Phishing Alert for New Mexico Cannabis Businesses: Watch Out During the NMS2S Transition

New Mexico cannabis businesses are currently managing a significant regulatory technology change. The state is transitioning licensed operators from BioTrack to the New Mexico Seed-to-Sale System, or NMS2S, and the timing creates an unusually favorable environment for phishing and business-email-compromise attacks.

Groth Industries is sharing this alert for local growers, suppliers, partners, license holders, and other industry peers because a trusted sender is no longer proof that an email is safe. The message may come from a genuine business contact, use a familiar name, and pass ordinary visual checks while still carrying a malicious file or credential-stealing link.

This advisory is not suggesting that the New Mexico Regulation & Licensing Department, or RLD, was breached or has any connection to the scam. RLD has separately warned that unauthorized individuals are impersonating department employees. The central risk is that attackers are exploiting a period when cannabis businesses reasonably expect official transition-related communications.

Why the NMS2S transition creates phishing risk

NMS2S is the state’s new seed-to-sale tracking system for New Mexico cannabis licensees. The system is free, and its use is mandatory for every licensed cannabis business. According to the official RLD NMS2S transition hub, BioTrack functionality was scheduled to be turned off for non-retailer licensees after 5:00 p.m. on August 25, 2026. Retailers are scheduled to move fully away from BioTrack at 12:01 a.m. on September 4, 2026.

The transition involves inventory migration, account access, system training, facility information, testing, transfers, and other operational requirements. RLD has stated that official communications will be sent to the business email address listed in NM-PLUS and posted on the official transition webpage. This creates a predictable situation. License holders are monitoring their inboxes for instructions, deadlines, access notices, and technical guidance.

Attackers understand that expectation. A fraudulent email can be made more convincing by referring to BioTrack, NMS2S, license verification, account activation, compliance deadlines, or system updates. A message may create urgency by claiming that access will be suspended, inventory will be affected, or a license will be placed at risk unless the recipient acts immediately.

The system is free and mandatory. Therefore, an email requesting payment for NMS2S access, asking a business to “verify your license” through a link, or requiring a login to avoid losing access should be treated as fraudulent.

Minimalist illustration showing one trusted email leading to a software download trap and a fake sign-in page

How the scam works

The phishing campaign described in the NICK advisory for New Mexico cannabis businesses uses a business relationship as part of the attack.

First, an actual supplier’s or partner’s email account is compromised. The account is not merely imitated with a similar-looking address. The attacker gains access to the real mailbox, which means the fraudulent message may come from a genuine, authenticated account that the recipient recognizes and has previously trusted.

One message can then contain two separate traps:

  1. A fake software update. A file or link may claim to provide an update, compatibility tool, document viewer, or system component required for the NMS2S transition. Opening or approving the installation can place hidden remote-management software, commonly called RMM software, on a Windows computer. This may give an attacker continuing access to the machine.

  2. A fake sign-in page. The same message may direct the recipient to a page designed to resemble Google or another familiar login service. If the user enters an email password, the attacker may capture the credentials and use them to access mail, reset other accounts, impersonate the business, or target additional contacts.

Neither trap necessarily looks suspicious. The sender may be a real supplier. The writing may be professional. The address may be familiar. The branding may appear authentic. In this situation, “does it look real?” is not a sufficient security test.

A compromised account also allows the attack to spread through existing relationships. Suppliers, laboratories, distributors, regulators, technology providers, and retailers often communicate with overlapping networks of businesses. Once one mailbox is taken over, the attacker can use its contacts and sending history to approach the next organization.

Three protection rules

1. Stop and verify any seed-to-sale request

If an email about BioTrack, NMS2S, licensing, compliance, inventory, or system access asks you to click, log in, download, or provide information, stop before taking action.

Contact the agency or vendor through a known, independently verified channel. For RLD-related questions, use the official RLD staff directory. Do not use a phone number, email address, or hyperlink supplied in the suspicious message. Type the official website address into your browser or use contact information already maintained in your business records.

