Back to Blog
Pharmaceuticals Regulatory 29 June 2026 10 min read

Beyond the Barcode: Why Pharmaceutical Serialization Is Failing — and What Closes the Gap

The EU FMD and DSCSA were landmark achievements. They also contain a structural flaw every motivated counterfeiter already knows how to exploit. The good news is that the fix exists, costs a fraction of what a single recall costs, and can be deployed without touching your existing regulatory infrastructure.

Pharmaceutical serialization — the mandate that every medicine pack carry a unique identifier traceable through the supply chain — represented a decade of regulatory work, hundreds of millions in industry investment, and genuine public health ambition. The EU's Falsified Medicines Directive (FMD), fully enforced since 2019, and the United States Drug Supply Chain Security Act (DSCSA), with full enforcement ramping through 2026, together cover the two largest pharmaceutical markets on earth.

And yet the counterfeit problem has not gone away. In some categories and markets, it has gotten worse. Understanding why requires understanding exactly what barcode serialization does and does not protect against — and where the architecture of the system has a gap that no amount of regulatory tightening will close without a physical layer the copy cannot reproduce.

The Promise That Was Made

The original argument for pharmaceutical serialization was straightforward: if every pack has a unique identifier, and that identifier is registered in a central database at the point of manufacture, then any pack carrying a fraudulent identifier will fail verification when scanned at the pharmacy. Counterfeiters cannot manufacture legitimate identifiers. The system closes the loop between production and dispensing.

That argument is correct as far as it goes. Serialization has meaningfully reduced the simplest forms of pharmaceutical fraud — packs with no identifier, packs with obviously duplicated batch codes, and product diverted from one market to another without re-registration. These are real wins that should not be dismissed.

The argument fails, however, when it meets a counterfeiter who does not need to manufacture a legitimate identifier — because they can simply copy one that already exists.

The Copy Attack: Why a Serial Number Is Just Data

A 2D barcode carries data. That data can be read by any scanner — including the scanners counterfeiters use when they acquire a legitimate pack to analyze. Once read, the data can be reproduced on any printing equipment capable of printing a 2D barcode, which is to say: any modern printer with sufficient resolution.

The attack sequence looks like this. A counterfeiter acquires a single legitimate pack of a high-value medicine — through a pharmacy purchase, through a grey market channel, or through an inside source in the supply chain. They scan the 2D barcode, extract the Unique Product Identifier (UPI), and begin printing counterfeit packs carrying that same identifier. Every counterfeit pack they produce now carries a real, registered, valid serial number.

Serial number cloning is not a sophisticated attack. It is the pharmaceutical equivalent of photocopying a banknote — crude, fast, and devastatingly effective against a verification system that checks the image instead of the paper.

The first counterfeit pack dispensed with the cloned serial number will generate an alert in the national medicines verification system — because the number has already been used. But in high-volume pharmacy environments, verification alerts are extremely common for legitimate reasons: process errors, connectivity failures, timing issues during dispensing. A counterfeiter who understands the alert patterns in a target market can calibrate the volume of their output to stay below the threshold that triggers investigation. And in markets where verification is inconsistent, or where end-to-end verification is not yet mandated, the cloning attack generates no alert at all.

The Alert Noise Problem

EU FMD verification systems routinely generate false-positive alerts at rates that overwhelm investigation capacity. When a legitimate alert pattern looks identical to a process error, the system relies on human judgment to distinguish them — judgment that is exercised under time pressure, at high volume, with no additional information beyond the alert itself. Counterfeiters who understand this dynamic use it deliberately.

What the FMD Alert Numbers Actually Reveal

The EU medicines verification system generates large volumes of alerts, and the overwhelming majority are resolved as process-related false positives: connectivity issues, timing errors, packs scanned in the wrong sequence, or products moving across national borders with incomplete re-registration.

That leaves a small minority that require manual investigation, of which a fraction are confirmed as potentially falsified product and referred to national competent authorities. Those numbers sound reassuring until you consider what they cannot measure: counterfeits successfully dispensed with cloned serial numbers that generated no alert because the original identifier had not yet been used in the verification system.

The FMD system can catch a duplicate. It cannot catch a first use of a cloned number. And in a market processing hundreds of millions of verifications per year, the number of first-use clones that could be in circulation before detection is not trivial.

DSCSA 2026: Full Enforcement and Its Remaining Gaps

The US Drug Supply Chain Security Act reached a milestone in November 2024 with the enforcement of interoperability requirements — mandating that all supply chain partners exchange electronic product identifier data in real time. The final phase of full DSCSA implementation is expected to complete in 2026, at which point every prescription drug transaction in the United States will require verified electronic documentation of the product's chain of custody.

This is a significant achievement. But DSCSA shares the same structural limitation as FMD: it verifies data, not physical objects. The interoperability requirements mandate that trading partners exchange serialization data — but the data they are exchanging is the 2D barcode serial number. An attacker who can clone that number into the supply chain documentation, not just the physical label, has defeated the system at a deeper level than simple pack-level counterfeiting.

  • Document fraud risk: DSCSA's electronic documentation layer can be attacked through fraudulent transaction statements, falsified previous transaction data, or compromised trading partner credentials — none of which is prevented by the serialization mandate alone.
  • OTC exclusion: DSCSA covers prescription drug products. Over-the-counter medicines — which account for the majority of counterfeit pharmaceutical seizures by volume — are outside the mandate's scope entirely.
  • Patient-level verification gap: Neither FMD nor DSCSA provides a verification mechanism that reaches the patient. The supply chain verification events all happen upstream of the dispensing point. What the patient actually receives has no verified-authentic signal they can access.

