The Executive Recruitment Scam That No Longer Looks Like a Scam

SHARE

Generative AI has stripped many of the grammatical errors from recruitment scams. For senior leaders, verifying a headhunter now requires analysing the commercial structure of the approach, not just its prose.
Executive Recruitment Scam

Generative AI has stripped many of the grammatical errors from executive recruitment scams. For senior leaders, verifying a headhunter now requires analysing the commercial structure of the approach, not just its prose.

The communications senior leaders are being taught to distrust increasingly resemble the communications they have been taught to trust. Over a recent two-week period, our practice reviewed two closely similar approaches directed at senior executives. In both cases, an individual presenting as an executive-search professional referred the executive to a specific career-services provider using unauthorised brand-adjacent contact details. In the more developed of the two approaches, the executive was also told that their documents required professional improvement before submission and was encouraged to act before the hiring process progressed. The correspondence matched several features of documented recruitment-fraud schemes.

If style no longer separates genuine from fraudulent outreach reliably, what does?

Good grammar is no longer a fraud test

For years, the standard advice for identifying a fraudulent recruitment email relied on stylistic tells. Candidates were told to look for poor grammar, generic salutations, crude urgency and obvious spelling mistakes.

That heuristic is no longer reliable on its own.

Research from Microsoft Threat Intelligence and peer-reviewed cybersecurity studies published in 2025 and 2026 demonstrates that generative AI allows attackers to produce highly polished, persuasive and contextually relevant phishing communications at scale. Microsoft has specifically noted that AI can eliminate grammar mistakes and awkward phrasing that previously made phishing attempts easier to recognise.

This does not mean grammar is entirely useless, but it is no longer a sufficient trust signal. Professional prose should no longer be treated as evidence of professional provenance.

The implication for senior leaders is clear. Verification must move from asking how a message sounds to analysing how the underlying arrangement is structured.

The current executive variant follows a recognisable sequence

The executive-tier mechanism has precedent.

In 2019, the US Federal Trade Commission documented an executive-focused job-placement and résumé-repair operation in which candidates were told they needed paid résumé services to be considered for high-level opportunities. The pattern we are seeing resembles that documented mechanism, but with an additional layer of borrowed third-party credibility.

Across both approaches reviewed by our practice, common elements included an individual presenting as an executive-search professional, a referral to a specific career-services provider and unauthorised brand-adjacent contact details.

In the more developed of the two matters, additional elements appeared: the executive was told their documents needed professional improvement before submission, urgency was introduced, progress towards the opportunity was implied after the service was completed, and the executive was asked to confirm once contact had been made.

The persuasion works because every individual step can sound reasonable in isolation.

A recruiter may genuinely suggest improving an executive CV.

A recruiter may genuinely work under time pressure.

A recruiter may genuinely know career-service providers.

The concern emerges from how those elements are connected.

A legitimate company’s name can be used to authenticate a message it never sent

A critical feature of the recent approaches we reviewed was the use of brand-adjacent contact details.

The recipient sees a familiar-looking name, searches for it, finds the real career-services firm, and unconsciously transfers that firm’s legitimacy to the supplied contact details.

This is a sophisticated exploitation of digital verification habits.

A search result can verify that a company exists while doing absolutely nothing to verify the sender.

Finding the legitimate company in search results verifies the company’s existence. It does not verify that the contact point supplied in the message belongs to that company.

The proper method requires bypassing the information supplied inside the suspicious message entirely. Verification should rely on the official website, official domain, published telephone numbers, professional-body directories and independently sourced contact details.

Never rely exclusively on contact information provided within the initial outreach.

Follow the money

One of the strongest structural indicators is the commercial direction of the engagement.

Who is paying whom, and what is being conditioned on that payment?

In a legitimate retained executive search, the hiring organisation engages and pays the search firm. The candidate does not purchase access to the mandate.

Within AESC member practice, the commercial relationship is explicit: the search firm is retained by the client, and candidates are not charged to enter or progress through the search.

The Association of Executive Search and Leadership Professionals (AESC) published a recruitment-fraud alert on 1 September 2026 that explicitly warns against impersonation of search firms, fake job opportunities and suspicious payment requests. AESC states that its member firms do not ask candidates to pay to be considered for a role, submitted to a client, coached for an opportunity or introduced to a hiring organisation.

