Risk & Fraud

Coupon fraud in trade schemes: patterns, controls, and what leakage to accept

Every trade coupon scheme leaks. The useful questions are how much, through which specific mechanism, and whether the control you are about to add costs more in blocked honest members than it saves. Brands that skip that third question end up with a program that is technically secure and commercially dead.

Scan data being analysed for anomalous patterns across a distribution network

Key takeaways

  • Set an acceptable leakage rate before launch — typically 3–8% of pool — and design controls to hold it, not to reach zero.
  • Placement beats detection. A code that cannot be reached before the pack is opened removes most fraud without any algorithm.
  • Escalate to review with the reward pending; never block an honest member mid-job. Wrongful blocks cost more members than fraud costs rupees.
  • Invalid-code scan clusters are counterfeit intelligence, not just failed claims — route them to brand protection.

The eight recurring patterns

1

Pre-sale harvesting

Counter or warehouse staff claim codes visible on the outside of packs before sale. Usually the single largest loss in any scheme with external codes. Control: move the code inside the pack, under a cap, or onto the product itself. Detection alone will not fix a placement problem.

2

Code sharing in trade groups

Photographs of codes circulate on WhatsApp and are claimed by whoever is fastest. Control: single-use serialised codes bound to the first valid claim and the claimant's identity, plus a visible message explaining why a shared code failed.

3

Sequential guessing

If codes are sequential or weakly structured, a scripted attempt will find valid ones. Control: a large sparse keyspace with a check digit, so guesses fail against the database rather than against a visible pattern, and rate-limit validation attempts per device.

4

Bulk scanning by one member

A single member scans a district's worth of stock, usually with a dealer's cooperation. Control: velocity caps per member per day, geo-clustering that flags claims resolving repeatedly to the same coordinates, and escalation to verification above a threshold rather than a hard cut-off.

5

Ghost claims

In installer and warranty schemes, serials registered as installed that never left the warehouse. Control: customer OTP sent to the number on the sale record, geo-stamped photographs at randomised checkpoints, and cross-checks against dispatch data.

6

Photo and evidence reuse

The same installation or display photographed for multiple claims. Control: perceptual image hashing, EXIF and timestamp validation, and randomising which checkpoint photograph is requested so evidence cannot be pre-staged.

7

Collusive rings

A dealer, a member and sometimes a field executive coordinating claims. Control: network analysis on shared devices, VPAs, bank accounts and locations. This is the pattern where investigation, not automation, does the work.

8

Counterfeit codes

Fake product carrying copied codes, which turns your program into a certification service for counterfeits. Control: validate against a live database rather than a checksum, invalidate duplicated codes on second use, and treat repeated invalid scans in a geography as an intelligence signal.

Placement beats detection

It is worth stating plainly, because most fraud budgets are spent the wrong way round. A code under a cap or inside a primary pack eliminates pre-sale harvesting — the largest single loss category — at close to zero ongoing cost. A sophisticated anomaly engine watching an externally printed code is expensive, imperfect, and generates false positives against honest members. Fix the physical design first; use analytics for what remains.

Setting an acceptable leakage rate

Zero leakage is achievable and always too expensive, because the controls required — mandatory verification, hard blocks, manual review of everything — suppress genuine participation more than they suppress fraud. Practical targets:

Scheme typeAcceptable leakageDominant risk
Influencer scan-to-earn, internal codes3–5% of poolBulk scanning with dealer collusion
Influencer scan-to-earn, external codes8–15% of poolPre-sale harvesting — fix placement instead
Retailer invoice-linked coupons1–3% of poolClaim concentration and cross-territory arbitrage
Installer registration schemes4–8% of poolGhost claims and evidence reuse
High-value milestone and gift schemes< 2% of valueCoordinated rings; worth manual verification

Decide the number before launch, measure against it monthly, and treat a breach as a design question rather than an enforcement one. If leakage is 14% on an internally coded scheme, something structural is wrong — not something a stricter rule will fix.

How to intervene without damaging the program

  1. Hold, do not block. Mark the reward pending and tell the member why, in his language. A member stopped mid-job in front of a customer becomes a story that circulates for months.
  2. Investigate before clawback. Reversing a credited reward without explanation is the single most damaging action available to a program operator.
  3. Give an appeal route with a human. Genuine edge cases exist — a large contract job, a reinstallation, a member helping a colleague scan.
  4. Explain outcomes. Honest members judge the program by how the accused are treated, and they discuss it.
  5. Fix the cause. Every confirmed pattern should end in a design change, not just an enforcement action.

The intelligence dividend

A well-instrumented scheme produces something a brand cannot otherwise buy: a live map of where invalid codes are being scanned. That is where counterfeit product is circulating, months before the sales team reports it. Route those clusters to brand protection weekly, and the fraud-control system stops being purely a cost centre. The joint design is covered in anti-counterfeit plus loyalty in one QR, and the wider control framework in loyalty program fraud prevention.

Frequently asked questions

What is the biggest source of coupon fraud in Indian trade schemes?

Pre-sale harvesting — counter or warehouse staff claiming codes that are visible on the outside of packs before the product is sold. It is a placement problem rather than a detection problem, and moving the code inside the pack, under a cap or onto the product itself removes most of it at close to zero ongoing cost.

What leakage rate is acceptable in a trade loyalty scheme?

Typically 3–5% of pool for influencer schemes with internal codes, 1–3% for retailer invoice-linked coupons, 4–8% for installer registration schemes and under 2% for high-value milestone rewards. Externally coded influencer schemes often run 8–15%, which is a signal to change the packaging rather than tighten the rules.

How do you stop coupon codes being shared on WhatsApp?

Make every code single-use, serialised from a large sparse keyspace with a check digit, and bind it to the first valid claim along with the claimant's identity. Show a clear message explaining why a shared code failed, so the member who was beaten to it understands the rule rather than assuming the scheme is broken.

Should suspicious claims be blocked automatically?

No. Hold them as pending with a clear explanation in the member's language and route them to review. Blocking an honest member mid-job, in front of a customer, produces a story that circulates for months and costs more participation than the disputed amount is worth. Always provide an appeal route staffed by a person.

How do you detect collusion between a dealer and a member?

Network analysis across shared devices, VPAs, bank accounts and claim locations, looking for clusters that persist over time rather than single anomalies. This is the one pattern where investigation beats automation — the signals are usually clear once someone looks, but rarely trip a single-rule threshold.

What should happen to invalid code scans?

They should be logged, mapped and routed to brand protection weekly, not simply rejected. Repeated invalid scans in a geography indicate counterfeit product carrying copied or fabricated codes, and the loyalty program is usually the earliest detection system a brand has — often months ahead of field reports.

Does clawing back fraudulent rewards work?

Only when it is investigated, explained and appealable. Silent reversals are the most damaging action a program operator can take, because honest members cannot distinguish them from arbitrary ones. Every confirmed pattern should also produce a design change, since enforcement without a structural fix simply repeats next quarter.

Want this running for your brand?

Unotag mirrors your channel structure in a sandbox within 48 hours — your SKUs, your slabs, your states.

Related reading