Security Alert: What initially appeared to be an isolated phishing attack involving WeedWeek appears to reflect a broader pattern of fraudulent bid and proposal solicitations targeting businesses. Since mg issued its initial alert, industry contacts have reported receiving similar messages involving bid proposals and requests for proposals.
WeedWeek founder and editor Alex Halperin confirmed in a LinkedIn post that his WeedWeek email account was hacked and used to send a fraudulent “Bid Proposal Invitation.” The message directs recipients to weedweek.framer.website/proposal, a phishing site posing as a secure document portal before presenting what appears to be a Google account login page designed to capture users’ credentials.

Screenshots from the phishing email sent from a compromised WeedWeek account on Sep. 8, 2026.
mg also has received a separate example of a “Bid Proposal Invitation” appearing to originate from a Grenco Science email address earlier this month. While there is not enough information to determine whether the messages are connected to the same attacker, the similarities reinforce the need for businesses to treat unexpected proposal and RFP requests with caution.
The tactic itself is not new. The Better Business Bureau previously warned businesses about fraudulent RFP solicitations that impersonate legitimate companies and direct recipients to malicious documents or websites. A BBB warning described emails asking businesses to download an RFP and submit a bid, sometimes using real company names, employee information, and professional-looking materials to make the request appear legitimate.
More recent cybersecurity research shows how much more sophisticated this type of attack has become. In July, security researcher David Weekly documented another phishing campaign using the subject line “Bid Proposal Invitation” that originated from a compromised email account, directed recipients through a Framer-hosted proposal page, and ultimately attempted to compromise a Google account.
Phishing and social-engineering attacks are becoming increasingly difficult to recognize as attackers combine compromised accounts, authentic company branding, legitimate cloud services, and increasingly capable AI tools to create convincing communications. Businesses and employees should verify unexpected requests involving proposals, documents, payments, or account access directly with the purported sender before interacting with them.
Read more about the growing threat of AI-powered cyberattacks to cannabis businesses.
DO NOT CLICK UNEXPECTED BID OR PROPOSAL LINKS. Verify the request independently with the person or company that appears to have sent it. Do not rely solely on contact information contained in the suspicious email.
The screenshots shown here contain fraudulent content and a potentially malicious URL. Do not visit or interact with any links shown in the images. If you already entered account credentials after following one of these links, change your password immediately, enable multifactor authentication if available, and notify your IT or security contact.






