Monday, 22 April 2024

Brand protection: clarifying the terminology

The description of brand protection products and services involves the use of a wide range of terminology, including terms which are frequently used interchangeably, in different ways by different providers, or in ways which do not fully or accurately describe the component parts. In this article, we look to set out a group of terms which can be used to standardise the descriptions. A schematic illustrating the high-level approach is shown in Figure 1.

Figure 1: Schematic of the basic elements of brand protection (and related product and service areas) across both the online and offline worlds

Overall, brand protection sits across the intersection of the online and offline environments. In its broadest sense, it comprises a combination of:

  • Monitoring - the detection of potentially relevant (and/or infringing) content
  • Analysis - the processes of filtering the data (e.g. removing false positives), prioritising the relevant findings for further action, and using clustering techniques to establish links between findings
  • Enforcement - follow-up actions to mediate or remove infringing content

In general, all of these elements can utilise a combination of automated and manual approaches.

The tools and techniques appropriate for use with monitoring and analysis of online vs offline content are, in general, relatively distinct from each other. They typically involve technical approaches (e.g. the use of search and monitoring tools) for online content, and more on-the-ground approaches (information derived from partnerships with customs and law enforcement, physical investigations, etc.) for offline content. Accordingly, these are shown separately in Figure 1.

'Enforcement' encompasses a range of approaches. To a high level, these are often categorised as those which primarily relate to online content (e.g. marketplace or social-media takedowns, host- or registrar-level domain takedowns - i.e. online brand enforcement), whilst others (such as physical raids or seizures) are most meaningful when thought of in association with the offline world (i.e. offline brand enforcement). In reality, however, these two areas are not really separate, for a number of reasons:

  • The offline world is a key part of the supply chain for infringing goods to be sold online
  • In many cases, 'online' enforcement may require the use of 'offline' elements (e.g. communications via telephone, fax or physical mail) and conversely 'offline' enforcement approaches may require e-mail communications or may be associated with individuals who are also responsible for online infringements
  • Many of the escalation routes for enforcement actions (IP disputes, litigation, etc.) may be relevant both to online and offline content

Overall, therefore, enforcement is best viewed as a spectrum of approaches which collectively straddle both the online and offline worlds.

It is then possible to use this overall framework to 'read' the lists of components relating to specific service areas - e.g. 'online brand protection' consists of online monitoring, online analysis and (online) enforcement, together with the defensive-registrations component of an official domain portfolio.

As a next step, it is also helpful to consider how specific service areas 'map' into this overall framework. For example, the provision of 'anti-counterfeiting' services typically incorporates monitoring, analysis and enforcement across both the online (e.g. e-commerce websites) and offline (e.g. physical manufacture and sales) worlds. Conversely, domain name management - an area which occupies purely the online environment - requires elements of domain name registrations (i.e. the construction of an official domain portfolio), domain-related brand protection against third-party infringements, and (if done appropriately) the use of cybersecurity measures to secure official domains from compromise and attacks. The construction of an official domain portfolio is shown as sitting partly outside and partly inside the considerations of 'brand protection', as it encompasses both the registration of 'core' domains used for general business operations, and strategic domains (a subset of the 'tactical' portfolio) relevant to potential future business expansions, but also the registration of defensive domains (also 'tactical') held to prevent infringing use by third parties (i.e. a purely brand-protection-related consideration).

The final piece of this high-level picture, but one of central importance, is the process of IP portfolio management. This is the registration and maintenance of appropriate IP rights such as trademarks (in appropriate classes and jurisdictions), patents, design rights, etc. It is shown as an 'offline' element of the overall approach, but comprises a key dependency for effective enforcement across both the online and offline environments. Essentially, it is impossible to operate an effective brand protection programme without having a strong IP rights portfolio in place. The converse is also true; proactive brand protection is often a prerequisite for retaining IP protection. In addition, once a brand protection programme reaches a mature state, it can also help inform the development and evolution of the IP portfolio - insights drawn from trends and patterns in infringements, and subsequent enforcement actions, can feed into the ongoing process of 'rightsizing' the portfolio, to balance protection against budget.

This article was first published on 22 April 2024 at:

https://www.iamstobbs.com/opinion/brand-protection-clarifying-the-terminology

You’re so fake: the ugly side of beauty product sales - Counterfeit perfume and cosmetics

by David Barnett and Claire Breheny

BLOG POST

Following the recent launch by the IPO (in conjunction with the ACG) of the #choosesafenotfake campaign, highlighting the dangers of fake beauty, skincare and perfume products, we took a look at the landscape of counterfeit beauty products in a new study, with a specific focus on standalone e-commerce websites.

For perfumes and cosmetics, we found that websites offering the sale of potentially counterfeit products targeting top brands are easily identifiable through quick and simple searches. Many of these websites incorporate 'red-flag' indicators of non-legitimacy, including low price point and the use of high-risk domain-name extensions. Some also include features such as 'Trusted Site' icons which appear to have been used without authorisation.  

