Counterfeiters don’t give interviews.
What years of investigating counterfeit products have taught us about how counterfeiters really think.
After years of analyzing fake products, reproducing counterfeit attacks in our own lab, and investigating authentication failures around the world, certain patterns emerge. The conversation below is a reconstruction of those recurring observations, how a professional counterfeiter would likely explain his craft if he had nothing left to lose.
“People think I attack security features. I don’t.”
“People think I attack security features. I don’t.”
Interviewer: What’s the first thing you look for when choosing a product to counterfeit?
Counterfeiter: I don’t start with the product.
I start with the authentication.
Every security feature tells me something.
Not about how secure it is but about how it expects to be authenticated.
My job is simply to find the weakest assumption.
“I’m not trying to fool a microscope.”
“I’m not trying to fool a microscope.”
Interviewer: What do you mean?
Counterfeiter: Every authentication technology ultimately depends on someone or something making a decision.
Today, that “something” is usually a smartphone.
Consumers have smartphones.
Retail staff have smartphones.
Customs officers have smartphones.
That’s actually a good thing. Smartphones have made authentication accessible to everyone.
But smartphones were never designed to inspect microscopic structures with scientific precision.
So I don’t ask myself whether my copy would fool a laboratory.
I ask myself a much simpler question.
Can I create a printed copy that still looks authentic through a smartphone camera?
If the answer is yes… I’m in business.
“QR Codes are the easiest”
“QR Codes are the easiest”
Interviewer: Most brands have moved towards QR codes and serialization. Doesn’t that make counterfeiting harder?
Counterfeiter: It makes copying numbers harder.
It doesn’t necessarily make copying products harder.
If a QR code simply points to a valid serial number, I only need one genuine product.
I duplicate the code.
Maybe a hundred times.
Maybe a thousand.
Many consumers never scan it.
And if they do, many systems only verify that the code exists, not whether the same code has suddenly been scanned in three different countries within the same week.
Serialization is powerful.
But only if the backend is designed to detect abuse, duplicate scans and suspicious behaviour.
Otherwise… it’s just another printed graphic.
“I don’t need a perfect copy.”
“I don’t need a perfect copy.”
Interviewer: So your goal isn’t to create an identical security feature?
Counterfeiter: Never.
People think counterfeiting is about making perfect copies.
It isn’t.
It’s about understanding what the authentication system is actually measuring.
Perfection is expensive.
Passing authentication is profitable.
Those are two very different objectives.
“Printed security is still just printing.”
“Printed security is still just printing.”
Interviewer: Many labels contain intricate printed patterns, micrographics, guilloches or copy detection patterns. Aren’t those difficult to reproduce?
Counterfeiter: They’re difficult to redesign.
That’s not what I do.
I copy them.
People often assume I have to recreate every microscopic detail.
I don’t.
I duplicate the printed image.
“The smartphone isn’t looking through a microscope.”
“The smartphone isn’t looking through a microscope.”
Interviewer: But surely the copy loses detail?
Counterfeiter: Of course it does.
Look at it under a microscope and you’ll see differences everywhere.
Edges become softer.
Tiny structures disappear.
Fine details merge together.
But here’s the important question.
Who authenticates products with a microscope?
Your customer doesn’t.
Neither does a smartphone.
The question isn’t whether microscopic information is lost.
The question is whether enough survives to fool the smartphone that’s performing the authentication.
Quite often… it does.
“Then I found something I couldn’t print.”
“Then I found something I couldn’t print.”
Interviewer: Have you ever encountered a security feature that genuinely stopped you?
Counterfeiter: Yes.
Because for the first time…
I wasn’t attacking printing anymore.
“The scanner became useless.”
“The scanner became useless.”
Interviewer: What made it different?
Counterfeiter: At first?
Nothing.
I thought it was just another security label.
So I treated it like every other security label.
High-resolution scan.
Professional printer.
Excellent result.
Visually.
Authentication failed.
I assumed I had missed something.
So I scanned it again.
Higher resolution.
Better printer.
Better paper.
Same result.
That’s when I realised the first mistake.
I was trying to reproduce a three-dimensional structure with a two-dimensional process.
A scanner captures an image.
A printer reproduces an image.
But this wasn’t just an image.
The authentication was responding to the microscopic surface itself.
Not the print.
No matter how good my scanner or printer became…
I could only ever produce a flat copy.
So I changed my approach.
I stopped thinking like a printer.
I started thinking like an optics engineer.
I brought in someone who specialised in holographic structures.
If the problem was three-dimensional, then maybe we had to manufacture a three-dimensional replica.
We got close.
Visually, it looked convincing.
Authentication still failed.
That’s when we discovered the second problem.
The microscopic structure wasn’t designed.
It wasn’t manufactured to match a template.
It was created naturally during production.
Every single label was different.
Even if you know exactly how it’s made… you still can’t recreate the same microscopic structure twice.
That’s when I stopped trying.
The Real Difference
Listening to the counterfeiter, one observation became impossible to ignore.
The smartphone isn’t the weakness. In fact, smartphones have made product authentication practical on a global scale. The weakness appears when the smartphone is asked to authenticate something that exists only as printed information.
- QR Codes.
- Serial Numbers.
- Printed Security Graphics.
- Copy Detection Patterns.
- Proprietary Secure Codes.
They’re all ultimately asking the same question:
“Does this printed information still look authentic?”
If a counterfeiter can scan that information, print it again and preserve enough detail for the smartphone to reach the same conclusion, the attack has succeeded. Some authentication technologies ask a fundamentally different question:
“Is this still the same physical fingerprint?”
Instead of authenticating printed information, they authenticate a naturally occurring microscopic fingerprint created during manufacturing. That fingerprint is inherently three-dimensional and shaped by microscopic production irregularities. It isn’t designed, it simply exists. That changes the nature of the attack.
As we wrapped up our conversation, we asked one final question:
Interviewer: If you had one piece of advice for companies designing authentication systems today, what would it be?
Counterfeiter:
“Stop trying to make re-printing harder. Start making cloning impossible.”
“Stop trying to make re-printing harder. Start making cloning impossible.”
About Authentic Vision
Headquartered in Salzburg, Authentic Vision has rapidly emerged as a well trusted partner in Secure Product Digitalization, establishing a significant presence worldwide. The company initially focused on brand protection and swiftly expanded its expertise to serve fields with demanding security standards like the banking industry. Today, Authentic Vision’s impact is global, with its technologies being utilized daily in over 50 countries.
For additional information about this partnership, please contact:
marketing@authenticvision.com

