Join our Newsletter — 33% off our NHI Course
Home FAQ Cyber Security Who is accountable when counterfeit goods move through…
Cyber Security

Who is accountable when counterfeit goods move through a marketplace?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated August 28, 2026 Domain: Cyber Security

Accountability is shared, but the marketplace owns the trust framework that allowed the seller to reach buyers. Brand owners, payment providers, and enforcement teams all have roles, yet the platform is responsible for onboarding controls, listing review, and response escalation. If those controls are weak, the marketplace becomes the fraud distribution channel.

Why This Matters for Security Teams

Counterfeit goods are rarely just a brand-protection problem. In a marketplace, the real security question is who controlled seller onboarding, listing publication, payment routing, and takedown response. When those trust controls are weak, the platform does not merely host fraud, it distributes it at scale. Current guidance suggests treating marketplace accountability as a governance issue, not only an enforcement issue, because the platform sets the conditions under which bad actors can operate.

This is why NHI management patterns matter even outside classic infrastructure. The same weak control themes seen in Ultimate Guide to NHIs show up here as overly broad permissions, poor revocation discipline, and inadequate visibility into who or what is acting on the platform. NHIMG notes that 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, which is a reminder that weak identity controls often become the delivery mechanism for downstream abuse. External controls such as CISA cyber threat advisories reinforce the same operational lesson: trust boundaries must be continuously validated, not assumed.

In practice, many security teams discover counterfeit-fraud exposure only after payment disputes, law-enforcement notices, or brand complaints have already escalated.

How It Works in Practice

Accountability usually follows control ownership. The marketplace is accountable for the trust framework because it decides seller admission criteria, identity verification depth, listing moderation rules, and whether suspicious activity triggers friction or removal. Brand owners are accountable for reporting counterfeit activity, providing product signatures, and helping define authenticity signals. Payment providers are accountable for their fraud screening and chargeback controls, while enforcement teams handle investigation and legal action. The key point is that shared responsibility does not dilute platform responsibility for the controls it exclusively operates.

A practical control model starts with strong seller identity proofing, risk-based onboarding, and continuous monitoring of account behaviour after approval. It should also include automated listing review for known counterfeit markers, payment holds for anomalous sellers, and rapid escalation paths for verified complaints. This is where NHI discipline maps cleanly: short-lived credentials, least privilege, and revocation matter because marketplace abuse often uses machine-mediated workflows rather than a single human login. The 52 NHI Breaches Report illustrates how quickly weak identity controls can turn into systemic exposure, while Anthropic’s AI-orchestrated cyber espionage report shows how automated workflows can scale harmful activity when access is not tightly bounded.

  • Define who approves sellers, who reviews listings, and who can suspend or delist.
  • Use evidence-based authenticity checks for high-risk categories, not blanket manual review.
  • Require traceable decision logs so disputes can be reconstructed quickly.
  • Revoke or freeze suspicious accounts and credentials immediately when counterfeit indicators appear.

These controls tend to break down when marketplaces allow delegated seller tooling, third-party integrations, or automated bulk listing because identity and content signals become fragmented across systems.

Common Variations and Edge Cases

Tighter fraud controls often increase seller friction and operational overhead, requiring organisations to balance marketplace growth against abuse prevention. That tradeoff is real, especially for platforms with global sellers, high-volume catalogues, or fast-moving consumer goods where manual review does not scale well.

One common edge case is a marketplace that only provides the venue and payment flow while a third party handles fulfilment. In that model, accountability is still shared, but the platform remains responsible for the integrity of the marketplace controls it owns. Another edge case is escrow or protected-payment structures, where payment providers may detect fraud earlier than the marketplace but cannot replace platform onboarding or moderation. Guidance is evolving on how much automated detection is sufficient; there is no universal standard for this yet, so most mature programmes combine policy rules, human review, and escalation thresholds.

For broader identity and lifecycle context, Top 10 NHI Issues highlights why visibility, rotation, and offboarding failures keep recurring, and Ultimate Guide to NHIs — Key Challenges and Risks shows how weak governance compounds over time. In practice, the hardest cases are cross-border marketplaces with anonymous sellers and weak evidence-sharing, because takedown speed, legal process, and authenticity verification rarely align cleanly across jurisdictions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and CSA MAESTRO address the attack and risk surface, while NIST AI RMF, NIST CSF 2.0 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01Marketplace abuse often rides on weak identity and access controls.
CSA MAESTROT1Shared accountability depends on clear trust and governance boundaries.
NIST AI RMFFraud detection and listing moderation are AI-risk governance problems when automated.
NIST CSF 2.0PR.AA-01Accountability hinges on identity proofing and controlled access to platform functions.
NIST Zero Trust (SP 800-207)SC-3Marketplaces need continuous trust evaluation, not one-time admission checks.

Inventory seller and service identities, then tighten access boundaries for every platform workflow.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org