The findings illustrate the likely scale of the counterfeit problem, and highlight the importance of brand protection programmes to identify and take down infringing sites.

This article was first published on 17 April 2024 at:

https://www.iamstobbs.com/opinion/youre-so-fake-the-ugly-side-of-beauty-product-sales

* * * * *

WHITE PAPER

Introduction

The Intellectual Property Office (IPO) Counter-Infringement division, in conjunction with the Anti-Counterfeiting Group (ACG), has recently launched the #choosesafenotfake campaign, highlighting the dangers of fake beauty, skincare and perfume products[1,2]. In many cases, these products may contain harmful ingredients, and the campaign presents a series of guidelines to consumers for avoiding counterfeits, including careful vetting of sellers and websites (including checking of contact details, reviews, and site quality), avoiding platforms requesting payment by bank transfer, and being wary of sources which may otherwise seem attractive purely by virtue of a low product price point.

The issue of counterfeits - which are explicitly passing off as having been manufactured by the brand owner in question - is distinct from that of 'dupe' or replica products, more usually taken to mean own-brand items which just appear similar to the branded originals (and are also often offered at a significantly lower price). Dupes are problematic for brand owners in different ways, and can involve loss of revenue arising from cases in which unfair advantage is gained through trademark infringement - however, this issue is not specifically discussed in this study.

In this study looking at the counterfeit landscape for beauty products, we consider ('standalone') e-commerce websites offering the sale of perfumes or cosmetics. The analysis of registered domain names offers a readily available source of comprehensive data, and a focus on perfumes and cosmetics is likely to highlight areas where counterfeiting may be more commonplace, and potentially attractive to consumers, due in many cases to the high prices of the originals.

i. Perfume-related domain names

Using domain-name zone file data[3], it is possible to determine that there are over 146,000 registered gTLD domains with names containing 'perfum', 'parfum', 'fragrance', 'scents', 'essence' or 'aroma'. Of these, we focus on the subset which also contain the name of a well-known and/or highly-counterfeited perfume brand, and which are most likely to have been registered specifically to infringe against that brand (and provide the greatest potential for customer deception). The brands considered are the top ten highest-earning perfume brands in 2023[4,5], in addition to three further brands[6] known to be at risk of counterfeiting. This yields a dataset of 251 high-relevance domains, of which 128 were found to be
registered by third parties (with the remainder deemed to be official registrations, based on registrant contact details and/or use of an official corporate registrar).

The breakdown of site content type (based on a manual inspection) of these 128 high-relevance, third-party domain names is shown in Figure 1.

Figure 1: Content types observed on the set of 128 third-party (i.e. non-official) domains with names containing perfume-related keywords and top perfume brand names

A categorisation of 'potential counterfeit' is an opinion made on the basis of a number of indicators of non-legitimacy, which are outlined below, together with other observations of additional concern pertaining to the sites assigned to this category:

  • Many of the sites are low quality and/or lack the consumer rights information typically given on legitimate sites, and many are selling products at prices significantly below the recommended retail price (RRP) for the (genuine) goods in question. Indeed, in many cases, the significant price reductions below RRP are referenced on the sites as an explicit selling point (Figure 2).
  • 9 of the 13 sites utilise 'https' links (implying the use of an SSL certificate, often denoted by a 'secure' padlock alongside the address bar - historically frequently cited as an indicator of a legitimate site, but now commonly arising through the use of free or low-cost certificates obtained through budget providers who often do not check the authenticity of the sites in question).
  • Several of the domains utilise new-gTLD extensions, with examples including .store, .shop, .click, and .tokyo, many of which have previously been noted as being popular with infringers.
  • Some incorporate pull-down menus for buyers to select their local currency, a feature which is uncommon on official sites (which tend to utilise specific distinct domains for individual customer markets).
  • In some cases, site features such as a 'Trusted Site' icon is included (which can easily just be copied from another site and displayed with no authorisation).

Figure 2: Examples of products being offered at significant price reductions below RRP

Of particular concern is the fact that 13 live sites offering potential counterfeits (10% of the potential high-relevance dataset) were identified through this simple search. Some examples of these sites are shown in Figure 3.

Figure 3: Screenshots of examples of sites offering the sale of potentially counterfeit perfume items (second-level domain (SLD) names (i.e. the part of the domain name to the left of the dot): creedperfumeus; diorperfume; perfume-chanel; baccaratperfume)

Amongst the other sites in the dataset:

  • 'Other potential brand infringements' include instances of third-party sites using the same (or similar) brand names in related industry areas, or cases where the domain resolves or re-directs to a third-party site; 'unrelated third-party content' comprises cases where the name appears to be being used legitimately and/or there is a less close overlap in industry or product area.
  • 'Generic product-related content' includes results such as blog sites giving information on the products in question.
  • Some of the non-active sites have been monetised through the inclusion of pay-per-click links or the hosting of content offering the domain name for sale, indicating an intention to benefit from the abuse of the brand name.
  • Instances of third-party sites which re-direct to the official brand site may be of little or no threat, but can be associated with e-mail scams (e.g. where the domain name is used as a 'from' address, and the re-direction is intended to provide the impression of legitimacy), or affiliate revenue generation schemes.

ii. Cosmetics-related domain names

In the second part of the study, we similarly focus on domains with names containing either 'make(-)up' or 'cosmetics' (of which there are over 110,000 in total) together with the names of any of the top ten cosmetics brands according to Brand Finance[7], or any of a set of other 'high-risk' brands[8] selected by virtue of their large followings on social media (implying potential popularity with younger consumers who may be more inclined to risk the purchase of a cheaper product), and/or which may be attractive to counterfeiters because of their high price point.