The Physical Layer That Closes the Gap

The structural gap in barcode-based serialization — that it verifies data, not objects — is closed by two things a printed serial alone cannot provide: a code that is unique to each unit, and a physical label a copy cannot reproduce. The difference is not incremental. It is architectural.

A SealsTrust label carries a serialized QR code that is never assigned to another unit, plus a physical layer — raised relief, embedded optical fibers and a light-reactive coating — that a photo or photocopy cannot capture. When a verification device (a pharmacist's terminal, a hospital scanner, or a patient's phone) scans the code, the scan is logged and the visitor is taken to the manufacturer's page for that unit.

The serial is unique, so a counterfeiter who copies one code onto many packs makes every copy carry the same serial — and those duplicates expose themselves the moment two of them are scanned, or one is scanned outside its authorized territory. And because the physical label cannot be convincingly reproduced from an image, a copied label looks and feels wrong to a person handling the pack. The credential is the unique serial and the physical label together, not just the number printed on it.

A physical layer, not just a code

Raised relief, embedded optical fibers and a light-reactive coating make the label itself hard to reproduce convincingly. A photo or photocopy loses these, so a copied label looks and feels wrong on inspection.

Unique serial per unit

Every unit's code is one-of-a-kind. A counterfeiter who clones one code onto a run makes every fake share a single serial — so the copies give themselves away as duplicate scans rather than passing as distinct genuine packs.

Geolocation scan log

Every scan event — timestamp, device, coarse location — is logged. A pack whose serial is scanned in two cities in the same hour is flagged automatically as a cloning indicator.

Suspect on sight

A pack with a missing, damaged, or unreadable label — or one whose relief and optical features do not match — is treated as suspect at any point in the chain. The physical characteristics are what counterfeiters struggle most to reproduce.

The Dual-Layer Strategy: Barcode Plus a Physical Layer

A question that arises consistently in pharmaceutical deployment discussions is whether the authentication label is intended to replace barcode serialization. The answer is no — and the distinction matters commercially and regulatorily.

Barcode serialization under FMD and DSCSA is a legal requirement. Removing it is not an option. The role of the physical authentication label is to add a verification layer that closes the structural gap barcode serialization cannot close on its own. Both run in parallel on the same pack. The barcode handles regulatory compliance and supply chain track-and-trace. The serialized physical label handles authentication at any point in the chain — including the patient-facing moment that the regulatory systems don't reach.

From a regulatory perspective, adding an authentication label to a pack is a pack change. In most jurisdictions this requires a change control process and may require regulatory notification. The timeline for this varies and should be factored into project planning from the outset.

Planning Note

Adding an authentication label to pharmaceutical packaging is typically classified as a minor pack change in most regulatory frameworks. It does not usually require a new marketing authorization. But it does require a documented change control process, which takes time. Starting the regulatory submission in parallel with the technical implementation is the fastest path to market.

The Case for Acting Before the Deadline Forces Your Hand

There is a standard argument for waiting. A physical authentication layer is not yet mandated under FMD or DSCSA. The compliance cost of not deploying it today is zero in most markets. Why absorb the operational complexity now?

The answer comes in three parts.

The regulatory direction is clear. Pharmaceutical authentication frameworks have moved steadily toward stronger verification, and the expectation that high-risk products be verifiable to the individual unit is spreading. The question is not whether a physical authentication layer will become an expectation — it is whether you will deploy it proactively or under a deadline.

The competitive differentiation is real now. A pharmaceutical brand that deploys patient-facing authentication is offering something concrete: a scan that tells a patient, on their own phone, that the medicine in their hand is a genuine unit the manufacturer released. That is not a regulatory checkbox. It is a trust product — and in markets where counterfeit prevalence is high enough that patients have lost confidence in the channel, it is a commercial differentiator with measurable impact on adherence and brand loyalty.

The deployment infrastructure compounds. Every pack you enroll, every distribution partner you integrate, every pharmacist who develops the scan habit adds to an authentication network that becomes more valuable as it grows. Brands that start now build the network effect. Brands that wait start from zero against a deadline, with compressed timelines and no operational learning.

The serialization mandates were necessary. They closed the simplest forms of pharmaceutical fraud. But the attack surface they left open — cloned identifiers, first-use exploitation, patient-level verification gaps — is exactly where sophisticated counterfeiters operate today. The barcode got the supply chain most of the way. The physical layer closes the part it cannot — cloned identifiers, first-use exploitation, and the patient-level verification gap. And that is the part where patients are actually harmed.

S

SealsTrust Editorial Team

SealsTrust builds physical authentication labels and scan-analytics infrastructure for brands whose products are counterfeited. Seals Data LLC, Sheridan, Wyoming.

Close the Serialization Gap

See the label for yourself

Request a free demo kit and test the label on your own packaging. No app, any phone camera.

All Articles
Pharmaceutical Counterfeiting: Why Authentication Is a Life-or-Death Issue
Patient Safety

Pharmaceutical Counterfeiting: Why Authentication Is a Life-or-Death Issue

Counterfeit medicines kill hundreds of thousands of people each year. How serialization and physical authentication are changing the equation for pharma brands and patients alike.

Counterfeit Biologics: Why Insulin, Vaccines, and Biosimilars Are Fraud's Fastest-Growing Target
Biologics

Counterfeit Biologics: Why Insulin, Vaccines, and Biosimilars Are Fraud's Fastest-Growing Target

When the drug being counterfeited is a protein that mimics a human hormone, the gap between fake and genuine is invisible to the naked eye and lethal to the patient.

Falsified Medicines in the Legitimate Channel: How Diversion Becomes Danger
Pharmaceuticals

Falsified Medicines in the Legitimate Channel: How Diversion Becomes Danger

How diverted medicines re-enter the legitimate channel, and why diversion and falsification travel together.