Another recruiter found me this week. Confidential retained search, CISO role, loved my background. She forgot to mention the search firm or the client, and she wrote from a Gmail account while the From line claimed a business domain.
I get a lot of these, and I wrote about one on my blog last month. This time I turned it into an EOTISEC report, number 60, and we’re tracking the persona as HOLLOW MANDATE.
Most of the time this ends with a fake recruiter telling you your resume has a problem and pointing you to a “specialist” who fixes it for $400 to $800. That is annoying, and nobody reports it because nobody wants to admit they fell for flattery. But the same opening email has also been used to drop remote access tools on finance executives’ machines, and you can’t tell which version you got from the first message.
The part that got my attention is that email authentication was useless both ways. My September lure passed SPF, DKIM, and DMARC because it really was just Gmail. This one failed DMARC and landed in my inbox anyway. What caught both was checking the sender against the firm’s own published contact policy.
These go to personal inboxes where your corporate tools never see them. So ask yourself whether your executives would tell you if one showed up.