For this set of brands, 154 brand-specific domains were identified (of which the selected group of 'high-risk' brands actually make up the majority - 104 domains, compared with 50 relating to the top ten brands from the Brand Finance list). In total, 40 of the domains appear to be under official ownership, leaving 114 third-party domains. The breakdown of site content type of these domains is shown in Figure 4.

Figure 4: Content types observed on the set of 114 third-party domains with names containing cosmetics-related keywords and top cosmetics brand names

Many of the top-level trends are similar to those seen in the perfumes dataset; the three examples of potential counterfeit sites are shown in Figure 5 (note that one of the sites explicitly gives a webmail contact e-mail address, also an indicator of likely non-legitimacy).

Figure 5: Screenshots of examples of sites offering the sale of potentially counterfeit cosmetics items (SLD names: lorealcosmeticspk; kyliecosmetics-bestseller; lancome-cosmetics)

Conclusion

The range of concerning sites identified through these relatively simple searches, together with the large numbers of domains generally containing relevant keywords, gives some indication of the likely scale of the counterfeit problem - which will comprise a significantly larger landscape if other online channels are also considered. These observations highlight the importance of brand owners taking a proactive approach to monitoring and enforcement as part of a wider brand-protection initiative, to protect both their reputations and the safety of their customer base.

References

[1]  https://www.linkedin.com/posts/ipo-counter-infringement_choosesafenotfake-ugcPost-7168534063534821376-aGmT

[2] https://www.a-cg.org/consumer-advice/safe-not-fake

[3] Analysis carried out on 07-Mar-2024

[4] https://www.insidermonkey.com/blog/top-10-perfume-brands-in-the-world-1135358/?singlepage=1; the brands (expressed as the strings used in the domain searches) are: 'dior', 'loreal' ,'estee(-)lauder', 'rolex', 'hermes', 'gucci', 'chanel', 'vuitton', 'shiseido', and 'givaudan'

[5] https://finance.yahoo.com/news/top-50-perfume-brands-world-035618724.html

[6] 'baccarat', 'tom(-)ford', and 'creed'

[7] https://brandirectory.com/rankings/cosmetics/table; the brands are: 'loreal', 'estee(-)lauder', 'nivea', 'gillette', 'dove', 'guerlain', 'lancome', 'clinique', 'pantene', and 'garnier'

[8] 'kylie', 'huda', 'fenty', 'charlotte(-)tilbury', and 'drunk(-)elephant'

This article was first published as an e-book on 17 April 2024 at:

https://www.iamstobbs.com/counterfeit-beauty-products-ebook

"My brand’s bigger than your brand" - Quantifying brand strength using benchmarking analyses

by David Barnett, Bryn Anderson and Tosshan Ramgolam

Introduction: brand strength and brand value

The value associated specifically with an organisation's brand can be significant, typically comprising around 20% of total enterprise value when taken as an average across all industry sectors[1,2]. A number of components contribute to the value of a brand, including the value of associated products and services, and the future potential for revenue generation. Additionally, infringement activity, and the remediating effects of brand protection initiatives, can greatly impact on brand value.

A brand valuation study can have a number of benefits to an organisation, including the capability to better inform trademark protection and licensing strategies, assisting with investment planning and budgeting, quantifying brand damages arising through IP abuse, facilitating access to financial credit, and as part of general valuation projects necessary for tax considerations or mergers and acquisitions.

The first stage in valuing a brand is often a brand strength analysis, which can also provide a basis for comparison against competitor organisations. The strength of a brand can also affect its 'royalty rate'. This is essentially an input into 'royalty relief methodology' which aims to quantify the cost of licensing relevant IP if it were not already owned by the brand). It can also affect customer behaviours - and ultimately revenue - all of which feed into a full, formal, final brand valuation.

In this article, we present an overview of some of the components of a typical brand strength analysis.

