, , ,

The Recruiter Is Real. The Email Isn’t.

The recruiter was real. The company was real. Even the photograph was real. But the email wasn’t. A recent executive recruiting scam reveals how stolen professional identities and highly personalized outreach are making impersonation attacks harder to detect.

Cybersecurity illustration showing a hooded impersonator beside a fraudulent Gmail recruiting email using real recruiter Jamie Desautels’s name and photo, contrasted with her portrait and Aerotek identity.

Inside the New Executive Impersonation Scam

Summary

Executive recruiting scams are becoming more sophisticated by borrowing the identities of real professionals rather than inventing fake ones. After receiving an unsolicited Fractional CIO/Cyber Governance opportunity apparently from an Aerotek recruiter, Victor Font discovered that the sender was using a Gmail account while appropriating the real recruiter’s name, employer, professional details, and photograph.

The case illustrates an emerging verification problem: searching for the recruiter may actually reinforce the deception because the person being impersonated genuinely exists. Combined with highly personalized job descriptions that can potentially be produced using publicly available professional information and generative AI, these attacks challenge traditional phishing-awareness techniques.

The article examines the anatomy of synthetic executive recruiting, explains why personalization is no longer evidence of legitimacy, and argues that professionals must verify not merely the identity being presented but the communication channel through which that identity is operating.

The name was real.

The company was real.

The recruiter was real.

Even the photograph was real.

The job was the part I couldn’t verify.

That distinction may represent an important evolution in recruiting fraud.

For years, the standard advice for identifying employment scams has been relatively straightforward: research the recruiter, look up the company, inspect the email address, search for the person on LinkedIn, and determine whether the opportunity seems consistent with your professional background.

But what happens when the person you research actually exists?

What happens when the photograph matches?

What happens when the company is legitimate?

And what happens when the supposed opportunity has been written specifically around your career?

I recently received an email that illustrates exactly that problem.

The message claimed to come from Jamie Desautels at Aerotek regarding a “confidential retained search” for a Fractional CIO / Cyber Governance Lead in healthcare technology.

It was remarkably well targeted.

The message referenced my background in IT governance, FedRAMP readiness, board-level advisory work, cybersecurity governance, digital transformation, published authorship, and fractional technology leadership.

Those are not random technology keywords.

They closely reflect how I publicly describe my professional work.

The compensation was equally attention-grabbing:

$350,000–$500,000+ base salary, performance bonuses, equity, and executive-tier benefits.

For an executive receiving the message between meetings, the natural reaction might be:

This person did their homework.

And apparently, someone did.

Just not necessarily the recruiter whose identity appeared on the email.

The First Problem Was the Email Address

The message came from:

jamie.aerotek.desk1@gmail.com

That immediately raised a question.

Why would someone representing a major staffing and recruiting company conduct a confidential executive search from a Gmail account rather than a corporate email address?

That question becomes considerably more important when compared with Aerotek’s own fraud-prevention guidance.

Aerotek warns job seekers to verify that recruiter communications use the company’s legitimate @aerotek.com domain. The company has specifically warned about individuals impersonating Aerotek recruiters through Gmail and other unofficial channels.

In other words, the email failed one of the company’s own basic authenticity tests.

That alone was sufficient reason not to trust the message.

But then the case became more interesting.

The Recruiter Appears to Be Real

The name in the email was not necessarily fabricated.

There appears to be a real Jamie Desautels associated with Aerotek recruiting.

And the photograph used by the sender was the photograph of the real recruiter.

That changes the nature of the deception.

The attacker was not simply pretending to work for Aerotek.

The attacker appeared to be assuming the professional identity of an actual person.

Name.

Company.

Professional role.

Photograph.

Those details create something far more persuasive than the crude recruiting scams many people have learned to recognize.

A recipient who performs a quick search may actually make the scam appear more legitimate.

Search the recruiter’s name.

The person exists.

Search the company.

The company exists.

Look at the photograph.

It matches.

Search the person’s professional background.

It appears consistent with the signature.

The victim has now performed several verification steps—and paradoxically may feel safer because of them.

That is the security problem.

The Verification Paradox

Traditional anti-fraud advice frequently assumes that scammers invent identities.

Increasingly, they do not need to.

The internet already contains millions of professionally curated identities.

LinkedIn profiles provide names, photographs, employers, titles, employment histories, professional interests, certifications, connections, recommendations, publications, and recent activity.

Corporate websites provide leadership biographies.

