More than 100 companies, including OpenAI, Anthropic, Google, Microsoft, Amazon Web Services, and Cisco, signed an open letter this week warning that AI cyberattacks are poised to scale dramatically.
The letter, organized by OpenAI, also drew support from banks, insurers, and security companies including CrowdStrike, Palo Alto Networks, and Mastercard. It warns of a “limited window” for organizations to strengthen their defenses before hospitals, water systems, and other critical infrastructure face a growing wave of AI-assisted attacks.
This warning should hit very close to home for cannabis businesses bracing for, as the industry already has experienced several security breaches firsthand.
Cannabis has seen the warning signs
In November 2024, STIIIZY disclosed a breach that exposed the personal data of roughly 380,000 customers, including names, addresses, dates of birth, driver’s license numbers, passport numbers, and medical cannabis card details. The breach was traced to a compromised point-of-sale (POS) processing vendor.
Years earlier, an unsecured cloud-storage bucket connected to POS provider THSuite exposed scanned government IDs, medical identification numbers, and purchase histories associated with more than 30,000 people across dozens of dispensaries. Cannabis software provider MJ Freeway also suffered repeated cyber incidents that disrupted operations for businesses relying on the platform for point-of-sale and state-mandated seed-to-sale tracking.
It’s important to note these incidents occurred prior to generative AI becoming widely available to attackers. Today, the risks have increased.
AI cyberattacks have lowered the barrier
The open letter’s central argument is that artificial intelligence is rapidly lowering the technical barrier to launching sophisticated attacks. Attackers no longer need a team of specialists to identify a misconfigured server, probe for vulnerabilities, or develop malicious code. AI systems increasingly can assist with reconnaissance, identify exploitable weaknesses, and generate or modify attack code at a speed that previously required considerably more expertise and time, putting AI cyberattacks within reach of bad actors who are far less sophisticated.
That should concern dispensaries, cultivators, and all other cannabis businesses — especially those businesses operating with limited IT resources.
Why cannabis businesses are especially exposed
Cannabis retailers possess an unusually valuable collection of customer information, including government-issued identification, medical information in some markets, payment-related data, and detailed purchase histories. Much of the information is collected as part of state compliance requirements and stored within interconnected POS, compliance, and seed-to-sale systems.
At the same time, cannabis businesses historically have faced restricted access to traditional banking and other financial services because marijuana remains federally illegal. Many operators also have digitized rapidly to satisfy increasingly complex regulatory requirements while cybersecurity investment has struggled to keep pace. Add AI cyberattacks to that environment, and the STIIIZY and THSuite incidents begin to look less like isolated events and more like warnings of what could come next.
Federal agencies are seeing attacks accelerate
Federal agencies already are seeing signs of the shift toward AI cyberattacks. A joint advisory from the National Security Agency, Cybersecurity and Infrastructure Security Agency, and FBI issued Aug. 19 described threat actors using AI-generated exploitation scripts disguised as monitoring tools to target industrial control systems. Water utilities and manufacturers were among the sectors identified.
CrowdStrike’s latest threat-hunting report found attackers weaponized 88 percent of newly disclosed proof-of-concept exploits within 48 hours during the first half of 2026. That pace leaves organizations with diminishing time periods to identify vulnerabilities and deploy patches before attackers begin exploiting them.
The warning comes with conflicts
Not everyone is convinced the open letter’s timeline or framing should be accepted at face value. Critics have noted the letter contains no deadlines, funding commitments, or measurable targets. Many of its signatories also develop or sell AI and cybersecurity products. John Gallagher, vice president at operational-technology security company Viakoo, compared a frontier AI developer warning of imminent cyber threats while selling defensive technology to “an arsonist selling fire extinguishers.”
Whatever the motivations behind the letter, however, the underlying vulnerabilities it identifies are familiar: weak authentication, unpatched systems, excessive access permissions, and poorly secured third-party systems. Cannabis businesses already have experienced the consequences of many of them.
What operators should do now
For operators, the practical takeaway does not require an elaborate AI strategy. It begins with basic cybersecurity discipline: vetting the security practices of POS and compliance vendors before signing contracts, enforcing multifactor authentication, restricting access to customer identification and medical data, keeping systems patched, and developing an incident-response plan before a breach forces one.
The cannabis industry already has demonstrated what can happen when a data-rich, under-resourced sector becomes a target. The warning now is that AI may allow the next attack to happen faster, at greater scale, and with considerably less effort.









