Phishing schemes target cannabis operators across multiple states

Phishing schemes target cannabis operators across multiple states

Cannabis operators and industry professionals across multiple states are reporting a wave of phishing attempts designed to exploit familiar names, regulatory obligations, and routine business communications.

The schemes have appeared in several forms.

In Missouri and other state markets, industry professionals have been inundated with messages carrying subject lines such as “Dinner & drink invitation from,” followed by the name of a recognizable executive, operator, or other prominent industry figure. Similar invitation scams documented by the Federal Trade Commission attempt to direct recipients to fraudulent pages that collect login credentials, phone numbers, or verification codes.

In California, scammers have taken a regulatory approach, sending emails that appear to originate from the state’s Department of Cannabis Control.

According to the DCC, several California licensees reported receiving messages asking them to review or verify important information by clicking a “REVIEW DOCUMENT” button. The fraudulent emails may describe the request as an annual document review or verification and may include license details, personal information, or references to DocuSign.

“These emails were not sent by DCC,” the agency warned.

Although the messages differ in presentation, they rely on the same strategy: establishing trust through a familiar name, government agency, or recognizable platform before directing the recipient to a fraudulent website.

Familiar names make invitations appear legitimate

The invitation scheme circulating within the cannabis industry appears to take advantage of the close-knit nature of state markets. Recipients may recognize the purported sender from conferences, trade associations, regulatory discussions, LinkedIn, or previous business dealings.

That familiarity can make a dinner or drink invitation seem plausible, particularly when the message appears to come from a well-known industry figure. Clicking the invitation may direct the recipient to a page that requests an email address, password, phone number, or verification code.

The Federal Trade Commission issued a broader warning on May 26 about unexpected electronic invitations designed to steal account credentials. According to the agency, fraudulent invitations may appear to come from established platforms such as Evite or Paperless Post and sometimes identify someone known to the recipient as the host.

The FTC warned that legitimate invitations should not require recipients to provide their email passwords or share security codes to view event information. Once scammers gain access to an email account, they may use the compromised account and its contact list to distribute additional invitations, making subsequent messages appear even more credible.

Recipients should also understand that the displayed name and email address are not always reliable indicators of legitimacy. Email addresses can be spoofed, making a fraudulent message appear to come from the correct organizer, regulator, executive, or familiar industry contact.

In other cases, a legitimate account may have been compromised and used to distribute fraudulent invitations to people in the account holder’s contact list. That means a message can appear to come from the correct address and still be malicious.

If an invitation or request seems suspicious, recipients should verify it directly with the purported sender through a previously established phone number, email address, or messaging account before clicking a link, opening an attachment, or providing information. They should not reply to the questionable message or use contact information contained within it.

   

Scammers impersonate regulators and business platforms

The California campaign introduces additional pressure by presenting the message as an official licensing or compliance matter.

Licensees are accustomed to receiving time-sensitive notices concerning renewals, fees, inspections, documentation, and regulatory requirements. A message suggesting that a license could be affected by an incomplete review may prompt a recipient to act before carefully examining the request.

The DCC said legitimate information requests will come from an agency employee using an email address ending in @cannabis.ca.gov. Licensees who receive a questionable request for licensing information or payment should independently contact the department at info@cannabis.ca.gov or (844) 612-2322.

The agency advised recipients not to click links or buttons, provide personal, business, or license-related information, or reply to the sender.

Even when an email appears to use the correct domain, recipients should remain cautious if the request is unexpected, creates an unusual sense of urgency, or directs them to provide login credentials or payment information. Because sender information can be spoofed, independent verification remains the safest response.

References to DocuSign can add another layer of perceived legitimacy. However, DocuSign has documented phishing campaigns in which scammers use fake or misappropriated document notifications to direct recipients to credential-harvesting pages.

DocuSign’s Safety Center advises users to treat unexpected document requests cautiously, even when a notification appears authentic. Suspicious DocuSign messages can be forwarded as attachments to verify@docusign.com.

How cannabis businesses can respond

Cannabis companies should notify employees about the current campaigns, particularly staff members who manage licensing, compliance, accounting, human resources, executive scheduling, and industry partnerships.

Businesses can reduce their exposure by:

  • Verifying unexpected invitations directly with the named host.
  • Examining the full sender address while recognizing that addresses can be spoofed or legitimate accounts can be compromised. (Greenway has verified instances in which the originating email address was compromised rather than spoofed.)
  • Contacting regulators through phone numbers or email addresses published on official government websites. (Draft a new email rather than replying, or contact a different representative of that agency or company.)
  • Navigating to regulatory and business platforms independently instead of using links contained in an email.
  • Always refuse unsolicited requests for email passwords, multifactor authentication codes, or other login credentials.
  • Using unique passwords and multifactor authentication for email, regulatory, banking, payroll, and point-of-sale accounts.
  • Reporting suspected phishing messages to internal information technology or security personnel.
  • Changing compromised passwords immediately and reviewing active account sessions, recovery information, and email-forwarding rules.
  • Alerting employees and business contacts if a company account has been compromised.

Phishing emails can be forwarded to the Anti-Phishing Working Group at reportphishing@apwg.org. Attempts may also be reported through the FTC’s ReportFraud portal.

For cannabis businesses, a compromised account may expose more than a single employee’s inbox. Email systems can contain licensing records, employee information, invoices, banking communications, product data, and contact lists spanning an entire state market.

The recognizable names, official-looking email addresses, and regulatory details used in the current schemes make independent verification especially important. If a message seems unusual or suspicious, even when it appears to come from someone the recipient knows, the safest course is to contact that person or organization directly before taking any action.