Components of brand strength analysis

To a high level, a brand strength analysis might typically make use of some or all of the following inputs, each of which can be expressed as a numerical metric (and which can conveniently be displayed on a 'brand scorecard'), with a weighting controlling the extent of contribution to the overall measurement index:

  • Actions by the brand owner:
    • Brand protection (including consideration of both strategy and execution):
      • IP rights coverage
      • Brand protection implementation (monitoring and enforcement)
    • Brand marketing:
      • Marketing budget
      • Social media use and policies
  • Impact of stakeholders:
    • Customers:
      • 'Top-of-mind' and prompted brand awareness
      • Net Promoter Score (NPS) - a measure of likelihood of customer recommendation
    • Brand perception - including consideration of the factors driving likelihood of recommendation, such as product features / performance, brand attributes, emotional drivers, etc.
    • Media - online prominence and sentiment
    • Corporate and Social Responsibility (CSR)
  • Commercial / financial performance - revenue, revenue growth and profitability

Where appropriate, granular analysis can be carried out on a per-country basis.

Comments on some of the key components within this list are given below.

i. Brand protection programme benchmarking

Measurement and benchmarking (against peer companies) of the effectiveness of an organisation's brand protection programme can be a useful exercise in its own right, helping to identify what constitutes a 'best-in-class' programme, identifying gaps in the current programme, and encouraging internal stakeholder 'buy-in' for future initiatives.

Assessment might typically take account of the following characteristics of the programme:

Examples of some of the considerations for each of the above characteristics are given below:

  • e-commerce marketplaces - To what extent are infringing listings available on a range of core and emerging marketplaces? Of the listings returned in response to brand-specific searches, what proportion are genuine vs. (suspected) counterfeit goods? What should the relative weightings of the priority level / importance of each platform be?
  • Social media platforms - To what extent are infringing posts / accounts visible on core platforms? How protected are key handles / usernames? Are official / authorised accounts verified?
  • Domain names and websites - To what extent is the official portfolio consolidated with an enterprise-class (corporate) registrar? How many brand-specific, third-party domain registrations are there, and what is the breakdown by site content (e.g. official vs. scam / lookalike site)? What does the enforcement and dispute resolution procedure history look like?
  • Litigation - To what extent is the brand taking litigation measures against infringers to gain favourable decisions, deter future infringements, and recover damages / lost profits?
  • 'On-the-ground' programmes - To what extent does the brand have core marks registered with customs in key destination and source locations, to prevent the global movement of counterfeit goods?
  • Media coverage - How well are brand protection successes communicated to, and reported by, credible IP media outlets?
  • Trade association partnerships and memberships - To what extent does the brand collaborate with trade associations and platform-specific programmes vested in challenging intellectual property infringement?
  • Coverage to implement effective online enforcement - To what extent does the brand have core marks protected (e.g. by appropriate trademarks) in key jurisdictions related to e-commerce activity?
  • Coverage to implement effective offline enforcement - To what extent does the brand have core marks protected in key destination, source, and transit jurisdictions to combat counterfeits?
  • Presence of IP 'squatters' in at-risk territories - To what extent are trademark squatters present in first-to-file jurisdictions known to be infringement hotspots (which facilitates the production and proliferation of counterfeit goods)?

As part of the overall analysis, it may be appropriate to consider both the quality of the brand protection strategy itself (i.e. breadth of coverage demonstrating awareness of existing threats and ability to identify emerging threats), and the level of effectiveness of the execution of that strategy (i.e. demonstrable success in mitigating threats). Once these parameters have individually been quantified, companies can be benchmarked against each other by plotting their positions on a matrix, of which a schematic is shown in Figure 1.

Figure 1: Strategy / execution matrix for brand protection programmes

Generally speaking, those brands with the most effective brand protection programmes will appear to the top-right of the plot area; broadly, the matrix allows us to split programmes into one of four categories:

  • Best in class - Effective strategy, well executed (but still requiring ongoing oversight, to allow responsiveness to emerging threats)
  • Requiring realignment - Often arising in response to a lack of updates to a previously effective and well-executed strategy
  • Requiring process review - Reflecting shortcomings in the execution of the strategy, potentially reflecting an overall lack of investment in the programme, or a need to focus in higher priority areas
  • Requiring development - Typically arising in cases where there has been insufficient stakeholder buy-in by the brand owner

ii. Online prominence and sentiment

Online brand prominence and sentiment can readily be metricised using approaches similar to those described in previous articles (e.g. looking at the top 100 global brands[3], fashion brands[4], cryptocurrency brands[5] and AI brands[6]), which allow comparisons between brands to be carried out. Broadly, the calculation is carried out through the use of sets of relevant search queries to generate 'pools' of candidate pages for analysis, and then counting the number and prominence of the mentions of each brand on each page, and the proximity to any of a library of keywords deemed to convey 'positive' or 'negative' sentiment.

Ongoing tracking

As an additional part of the analysis process of these metrics, and consideration of performance over time, it is possible to construct a series of brand protection / brand strength KPIs. These might typically include:

  • General business-related metrics - e.g. such as sales volumes and revenue (overall, and by country)
  • Online performance metrics - e.g.:
    • Numbers of enforced infringements (by infringement type, country, brand, and/or product type)
    • Compliance rate (by platform)
    • Values of infringing items removed (potentially as part of a wider online BP ROI analysis)
  • Offline performance metrics - e.g.:
    • Numbers of civil / criminal enforcement actions
    • Numbers and values of infringing items seized (by country, brand, and/or product type)
    • Numbers of trademarks filed in relevant classes and jurisdictions
    • Numbers of 'overlapping' third-party trademark registrations

Summary and discussion

Measurement of brand strength takes into account a number of components, and can form the basis of a subsequent full brand valuation calculation. The overall measurement index allows brands to be benchmarked against their competitors, and the individual components can also be compared between brands, to give a more granular analysis and identify specific areas where improvements can be made.

