I Was Almost Headhunted for a US Board Seat (Spoiler: I Wasn’t)
Last week I got an email that made me sit up a little straighter in my chair. Someone claiming to be from Heidrick & Struggles — a genuinely well-known executive search firm — had “come across my profile” and thought my 20 years running Jascom made me a strong candidate for a confidential board appointment at a US company, with a focus on technology governance and cybersecurity.
For a brief, glorious moment, I let myself imagine it: flying business class to board meetings, saying things like “let’s circle back on that” with real authority, maybe getting my own parking space. Then the part of my brain that’s spent two decades in web security and domain names elbowed its way back in and said: mate, check the sender address.
Good thing it did.
The tell was hiding in plain sight
The email was well-written. No dodgy grammar, no “URGENT!!!” in the subject line, no obvious spelling mistakes — the usual giveaways were nowhere to be found. It even name-dropped my company and background accurately, which is easy to do since it’s all sitting on my LinkedIn and our own website. Spear phishing works precisely because it doesn’t look like the spam of old.
But the sender’s email address was @heidrickpartners.com. The real Heidrick & Struggles operates at heidrick.com. “Heidrickpartners.com” is what’s called a cousin domain — close enough to the real thing to slip past a quick glance, registered by someone with no connection to the actual firm.
This is a known scam pattern, sometimes called a board recruiting scam: a flattering opening message, no links or attachments to trip spam filters, designed purely to get you to reply. Once you engage, the ask usually escalates — send your bio, then it’s “not quite competitive enough,” then comes the pitch for a paid “board readiness” service. Heidrick & Struggles has even published its own warning about people impersonating them for exactly this reason.
The checklist I actually used
- Check the domain, not just the name. A display name is free to fake. The bit after the @ is what matters.
- Be suspicious of flattery with no ask — yet. Real recruiters don’t need to buttonhole you out of nowhere for a “confidential” chat with zero verifiable details.
- Verify independently. Don’t reply to the email or click anything in it. Go to the company’s real website yourself and contact them through official channels.
- Remember: legitimate recruiters are paid by the hiring company, not by you. Any request for money from “your side” is a hard stop.
The moral of the story
I didn’t get a board seat. I did get a good reminder of why we bang on about email security so much at Jascom — because even people who deal with this stuff for a living can feel that little flutter of “ooh, me?” before their common sense catches up.
If you run a business and want your team’s inboxes (and egos) a bit better protected against this kind of thing, that’s exactly what we help with. Get in touch — no board seat required.