I got an email this morning from a man I’ll call M, who introduced himself as a Senior Executive Recruiter with a major international staffing firm. He had the credential letters after his name, the warm tone, and a “confidential search” for a CISO role he thought I’d be right for. Would I like the full briefing?
No. And here’s why.
If you hold a security title at any level, you get these. They arrive in your inbox and your LinkedIn messages, and most of them are legitimate. Recruiters run searches. They find names. They reach out. That’s the business. The question is always whether the person writing to you is who they say they are, working for who they say they work for, recruiting for a role that exists. This one failed on all three counts.
The address told the first story. M sent the email from a personal Gmail account with a number suffix on the username, the kind of address you get when your preferred handle is already taken and you add digits to get through account creation. The staffing firm he claimed to represent publishes an explicit fraud awareness page on their corporate website. That page states, in plain language, that the firm communicates exclusively via official company domains and that public email services such as Gmail or Yahoo are not used for recruitment. They go further and use a Gmail address as their specific example of what a fraudulent contact looks like. M’s email matched the pattern their own security team warns people about.
The email headers confirmed the message genuinely originated from that Gmail account. DKIM passed. SPF passed. DMARC passed. All that proves is that a real Gmail account sent a real email. It proves nothing about the sender’s identity or affiliation.

The person didn’t exist where they should. A Senior Executive Recruiter conducting confidential CISO searches at one of the world’s largest staffing firms would leave a professional footprint. LinkedIn profile. Conference panels. Published thought leadership. Colleagues who reference them. I searched the sender’s full name in combination with the firm, with recruiting, with the credential he claimed, and with LinkedIn. Nothing. No professional presence at all. The only person by that exact name with any web presence is a music enthusiast on Bandcamp and SoundCloud in Serbia. That is not the professional identity of someone running C-suite security searches in the United States.
The structure was a script. The email opened with flattery calibrated to make you feel seen. It escalated to exclusivity with a “confidential search” that discourages you from verifying the opportunity through normal channels. It closed with a permission request designed to get you to reply: “Would you prefer that I send the full briefing first?” That question is not a courtesy. It is a foot-in-the-door technique. Once you reply, you are in a conversation. The next message will ask for something more. Maybe a phone call. Maybe a resume. Maybe information about your current employer’s security posture framed as context for the role.
The staffing firm’s fraud awareness page describes this progression as a known pattern and warns candidates to expect it.
What I did with it. I forwarded the original email as an attachment to the staffing firm’s compliance team at the address published on their fraud awareness page. They can pursue takedown actions against the sending account and flag the pattern for other potential targets. I did not reply to the sender. I did not engage.
What this means for you. If you hold a security title, a cleared position, or access to defense-related systems, you are a target for this kind of social engineering. The pitch will be tailored to your specific background because your background is available to anyone who can scrape LinkedIn or a resume aggregator. The flattery will be specific enough to feel personal because the data feeding it is specific. The firm name they use will be real because impersonating a known brand is the fastest way to borrow trust.
Check the sender’s email domain against the company’s published communication policy. Search the sender’s name independently. Verify your own career details in the message against what actually happened. If the email gets your own titles wrong, the person writing it did not do the work that a real search requires, and the question becomes what they are actually after.
The staffing firm in this case publishes clear guidance. Official communications come only from their corporate domains. They do not charge fees. Their executives do not cold-contact candidates via personal email. Every one of those guardrails was tripped by a single message.