In general, we should expect a well-performing brand - i.e. one where the brand strength is high - to be associated with certain characteristics (in terms of the measurement metrics), such as high online prominence and (positive) sentiment, and low levels of infringements. Accordingly, it is important that the calculation framework is constructed in such a way as to correctly to reflect these points. For example, measurement of infringement levels should take account of the overall landscape, rather than simply considering (say) ongoing numbers of enforcements. For example, it may make more sense to incorporate data showing how the long-term trends have changed in response to the implementation of a brand-protection programme.

References

[1] https://www.iamstobbs.com/brand-protection-return-on-investment-ebook

[2] https://static.brandirectory.com/reports/brand-finance-gift-2022-full-report.pdf

[3] https://www.iamstobbs.com/online-brand-prominence-and-sentiment-ebook

[4] https://www.iamstobbs.com/measuring-brand-prominence-of-fashion-brands-ebook

[5] https://www.iamstobbs.com/opinion/coining-success-trends-in-the-online-brand-prominence-and-overall-value-of-cryptocurrencies

[6] https://www.iamstobbs.com/opinion/the-top-generative-ai-brands-in-2024

This article was first published on 16 April 2024 at:

https://www.iamstobbs.com/opinion/my-brands-bigger-than-your-brand-quantifying-brand-strength-using-benchmarking-analyses

Friday, 12 April 2024

A mitwitter-up requiring a quick fitwitter

Following Twitter's somewhat shambolic rebrand to X last year[1], a technical blunder by the organisation on 8 April created a bit of a headache for some brand owners. An addition to the platform was intended to replace any links containing references to 'twitter.com' with copies instead reading 'x.com', but the implementation was rolled out as a clumsy blanket 'copy-and-replace'. This meant that the modification affected any domain name ending with 'twitter.com'. The error presented the potential for a platform-specific style of phishing attack, where any brand website ending with 'x.com' could in theory be impersonated using an equivalently named domain ending with 'twitter.com'. One early report involved the registration of fedetwitter[.]com, to which links would have appeared in tweets as links to fedex[.]com, the legitimate domain name of the logistics organisation[2].

The issue was fixed relatively quickly, but not before a resulting spike of '-twitter' registrations had taken place. These were by both brand owners as defensive actions, and by third parties, potentially with a view to launching an attack or, in some cases, as a way of drawing attention to the error. In this article, we look at the batch of domain registrations relevant to this incident, providing also a case study of the power of domain-monitoring tools which are able to be configured to inspect specific domain-name patterns.

In total, over 2,500 domains with second-level names (SLDs, i.e. the part to the left of the dot) ending with 'twitter' are currently registered, according to versions of the domain zone files downloaded on 11-Apr-2024. Of these, 71 show domain creation dates in the three-day period between 08 and 10-Apr-2024, a marked increase on the pre-existing 'background' levels of activity (Figure 1).

Figure 1: Daily numbers of registrations of domains with SLDs ending with 'twitter'

Of these, a significant proportion appear to have been registered to take advantage of the Twitter/X string-replacement issue to target the websites of well-known brands, with examples including ametwitter[.]com, carfatwitter[.]com, cinepletwitter[.]com, citritwitter[.]com, clorotwitter[.]com, dropbotwitter[.]com, duretwitter[.]com, equifatwitter[.]com, fedetwitter[.]com, firefotwitter[.]com, firefotwitter[.]site, fotwitter[.]com, goodrtwitter[.]com, hbomatwitter[.]com, horotwitter[.]com, imatwitter[.]com, indetwitter[.]com, kleenetwitter[.]com, linutwitter[.]com, netflitwitter[.]com, nutanitwitter[.]com, roblotwitter[.]com, roletwitter[.]com, space-twitter[.]com, spotetwitter[.]com, square-enitwitter[.]com, timetwitter[.]com, turbotatwitter[.]com, witwitter[.]com, xbotwitter[.]com, xerotwitter[.]com and yandetwitter[.]com (targeting - respectively - amex[.]com, carfax[.]com, etc.). Examples were also found pertaining to other content (including adult material, with the dataset including gaysetwitter[.]com and setwitter[.]com).

Of the 71 sites registered since 08-Apr-2024, only one (ametwitter[.]com) was found to resolve to content relating to the brand in question (American Express, 'amex'), and may thereby pose a potential threat (Figure 2). A number of others were found to resolve to warning pages highlighting the risk of misdirection (Figure 3).