Conference websites provide speaker profiles.

Podcasts provide interviews.

Professional associations provide directories.

Press releases document promotions and appointments.

The raw materials required to impersonate a credible professional are already public.

At the same time, the target’s professional identity may be equally accessible.

My own public presence makes it relatively easy to determine the subjects on which I work and write: cybersecurity governance, AI governance, enterprise technology leadership, board oversight, risk, architecture, and related areas.

An attacker does not need access to a confidential personnel file to construct a plausible approach.

The public internet can provide both sides of the conversation.

One identity supplies the recruiter.

Another supplies the candidate.

Generative AI can potentially supply the connective tissue.

The Job Description Was Almost Too Good

Consider how precisely the supposed position aligned with my professional positioning.

The email said the organization needed someone who could:

“Architect and oversee enterprise-wide cybersecurity governance frameworks.”

“Provide board-level counsel on risk, compliance, and digital transformation.”

“Drive FedRAMP readiness and IT oversight across a scaling healthcare enterprise.”

It then explicitly referenced my “published authorship on cybersecurity governance and fractional leadership experience.”

This wasn’t:

“We found your résumé and have an exciting opportunity.”

It was a miniature executive-search thesis.

The sender explained why I had supposedly been selected, connected specific aspects of my background with the requirements of the position, and presented the opportunity using terminology appropriate for an executive governance role.

That is precisely what makes this generation of social engineering potentially dangerous.

Bad personalization is easy to recognize.

Good personalization creates authority.

The Signature Contained Another Clue

There was another detail hiding in plain sight.

The signature identified Jamie Desautels with:

Construction ManagementTalent Acquisition | Aerotek

Yet the supposed engagement involved a Fractional CIO / Cyber Governance Lead for a healthcare technology organization.

At first glance, that seems like a mistake.

But if the sender copied elements from a real recruiter’s public identity, the inconsistency may tell us something about how the message was assembled.

Authentic identity information may have been combined with a fabricated opportunity designed specifically for the recipient.

That produces an unusual mixture of real and false information.

And that mixture is exactly what makes modern impersonation difficult to evaluate.

The question is no longer:

“Is this email fake?”

The better question is:

Which parts of this email are authentic, and which parts have been borrowed to make the fabrication believable?

This Wasn’t My First Recent Encounter

The message also caught my attention because it resembled another suspicious executive recruiting approach I had recently received.

That earlier communication purported to involve another legitimate organization and another unusually lucrative Fractional CIO / Cyber Governance opportunity.

I independently contacted the company.

The response was unequivocal.

It wasn’t them.

That experience changed how I evaluated the Aerotek message.

One suspicious executive opportunity can be coincidence.

When multiple approaches begin using similar positioning, similar executive compensation ranges, legitimate organizations, and professional identities, a larger pattern becomes worth considering.

I cannot establish from these messages alone that the incidents came from the same actor or campaign.

That would require evidence I do not have.

But the similarities demonstrate something important regardless of attribution:

The ingredients necessary to manufacture a convincing executive recruiting approach are now readily available.

The Anatomy of Synthetic Executive Recruiting

A sophisticated impersonation campaign could theoretically be constructed with six components.

1. Select the target.

Find an executive, consultant, board candidate, technology leader, physician, attorney, financial professional, or other high-value individual with a substantial public professional footprint.

2. Build the target profile.

Collect publicly available information about expertise, career interests, publications, industries, certifications, recent posts, speaking engagements, and professional positioning.

3. Select a credible recruiter.

Identify a real recruiter or executive-search professional whose identity can plausibly support the approach.

4. Clone the trust signals.

Use the person’s real name, photograph, company, title, signature information, and other publicly available professional details.

5. Generate the opportunity.

Construct a role that closely matches the target’s experience and aspirations.

6. Move the conversation toward the objective.

The eventual goal might be credential theft, identity theft, malware delivery, financial fraud, collection of sensitive information, or simply establishing enough trust for a later stage of the attack.

Not every suspicious recruiting message necessarily follows this process.

But every component is technically achievable today without extraordinary resources.

That is what should concern executives and security leaders.

AI Changes the Economics of Personalization

Artificial intelligence does not have to invent the scam.

Its more consequential role may be making personalization inexpensive.

Historically, a highly customized spear-phishing campaign required research.

Someone had to read the target’s biography, understand the person’s industry, study their career, and write a credible message.

That effort limited scale.

Generative AI changes the economics.

