The friction is a camera scan.


The Cost Arithmetic at FMCG Scale

The objection that stops most FMCG security programmes at the proposal stage is cost per pack. Hundreds of millions of units. Packaging that costs fractions of a cent per unit. Any security addition has to fit within that arithmetic.

This rules out: physical label additions (per-unit component cost), dedicated scanning hardware (infrastructure cost), and complex consumer-facing app downloads (adoption friction).

What fits within the arithmetic: an authentication feature embedded in the pack artwork.

Artwork-level authentication

An invisible cryptographic signature embedded in the pack artwork during print production is not a per-unit component. It is a change made at the artwork file level — the same file that goes to every print vendor for every pack in that SKU run. The cost is incurred once per artwork revision, not once per pack.

At FMCG volumes — hundreds of millions of packs per SKU per year — the per-pack cost of an artwork-level feature is fractional. It does not appear on the per-unit packaging bill of materials in a meaningful way.

Verification is by smartphone camera. No app download required in most implementations. No consumer hardware. No retailer infrastructure. The consumer's own phone is the verification device.

The business case

The case for FMCG packaging authentication has two sides:

Defensive: Complaint volume reduction (complaints about counterfeit product that the brand currently fields and pays for), care cost reduction, recall scope reduction (knowing which packs are genuine before issuing a recall), marketplace takedown support (authenticated genuine product demonstrably distinct from fakes).

Offensive: First-party consumer data from general trade, loyalty programme activation, direct consumer relationship in markets where none existed, scan intelligence for sales and distribution teams, promotional activation via pack scan.

The defensive case justifies the investment. The offensive case makes it a commercial argument rather than a cost argument.

FAQs

Can a product have both tamper evidence and authentication?

Yes, and for brands facing multiple threat types, both are appropriate. Tamper evidence addresses retail interference and regulatory compliance; authentication addresses manufactured counterfeiting and diversion. They solve different problems and coexist on the same pack without interference.

Is a QR code product authentication?

A standard QR code is not authentication — it is a link to a URL. Anyone can generate a QR code linking to any page, including a fake verification page. A serialised QR code with a unique code per pack gets closer, but serial numbers can be copied from genuine packs onto fakes. Cryptographic authentication embedded in the pack — not printed on its surface as a scannable code — is what makes verification forgery-proof.

Does pharmaceutical serialisation provide product authentication?

Serialisation under FMD and DSCSA verifies the serial number is valid and was assigned to a product of that type. It does not verify the physical pack is genuine — only that the credential on it is legitimate. A valid serial number can be copied onto a falsified pack. Physical authentication is a separate layer that addresses this gap.

How does invisible authentication work?

A cryptographic signature is generated using a private key and embedded in the pack artwork during the print process — not as a separate component but as part of the image. A smartphone camera reads the embedded signature and a server verifies it against the expected value generated by the corresponding public key. If the signature is valid, the pack is genuine. If not — because the pack is a fake without access to the private key — the verification fails. There is nothing on the surface to copy because the signature is not visible.

What is the cost difference between tamper evidence and authentication?

Tamper evidence costs per unit — label material, adhesive, application. At high volumes, standard VOID labels are very cost-effective. Authentication using embedded invisible signatures costs at the artwork level — it is an artwork change that applies to an entire print run, not a per-unit addition. At FMCG scale, this makes cryptographic authentication cost-competitive with physical label additions while providing significantly greater security.

Recommended Articles