Figure 2: Live content on ametwitter[.]com as of 11-Apr-2024

Figure 3: Live 'warning' pages as of 11-Apr-2024 (SLDs: apetwitter, bitmetwitter, carfatwitter, citritwitter, equifatwitter, netflitwitter)

The remainder of the sites appear to pose no serious risk currently, but may have been 'weaponised' for subsequent use in a brand-impersonation attack if the vulnerability had not been rectified by X (together with other registrations which might have arisen). The findings highlight the importance of ongoing proactive brand monitoring which is sufficiently configurable to be able to cover relevant brand variants in response to the emergence of specific issues.

References

[1] https://www.iamstobbs.com/opinion/x-trademarks-the-spot-not-a-textbook-example-of-a-successful-rebranding-exercise

[2] https://krebsonsecurity.com/2024/04/twitters-clumsy-pivot-to-x-com-is-a-gift-to-phishers/

This article was first published on 12 April 2024 at:

https://www.iamstobbs.com/opinion/a-mitwitter-up-requiring-a-quick-fitwitter

Wednesday, 3 April 2024

Tracking the UK trade in fakes – Part 2: Ins and outs

In the first article in this series[1], we considered the set of towns in the UK which were found most frequently to be associated with the trade in counterfeit goods, as the locations of either the senders or recipients of items. The analysis is based on case studies of working with customs and law enforcement for three key clients in different industry areas.

In this follow-up, we use the same dataset, but with the sender and recipient locations considered separately. Sender locations (goods 'out') are associated with distribution of goods (potentially either as manufacturing points, onward transport hubs, or locations of direct sale). They may constitute suitable candidates for on-the-ground investigation work, whilst recipient locations (goods 'in') are more likely to be reflective of routes by which the infringing items arrive into the country from overseas points of manufacture and/or distribution, and can provide insights into supply chains.

Figure 1 shows a 're-cut' of the heat map shown in Part 1 of this series, separating out locations from which goods are being sent ('out') (shown in red), from those where goods are being received ('in') (in green). The size of the circle in each case is proportional to the number of times each location appears in the dataset, and place names in blue are those which appear in both lists (i.e. as both sender and recipient locations).

Figure 1: Bubble chart 'heat map' showing the frequency with which each town has been the identified location of a sender (red) or recipient (green) of counterfeit goods

The primary 'out' locations are highlighted as those around Manchester, western Scotland (around Glasgow), north-east England (around Sunderland), the West Midlands (around Leicester), and Milton Keynes. The 'in' locations are more widespread, but a number of major airport and port locations are picked up, including Belfast, Glasgow, Hastings, Liverpool, and Newport.

For towns identified as recipient locations (goods 'in'), it is instructive to categorise the data by the country of origin, which is likely in many cases to relate to geographies in which the items are being manufactured. The frequencies with which the different origin countries appear in the dataset are shown in Table 1.

Sender location country
                                            
Proportion of instances
                                            
  Turkey 51%
  Hong Kong (China) 18%
  China 17%
  UK 2%
  Germany 0.4%
  India 0.4%
  Netherlands 0.4%
  Pakistan 0.4%
  Saudi Arabia 0.4%
  Singapore 0.4%
  South Korea 0.4%
  UAE 0.4%
  (not known) 8%

Table 1: Frequency of appearance of each sender location country within the dataset, for goods received in the UK

Turkey and Hong Kong / China can be seen to account for the vast majority of inward shipments by a striking margin. Whilst a significant part of this picture is likely to be the frequency of association of these locations with the manufacture of counterfeits, it is also likely in part to reflect the focus by customs and law enforcement on these geographies perceived as being 'high risk'.

The same dataset is represented in Figure 2, showing the frequency of each (overseas) country as an identified point of origin for goods intercepted at recipient locations in the UK.

Figure 2: Bubble chart 'heat map' showing the frequency with which each non-UK country has been identified as the location of a sender of counterfeit goods intercepted at recipient locations in the UK (place names are shown only for the most frequent recipient locations)

The analysis shows that items from Hong Kong (dark green in Figure 2) most commonly arrive at ports or airports in the south-east and north of England, items from China (red) in similar locations, plus Glasgow, and items from Turkey (blue) in a wider range of locations, but more commonly via the coastal ports.

As a final part of the analysis, it is instructive to consider the specific locations within Turkey and China from which the counterfeit goods received in the UK most commonly have been sent (where this information is available) - this is referred to below as the point of 'origin', although in many cases these locations may simply be distribution hubs, rather than the initial places of manufacture. This information is shown in Tables 2 and 3.