Public information about a target can potentially be transformed into a convincing recruiting narrative rapidly.

A model can identify professional themes.

It can infer terminology.

It can summarize publications.

It can construct job requirements that mirror a target’s experience.

It can adjust tone for a CIO, CFO, physician, attorney, researcher, or board director.

It can produce professional correspondence without obvious grammatical mistakes.

The attacker still needs a strategy.

But the cost of producing individualized persuasion has fallen dramatically.

That means we need to reconsider an assumption embedded in traditional phishing awareness:

Personalization is no longer evidence of legitimacy.

The fact that someone knows what you do does not necessarily mean they know you.

Executives May Be Particularly Attractive Targets

Senior professionals present an unusual combination of characteristics.

They have valuable identities.

They often possess broad organizational access.

Their professional histories are extensively documented.

They expect unsolicited approaches from recruiters.

They may routinely discuss confidential opportunities.

And large compensation packages are not inherently implausible.

That last point matters.

An email offering a junior employee a $500,000 salary may immediately trigger skepticism.

An executive recruiter approaching an experienced technology leader about a highly compensated CIO-level role does not necessarily create the same reaction.

The bait must fit the target.

The better the fit, the less it looks like bait.

Verification Must Move From Identity to Channel

This experience reinforces a principle that cybersecurity professionals have understood in other contexts for years:

Identity claims and communication channels must be verified separately.

Finding the recruiter on LinkedIn does not authenticate the email.

Matching the photograph does not authenticate the email.

Confirming that the recruiter works for the named company does not authenticate the email.

Finding mutual connections does not authenticate the email.

Even discovering that the recruiter’s actual specialty matches the conversation does not authenticate the email.

Those things establish that the person exists.

They do not establish that the person sent the message.

That distinction is fundamental.

If an unsolicited recruiter claims to represent a company, independently verify the communication channel.

Check the corporate domain.

Visit the company’s website independently rather than through links in the message.

Locate published fraud warnings.

Contact the recruiter through an independently verified channel when necessary.

Call the company’s published telephone number.

If you connect through LinkedIn, initiate the communication from the recruiter’s verified profile rather than following a link supplied in the email.

And do not send sensitive information until the relationship has been authenticated.

In security terminology, this is essentially an out-of-band verification problem.

The email is making an identity assertion.

Verify that assertion somewhere else.

The Photograph Proves Less Than We Think

There is something psychologically powerful about seeing a person’s photograph in an email.

Faces create familiarity.

A professional headshot accompanied by a recognizable corporate name makes an email feel less anonymous.

But photographs are among the easiest trust signals to appropriate.

If the image is publicly visible on LinkedIn, a company website, conference page, or other professional profile, possession of that photograph proves virtually nothing about the sender.

The same applies to logos.

Titles.

Biographies.

Company addresses.

Telephone numbers.

Email signatures.

Much of what makes business correspondence look authentic consists of public information.

We need to stop treating public information as authentication evidence.

The Next Generation of Social Engineering May Look Completely Normal

The most concerning thing about this email wasn’t that it looked suspicious.

It was that most of it looked reasonable.

There was no bizarre inheritance.

No obvious spelling disaster.

No desperate request for cryptocurrency.

No stranger claiming to have millions of dollars trapped overseas.

Instead, there was a recruiter.

A recognizable company.

A professional photograph.

A plausible executive role.

A flattering explanation for why I had been selected.

And a compensation package capable of getting someone’s attention.

That is where social engineering is heading.

The best attacks will not necessarily look extraordinary.

They will look routine.

They will resemble the normal communications professionals receive every day.

And increasingly, the people appearing in those communications may be completely real.

They simply won’t be the people sending them.

The Recruiter Is Real. The Email Isn’t.

That may become one of the simplest ways to understand this emerging threat.

We spent years teaching people to search for fake identities.

Now we also have to teach them to recognize stolen credibility.

The recruiter may be real.

The photograph may be real.

The employer may be real.

The candidate research may be accurate.

The terminology may be appropriate.

The opportunity may sound almost perfectly suited to you.

None of those facts authenticate the sender.

In an era of AI-assisted social engineering, verification cannot stop when we establish that a person exists.

It has to establish that the person we’re communicating with is actually that person.

Because the next phishing email may not arrive wearing an obviously fake identity.

It may arrive wearing a real person’s face.


Back to Articles

Not sure where your governance posture stands? Start Readiness Self-Assessment