Official instructions should also be compared with the NMS2S transition hub and its published bulletins, manuals, and resources.

2. Never install software to open a document

If a document asks you to install software before you can read it, treat the request as an attack. This applies even when the document appears to come from a state agency, supplier, laboratory, distributor, bank, or other familiar organization.

Legitimate regulatory documents do not require a recipient to install remote-control software from an email attachment or an unfamiliar link. Do not approve Windows prompts simply because a message describes the installation as necessary for compliance or system compatibility.

3. Remember that a trusted sender can be compromised

A real email from a real person with whom you conduct business can still be malicious when that person’s account has been hijacked. Familiarity is not verification. A known name is not verification. A previous email conversation is not verification.

When a message is unexpected or requests an unusual action, contact the sender by telephone using a number already stored in your records. Do not reply to the suspicious message until the account’s security has been independently confirmed.

Compliance manager reviewing an unexpected email on a laptop in a cannabis dispensary back office

Practical precautions for cannabis operators

Businesses can reduce risk by establishing a simple review process before the transition becomes more active. Designate one or two people to monitor official regulatory communications. Maintain a printed or offline list of verified contacts for RLD, key suppliers, laboratories, distributors, point-of-sale providers, and technology support. Require employees to escalate unexpected NMS2S or BioTrack requests to an owner, manager, or compliance lead.

Staff members who manage inventory, licensing, purchasing, sales systems, or customer information should understand that urgency is not proof of legitimacy. A request that combines a deadline with a download, login, payment, or password request deserves independent verification.

The official NMS2S system is free. Any message asking for a fee, gift card, cryptocurrency payment, personal-account transfer, or other unusual payment method is fraudulent. Any message asking for a password or two-step verification code is also fraudulent. Any message threatening loss of license access unless the recipient uses an embedded link should be treated as suspicious until confirmed through an official channel.

What to do if you think your business has been affected

If a team member opened the file, installed software, entered credentials, or approved an unexpected Windows prompt, respond promptly and methodically:

  1. Disconnect the suspected machine from the network. Unplug the network cable or disable Wi-Fi. Do not power the machine off, because shutting it down may destroy or alter evidence that could help determine what occurred.

  2. Change passwords from a different device. Use a separate phone or computer that has not been exposed. Begin with email accounts and then address financial, administrative, cloud-storage, point-of-sale, and other sensitive systems.

  3. Sign out of all active sessions. Changing a password alone may not remove an attacker who is already logged in. Use each provider’s option to revoke or sign out of sessions across all devices.

  4. Enable two-step verification. Activate it on email, cloud services, financial systems, business management platforms, and other accounts that support it. Store recovery codes securely and do not provide authentication codes to anyone by email or telephone.

  5. Assume the affected computer may need to be rebuilt. A machine that has provided an attacker with system-level access should not automatically be considered safe after a basic scan or software removal. Consult a qualified information-technology professional about preserving evidence, wiping the system, reinstalling it, and restoring only from trusted backups.

  6. Consult a lawyer about reporting obligations. If customer information, employee information, payment data, regulated sales records, or other sensitive business information may have been exposed, legal notification or reporting requirements may apply. Groth Industries is not a law firm, so businesses should obtain advice specific to their situation.

Incident-response illustration with an isolated laptop, two-step verification shield, password reset symbols, and secure evidence storage

Verify before you act

The NMS2S transition is a legitimate, mandatory change, and licensees should continue using the official RLD resources to prepare. The security issue is not the existence of the transition. The issue is that attackers can use a real transition, real deadlines, and real business relationships to make fraudulent instructions appear routine.

Groth Industries is sharing this information as part of a community-first approach to operating in New Mexico. Local cannabis businesses depend on connected relationships among growers, manufacturers, retailers, laboratories, suppliers, and service providers. Protecting those relationships requires a practical adjustment in behavior: trust the person, but verify the request through a separate channel.

Before clicking, logging in, downloading, or paying in response to an NMS2S-related email, will you verify it through an official source?

You must Be 21+ to View Our Site

Are you 21+ years Old?