Town / city
                                            
Proportion of instances
                                            
  Marmaris 41%
  MuÄŸla 20%
  Ä°stanbul 16%
  Esenler 2%
  Ankara 0.8%
  Arnavutköy 0.8%
  Aydın 0.8%
  Bursa 0.8%
  Dalaman 0.8%
  Fethiye 0.8%
  Hayrabolu 0.8%
  Kapaklı 0.8%
  Kayseri 0.8%
  Konya 0.8%
  Mersin 0.8%
  MuratpaÅŸa 0.8%

Table 2: Most common locations of origin of counterfeit goods within Turkey

Town / city
                                            
Proportion of instances
                                            
  Beijing 19%
  Huizhou 19%
  Guangzhou 14%
  Foshan 9%
  Shenzhen 7%
  Putian 5%
  Dongguan 2%
  Jiangmen 2%
  Shanghai 2%
  Yiwu 2%
  Zhengzhou 2%

Table 3: Most common locations of origin of counterfeit goods within China

The locations of these towns / cities are shown in Figures 3 and 4.

Figure 3: Most common locations of origin of counterfeit goods within Turkey (map data © Google)

Figure 4: Most common locations of origin of counterfeit goods within China (map data © Google)

Key features picked out from these visualisations are the clusters of activity around the port locations of Marmaris and İstanbul in Turkey (presumably primarily shipping points), and the manufacturing centres in Guangdong province in China.

Overall, this overview has shown how analysis and data-visualisation techniques can be used to highlight patterns of activity which can help inform policy on the most effective ways of disrupting the supply chain of counterfeit goods. Tactics can include focusing on-the-ground investigations, and customs and law enforcement focus and training, in appropriate locations in the primary geographical region of interest (i.e. the UK, in our study). This involves identifying the highest-risk points of origin for closer scrutiny of incoming goods, and carrying out on-the-ground work - including raids and seizures - at identified key overseas focuses of activity.

Reference

[1] https://www.iamstobbs.com/opinion/tracking-the-uk-trade-in-fakes-counterfeit-hotspots

This article was first published on 3 April 2024 at:

https://www.iamstobbs.com/opinion/tracking-the-uk-trade-in-fakes-ins-and-outs

Wednesday, 27 March 2024

Tracking the UK trade in fakes - Part 1: Counterfeit hotspots

The trade in counterfeit products is a complex picture, involving detailed interactions between the online and offline worlds. The offline ('real-world') movement of products is a key element of the overall landscape, encompassing the supply chain for items to be sold online, as well as for physical retailers.

Stobbs' anti-counterfeiting function assists business with addressing this offline activity, working with customs and law enforcement to intercept and disrupt the transit of infringing goods, and provide intelligence and evidence on their source.

In this case study, we draw supply-chain insights by utilising aggregated data from interceptions and seizures of counterfeit products for three key clients in distinct industry areas:

  • Client A: Clothing / apparel
  • Client B: Food
  • Client C: Manufacturing (tools and accessories)

The wider dataset covers activity which is international in scope, but in this first analysis we focus on activity relating to the UK only; that is, where either the sender (consigner) or recipient (consignee) location or both are in the UK. In the initial study, we consider all instances of sender and recipient locations together as a single dataset (since, in principle, both may represent intermediate stages in the overall supply chain of the infringing goods).

In order to provide a low-granularity overview, each location (usually represented as a full physical address) is assigned to its host town / city (hereafter referred to as the 'town'). From this dataset, we produce a bubble chart 'heat map', where the size of the circle for each town is proportional to the number of times it appears in the overall dataset (i.e. the frequency of its association with the trade in counterfeit goods as a transit point)[1]. This overview is shown in Figure 1.

Figure 1: Bubble chart 'heat map' showing the frequency with which each town has been the identified location of a sender or recipient of counterfeit goods[2]

The top level trends in the UK locations of counterfeit hostspots, as shown by the data visualisation, are as follows:

  • Much of the activity is concentrated in a geographical brand running from south-east to north-west, with primary centres in and around Manchester, London, and Glasgow.
  • Secondary centres of activity are apparent in Northern Ireland, the West Midlands, Edinburgh and eastern Scotland, and north-east England.
  • Other features highlighted on the heat map include the transit routes between Glasgow and Edinburgh, and key port locations (e.g. Hastings, Newport, Aberdeen, Bridlington, etc.).

Detailed views of some of the key areas of focus are shown in Figure 2.

Figure 2: Detailed views of the counterfeit activity 'heat map': (a) southern Scotland and Northern Ireland; (b) Manchester and surroundings; (c) London and surroundings

It is then possible to conduct deeper dives within a specific town / region by mapping the specific locations at a postcode level. For Manchester (the largest overall focus of activity) for example, also encompassing the overlapping areas of Salford, Stockport, Oldham, Rochdale and Irlam, the distribution of the individual locations identified as being associated with the trade in counterfeit goods is as shown in Figure 3.

Figure 3: Individual locations of interest within the Manchester region (postcodes appearing twice in the dataset shown using pink markers; three times using orange markers)

This type of analysis can help to inform decisions on locations where further on-the-ground investigations and scoping exercises may prove fruitful. In the case of the Manchester mapping exercise, for example, the analysis successfully highlights a cluster of activity around the Cheetham Hill area to the north of the city, long recognised as a real-world location involved in the sale of counterfeit items[3].

