A cracked shield with a gavel bursting open into a network of e-commerce listings, shopping bags, and product images — illustrating how counterfeit networks reconstitute after takedowns

If the Same Counterfeit Network Reappears After Every Takedown, What Exactly Did You Disrupt?

A brand protection team removes a seller account. Product photos, seller name, and listings disappear within days. Three weeks later, the same product photos surface under a different account name, a different registered business, sometimes a different marketplace entirely. The team removes that one too. It comes back again.

Practitioners who have run enforcement programs for more than a year recognize this pattern immediately. The question worth asking is not whether it happens. It is what the first takedown actually accomplished.

A Takedown Measures a Listing, Not a Network

Most enforcement reporting counts what left the platform: listings removed, accounts suspended, units seized, cease-and-desist letters sent. These are legitimate, verifiable actions, and they matter to the customer who would otherwise have bought a fake router or handbag that day.

But a listing is a legal and technical unit created by the platform’s reporting workflow. It is not the same as the operation behind it. When a counterfeit sale is generated by a supplier relationship, a repackaging facility, a set of product photographs, and a payment processing account, the takedown addresses exactly one visible expression of that operation — and only the expression currently in front of the reviewer.

The counterfeit trade is large enough that this gap matters at scale. The OECD and the EU Intellectual Property Office estimated in their 2025 joint study, Mapping Global Trade in Fakes, that global trade in counterfeit and pirated goods reached USD 467 billion in 2021, or 2.3 percent of world imports, with clothing, footwear, and leather goods accounting for 62 percent of seizures.[2][3] That volume is not produced by isolated bad actors reacting to enforcement one listing at a time. It is produced by operations built to withstand exactly that kind of enforcement.

Brand Protection IP Enforcement

The Boundary Enforcement Uses Is Not the Boundary the Network Uses

Here is the deeper issue. A takedown is scoped to whatever unit the platform, the case file, or the legal complaint defines: one seller account, one storefront, one shipment. That scope is administratively convenient. It is not how the counterfeit operation is actually organized.

The clearest documented illustration is the Department of Justice’s case against Onur Aksoy, who pleaded guilty in 2023 to running what prosecutors called the “Pro Network Entities”: at least 19 companies registered across New Jersey and Florida, roughly 15 Amazon storefronts, and at least 10 eBay storefronts, all funneling counterfeit Cisco networking equipment from the same suppliers in China and Hong Kong. Between 2014 and 2022, Customs and Border Protection seized approximately 180 shipments bound for these entities. Cisco sent seven cease-and-desist letters between 2014 and 2019. Each seizure, each letter, each individual storefront suspension addressed one node. None of them addressed the supplier relationship, the shared warehousing, or the fact that Aksoy kept ordering from the same counterfeiters after each seizure, at times using a false identity to evade further scrutiny. The operation generated over $100 million in revenue precisely because it was structured as more entities than any single enforcement action could reach at once.[1]

Few operations are documented this thoroughly, which is exactly the point: most of what investigators see is one node at a time, without the case file that later reveals the other eighteen companies.

What the Network Leaves Behind, Even When the Listing Disappears

The Aksoy case is unusual only in its scale and in how much of it surfaced in a single prosecution. The underlying mechanism — a single operation distributing itself across enough separately registered fronts that no individual takedown threatens the whole — is consistent with what researchers have found when they study counterfeit sellers as a network rather than as individual listings. Academic work on counterfeit seller detection published in ACM’s Transactions on Multimedia Computing, Communications, and Applications has examined network-analytic approaches and found that counterfeit sellers display measurable structural signatures, patterns in account centrality and shared connections, that distinguish coordinated operations from independent bad actors.[4] Those signatures exist at the network level. A reviewer evaluating one listing at a time has no way to see them.

This is why the same reused product photograph, the same shipping origin, or the same payment processing account can reappear across takedowns that were each, individually, closed as resolved.

The Harder Question: Is Network-Level Enforcement Actually Available to You?

It would be convenient to conclude that every takedown should be treated as network disruption. That is not always realistic. Many brand protection teams do not have subpoena power, cross-platform data-sharing agreements, or the legal standing to pursue a supplier in another jurisdiction. For them, removing today’s listing is a genuine harm reduction action, even if the supplier relationship survives it. There is nothing dishonest about taking the action that is actually available to you.

The failure is not in doing listing-level enforcement. The failure is in treating a listing-level action as though it resolved a network-level problem, then closing the case file on that assumption. A takedown logged as harm reduction — with the underlying entity flagged as unresolved and monitored for reappearance — is doing something different from a takedown logged as case closed.

This is the specific design problem behind Hubstream’s approach to brand protection work: treating a supplier address, a payment ID, or a reused product image as structural memory that persists across cases, rather than information that disappears the moment a single case closes.

What Better Enforcement Tracks

The distinction that matters operationally is between disrupting a node and disrupting a structure. Disrupting a node means the listing, account, or shipment in front of you stops. Disrupting a structure means the fulfillment relationship, the financial rail, or the identity infrastructure that generated that listing can no longer be reused to generate the next one.

Getting from the first to the second requires carrying identifying detail forward across cases rather than closing it out with the case: shared images, shared shipping or return addresses, shared payment processor merchant IDs, shared business registration agents, shared device or account creation patterns. None of these require new legal authority to collect. They require an investigative environment where a detail captured in one case does not disappear when that case closes, and where a new case can be checked against everything the organization has already seen — not just against the current platform’s own repeat-offender list.

Questions Worth Asking Before Calling a Takedown Resolved

Before marking an enforcement action closed, it is worth running through what the case file actually captured and what it left open:

Does the new seller reuse any product image, description text, or packaging asset from an account already removed? Does the shipping origin, return address, or warehouse location match a prior case, even under a different business name? Is the payment processor, merchant ID, or bank routing detail shared with an entity already flagged? Was this case closed because the platform confirmed removal, or because someone checked whether the underlying entity resurfaced? If this seller is connected to five others, would your current case management structure surface that connection, or would each be reviewed in isolation?

None of these questions require more legal authority than a standard takedown already uses. They require treating each case as a data point in a structure rather than a transaction to close.

The Real Measure Is What Can No Longer Be Reused

The number of listings removed is a real metric, but it answers the wrong question. The more useful measure is how much of the underlying infrastructure — the supplier relationship, the payment rail, the fulfillment address — can no longer be reused once it has been identified. By that measure, a takedown that removes one listing while leaving related entities untouched has not failed, exactly. It has simply not yet started the work that matters.

That is a different design goal than processing takedown requests faster. It is the difference between closing cases and closing networks — and it is worth knowing, before the next takedown request goes out, which one your program is actually built to do.


References

1. U.S. Department of Justice, “CEO of Dozens of Companies Pleads Guilty to Massive Scheme to Traffic in Fraudulent and Counterfeit Cisco Networking Equipment,” June 6, 2023.

2. OECD, “Global Trade in Fake Goods Reached USD 467 Billion, Posing Risks to Consumer Safety and Compromising Intellectual Property,” May 2025.

3. EUIPO and OECD, “Mapping Global Trade in Fakes 2025.”

4. ACM Transactions on Multimedia Computing, Communications, and Applications, “Social Network Analytic-Based Online Counterfeit Seller Detection Using User Shared Images.”

See it in action.

Request Demo