How a Family Company Proved Forty "Sellers" Were One Counterfeit Operation
Fake versions of their products were flooding the market and eroding trust they'd spent decades building. Here's how their brand lead used Expose to prove that dozens of "independent" sellers were a single operation - and to take it apart.

On this page
When the fakes started getting good
For three generations, the Reyes family had made a single thing well: a line of precision skin-care tools, sold under a brand their grandmother started in a back room. It was a small company with an outsized reputation, the kind customers recommended to friends. So the first counterfeits were almost flattering - clumsy knockoffs, easy to spot, the price of being worth copying.
Then the fakes got good. By the time Sofia Reyes, who ran the brand for the family, started getting the emails, the counterfeits were close enough to fool careful buyers. The packaging was nearly perfect. The listings used the company's own product photography. And the reviews were turning ugly - one-star complaints about rusting blades, skin irritation, and tools that fell apart in a week, all attributed to a brand whose entire value was that it didn't do those things. Customers weren't just being overcharged for junk; they were being hurt, and they blamed the Reyes name.
The fakes were spread across what looked like dozens of unrelated sellers on multiple marketplaces. Reporting them one by one was like bailing a boat with a teaspoon; take one down and three appeared. Sofia suspected they weren't really separate at all. To act on that suspicion, she had to prove it. She opened Expose.
Many storefronts, one fingerprint
Sofia started by collecting everything visible about the fraudulent listings - the seller names, the contact emails buried in their pages, the phone numbers some used for "customer service," the websites a few linked to, and the photos they'd stolen. On the surface, it was chaos: forty different shop names, scattered across marketplaces, presenting as independent small businesses in a handful of countries.
She fed the artifacts into Expose and asked it to do the thing that defeats a human working alone - correlate across all of them at once and surface what they secretly shared. Counterfeit operations face the same problem every operation at scale faces: running forty truly independent storefronts is expensive and tedious, so they cut corners. They reuse infrastructure. And reused infrastructure is a fingerprint.
The pattern emerged quickly. Beneath forty storefront names, Expose surfaced a much smaller skeleton:
- several "customer service" emails that resolved to the same handful of registrant addresses;
- a cluster of look-alike websites sharing the same hosting provider, name-server pattern, and a reused analytics identifier;
- phone numbers that traced back to the same small set of VoIP reseller lines;
- two payment-processing handles that appeared, unchanged, across storefronts claiming to be in different countries.
That shared analytics identifier was especially damning. It's a small string of text the operator had pasted into website after website to track their own traffic - and in doing so, stamped the same signature across "competing" shops that were supposedly run by strangers. Forty storefronts collapsed into one operation wearing forty masks.
"I'd been fighting forty enemies," Sofia said. "Expose showed me I'd been fighting one enemy forty times. That changes everything - the strategy, the legal approach, who you even send the letter to."From storefronts to the people running them
Proving the storefronts were one operation was the turning point, but it wasn't the destination. Takedown notices to marketplaces would knock out listings; they wouldn't stop the operator from spinning up forty more. To make the problem actually go away, Sofia needed to move from infrastructure to accountability - the humans and the registered entities behind the fingerprint.
She pivoted Expose from the storefronts to the contact data threaded through them. One of the reused registrant emails - on an older site, registered before the operator had tightened their habits - carried an exposed contact record. Run through Expose, that address connected to a business registration for an import company in a jurisdiction known for light-touch incorporation, and that registration shared a listed address and a director name with two of the payment handles. The same address appeared on shipping details a few of the counterfeit sites had carelessly left in their checkout pages.
Hitting the operation where it lived
Armed with the dossier, Sofia and the company's attorney stopped playing whack-a-mole and went after the structure. They did several things in coordination rather than one at a time.
First, they preserved everything - a structured export from Expose capturing each storefront, the shared infrastructure, the payment handles, and the entity trail, with dates, so the evidence was contemporaneous and survived the inevitable scrubbing once the operator realized they'd been mapped. Second, they submitted consolidated takedown and brand-protection complaints to each marketplace, framed not as forty isolated listings but as one coordinated infringement ring, with the shared fingerprints laid out. Linked storefronts came down in batches rather than one frustrating listing at a time. Third, they reported the shared payment handles to the relevant processors, the choke point an operation can't easily replace - it's far harder to re-establish payment processing than to register a new shop name.
Finally, counsel sent a properly targeted legal notice - to the actual registered entity the trail identified, not into the void of a fake storefront's contact form. For the first time, the letters were landing somewhere real.
"Every takedown before this had felt like punching fog," Sofia said. "Once we had the map, we were hitting the same body from five directions at once - the listings, the hosting, the payments, the entity, the record. That's when it actually started to hurt them instead of us."A repeatable brand-protection playbook
Sofia wrote the approach down so it didn't live only in her head:
- Collect every artifact from suspicious sellers - names, emails, phone numbers, linked sites, stolen photos - before assuming they're separate.
- Correlate across all of them at once to surface shared infrastructure: hosting, name servers, analytics IDs, payment handles. Reused infrastructure is the fingerprint that links "independent" shops.
- Follow the cluster from storefronts to a named entity where the public record allows it - registrations, addresses, directors - so legal notices land somewhere real.
- Hit the structure from several angles together - consolidated takedowns, payment-processor reports, targeted legal notice - rather than chasing listings one by one.
- Preserve everything with dates, and monitor your own footprint on an ongoing basis to catch new rings while they're still small.
The quiet lesson
The counterfeiters weren't masterminds, they were a single operation cutting the same corners every operation cuts at scale, betting that their forty masks would keep anyone from seeing the one face behind them. They were right for a while, because connecting forty storefronts by hand is nearly impossible. They were wrong once it became a single correlated lookup.
The fingerprints had been in the open the entire time - in the reused emails, the shared hosting, the analytics tag pasted from one site to the next. The difference was simply the will to look across all of it at once, and a way to look quickly enough to turn forty enemies back into the one they'd always been.
Could you prove that "independent" sellers are one operation?
Expose correlates emails, domains, infrastructure, and payment handles into a single picture - so you fight the operation, not the symptoms.