In the next part of this analysis, we carry out a more granular analysis of the data, separating out origin locations from destination locations. This helps us gain insights into the routes by which counterfeits are arriving into the country in cases where they are imported from overseas. It also highlights the regions from which they originate (to provide guidance on where customs training initiatives should be focused), and into locations from which counterfeit sales are being distributed (which may form the focuses of further on-the-ground investigation work).

References

[1] Note that there may be some 'overlap' within the data - e.g. in some cases a location of Rochdale or Oldham may have been categorised as being within the broader 'Manchester' area; however, the overall clustering of the data is still apparent from the final visualisation

[2] Coastline data source: https://www.evl.uic.edu/pape/data/WDB/

[3] https://www.bbc.co.uk/news/uk-england-manchester-67292006

This article was first published on 27 March 2024 at:

https://www.iamstobbs.com/opinion/tracking-the-uk-trade-in-fakes-counterfeit-hotspots

Tuesday, 19 March 2024

Web2/Web3 crossover - Part 3: Investigations and clustering

In the previous articles in this series[1,2], we have considered the emergence of new links between content in the classic Web2 ('standard' website and Internet) environment and the decentralised, blockchain-based world of Web3 (including blockchain domains, cryptocurrency and NFTs). In this follow-up, we consider how additional insights on links between content across these environments can be gained through investigation and clustering techniques.

One of the principal appeals of Web3 content is the opportunity for high levels of anonymity (part of the picture involved in a desire for lower restriction and regulation), and a lack of ties to 'real-world' contact details. However, this does not mean that no open-source intelligence (OSINT)-style techniques can be applied. Many of the characteristics associated with Web3 content - such as cryptocurrency wallet addresses - are unique and distinctive, and can be tied to other findings where the same details are used, and can imply (for example) that a particular entity may be associated with multiple infringements.

In this article, we present two anonymised 'mini' case studies illustrating how these types of techniques can be applied. Key to this process is the existence of publicly available databases ('ledgers') of information relating to Web3 content, which can be accessed through Web2 infrastructure. One such example is the etherscan.io website.

The case studies concern instances where bad actors were infringing particular marks (referred to in this article as Brand1 and Brand2), to promote cryptocurrencies. This is similar to the examples presented in Part 2 of this series. The first case made use of an associated infringing blockchain domain (Brand1deployer.eth) for which details were available on the etherscan.io public ledger.

The results of a search for the blockchain domain name bring up a number of unique strings ('hashes') relating to the domain and its registrant (Figure 1).

Figure 1: Results of a search for Brand1deployer.eth on etherscan.io

Clicking on the 'resolved address' string for the domain brings up an additional page, giving details of transactions made to and from the domain / user (Figure 2).

Figure 2: Extracts from the etherscan.io page giving details of transactions associated with Brand1deployer.eth

In this case, the fourth row from the bottom is the most significant; the content of the 'To' column reads 'Create: Brand1', indicating that this transaction is associated with creation of the 'Brand1'-infringing smart contract (a blockchain program set to run when certain conditions are met, and typically used to execute the terms of an agreement). Clicking on this link brings up another page pertaining to the particular smart contract specifically, giving information on users who have purchased the currency and the associated transactions.

Similarly, the ledger website includes pages giving details and connections associated with the domain registrant, etc., which can serve as a basis for building further links.

The second case involved the cryptocurrency 'Brand2 Coin' or '$Brand2', which was available to be viewed and purchased through reputable decentralised exchanges (DEXs) such as UniSwap, and was also involved in the sale of NFTs via the OpenSea marketplace. This case also utilised a blockchain domain name (Brand2deployer.eth), but was additionally promoted across Web2 content. In this instance, an associated Twitter account ('@Brand2-2Coin') was set up and used to promote the infringing currency, with the smart contract hash (the string beginning '0xf484…') also explicitly given in some postings (Figure 3).

Figure 3: A Twitter (X) post advertising the 'Brand2 Coin' infringing cryptocurrency

The Twitter profile also gave the address of an associated Web2 website (Brand2coin.xyz) and a Telegram link (t.me/Brand2coinportal).

Using a similar approach to that shown above, it is possible to search for the smart contract string on the etherscan.io public ledger to reveal associated details, such as information relating to the contract creator ('Brand2deployer.eth').

This brief overview highlights that, although it may be unusual to establish links from Web3 content to 'real world' contact details, application of OSINT-style techniques can still be used to draw connections and reveal additional related findings, and can help to provide information surrounding infringing use of cryptocurrencies.

References

[1] https://www.iamstobbs.com/opinion/the-crossover-two-recent-developments-in-web2/web3-interaction

[2] https://www.iamstobbs.com/opinion/web2/web3-crossover-brand-related-crypto-infringements

This article was first published on 19 March 2024 at:

https://www.iamstobbs.com/opinion/web2/web3-crossover-investigations-and-clustering

Brand Protection in the Digital Era: Interview with David Barnett

by Smart Protection Digital threats are evolving faster than ever. With AI-driven phishing and fraudulent marketplaces, traditional brand pr...