It is necessary to draw a sharp distinction here.

An executive independently deciding to purchase CV writing, LinkedIn support, interview coaching or career advisory services is entirely legitimate.

The warning sign is not that money changes hands.

The warning sign is that candidacy is made contingent on payment to a specified provider.

When a recruiter states that an executive must buy a specific service from a specified provider before they can be submitted or progressed, the candidate should stop and independently verify the arrangement before paying or sharing further information.

The limits of superficial signals

It is important to acknowledge the nuances of the executive recruitment market.

Some genuine recruiters recommend career-services providers.

Some legitimate recruiters use personal email addresses or operate without large corporate infrastructure.

Some authentic search professionals will advise a candidate to improve their CV before presentation.

Buying professional career support is not inherently suspicious.

Therefore, no single superficial signal proves fraud. The concern becomes materially stronger when the structure combines a specified purchase with purported recruitment progress.

We must also recognise the limits of external observation. We cannot determine from correspondence alone whether a particular approach represents deliberate fraud, aggressive lead generation, impersonation or some other conduct.

We are teaching verification, not assigning guilt.

What to verify, and in what order

When an approach requires scrutiny, executives should follow a strict verification sequence.

1. Verify the search professional

Check whether they appear on the official company website, an AESC or relevant member-firm directory, a credible professional profile, and whether their corporate contact details can be independently sourced.

2. Verify the search firm

Do not use links supplied in the message. Find the official website independently.

3. Verify the contact channel

Ensure the email domain actually belongs to the firm. Do not assume a mailbox containing a company’s name belongs to that company.

4. Verify the mandate

Ask directly whether they are formally retained, who the client is if disclosure is permitted, whether the assignment is exclusive, what stage the search is at, and what the executive recruitment process entails.

Confidential searches may not allow immediate client disclosure, but the process should be clear.

5. Verify the hiring organisation where appropriate

Use independently sourced information.

6. Ask directly about payment

Ask explicitly whether you are required to purchase any service, assessment, coaching or CV work to be considered, submitted or introduced.

If the answer is yes, stop and verify before paying.

7. Protect personal information

Do not send banking information, identity documents, passport copies, tax details or unnecessary personal data until the recipient and process have been independently verified.

The South African legislative context

For South African readers, the Employment Services Act 4 of 2014 provides an additional safeguard.

Section 15 restricts fees charged to work seekers for employment services and prohibits private employment agencies from requiring workers to pay in respect of placement, subject to specified statutory exceptions. The Department of Employment and Labour has separately warned work seekers not to pay fees for recruitment or related employment services.

The precise application of these provisions to different forms of independent career advisory is a separate legal question and should not be conflated with the recruitment arrangement described here.

Employer-side exposure and governance

Executives are also employers and board members, which introduces a secondary layer of risk.

Consider what happens if your own organisation’s name is the one being used.

Fraudsters can borrow employer brands, executive names, recruiter identities, logos, job titles and publicly known vacancies to authenticate fraudulent approaches.

This elevates the issue beyond individual candidate safety to corporate governance and reputation management.

A mature employer-brand protection process should include clear official recruitment domains, explicit recruitment-contact guidance, an impersonation-reporting process and a defined protocol for responding when spoofing is reported.

Boards and executive committees should be asking several foundational questions:

  • Could a candidate independently verify our recruiters?
  • Do candidates know which domains we use?
  • Who owns an employer-brand impersonation incident within the executive team?
  • How quickly can a fake recruiter or domain be reported and escalated?

This is not an IT-security manual. It is a question of protecting the integrity of the employer brand and the trust of the senior talent market.

Conclusion

The modern executive recruitment scam does not rely on poor spelling or clumsy urgency. It relies on the assumption that senior leaders will trust a well-written message and fail to interrogate its commercial structure.

Before engaging with any unsolicited recruitment approach, executives and the organisations they represent should ask:

  • Who is actually paying the recruiter?
  • Is any payment being made a condition of my progression?
  • Did I verify the recruiter through information I found independently?
  • Does the contact channel genuinely belong to the organisation it resembles?
  • If somebody used my organisation’s brand this way tomorrow, would we know how to respond?

The question is no longer whether the message looks professional. It is whether the structure behind it survives verification.

Sources and Further Reading

 

Share