How Directors Have Become the new Target of Sophisticated Identity Fraud and Blackmail
The message arrived via LinkedIn, neatly written, personal, with exactly the right tone. No spelling mistakes, no exaggerated superlatives, no classic red flags. A reputable company was seeking an experienced director for a strategic and particularly relevant and attractive board mandate. The ‘recruiter’ knew the background of the potential Board candidate contacted well: previous roles, sector experience, even elements from the public professional profile had been carefully incorporated. And aligned almost perfectly with the sought Board mandate, which had been clearly set out. It was precisely tailored enough for the information to be credible. And precisely the right kind of approach to neutralise suspicion.
The company seeking the new Board member existed. The name was correct, the ‘recruiter’ name really appeared on the Search firms website. But the mandate did not exist. Nor did the recruiter. It was a fraud attempt - it was too good to be true.
This is not an isolated incident. It is a pattern that is growing faster than many directors realise.
A Fraud That Does not Hide, but Rather Excels in Credibility
Classic fraud still often gives itself away through carelessness: poor language, implausible amounts, an exaggerated sense of urgency. The fraud that is now targeting directors, and experienced executives, does exactly the opposite. It builds trust, sometimes over weeks or months. It uses the name of existing, respected organisations and people. It speaks the language of the sector and of executives. And thanks mostly to generative AI with a little human fraudster effort thrown in, it is often flawless – and scalable for the fraudsters
The figures underscore that this evolution is not merely an impression, but a reality. LinkedIn periodically reports that tens of millions of fake accounts are blocked and removed, largely before users ever see them. In Belgium, the Centre for Cybersecurity reported that Safeonweb received nearly 10 million suspicious messages in 2025. Cybercriminals are increasingly using AI to personalise phishing messages and make them more convincing, including deepfake audio and video that imitate the voice or image of senior professionals. The case that drew the attention of the federal prosecutor’s office and the CCB in late 2025 and early 2026 made this even more tangible: the identities of prominent public figures were misused to fraudulently extract sums of money from dignitaries, Belgian families and business leaders via telephone, email and WhatsApp. The victims were not chosen at random. They were selected on the basis of their profile, network and ‘potential value’. It is the same underlying mechanism that also applies when ‘fake recruiters’ target directors: not everyone is approached, only those who are sufficiently credible and potentially valuable.
Why Directors in Particular are Also Being Targeted?
Executive and non-executive directors possess everything that is of interest to a fraudster: network, authority, money and information. Their knowledge and contacts are valuable. Their signature, their credibility and their access to confidential information are equally so. And precisely because they are accustomed to being approached for new mandates or strategic roles, the psychological threshold for taking such a message seriously is often somewhat lower than with an ordinary phishing email.
In that context, specialists refer to whaling: spearphishing aimed at the big fish, high-ranking or influential targets, such as executive and non-executive directors. The technology being used has become more accessible and more convincing in a short period of time. For voice cloning, a short audio recording may already suffice today. Deepfake videos are no longer a futuristic doom scenario, but a real instrument in criminal campaigns. What used to be amateurish has now become a sophisticated and scalable business model. In many cases, we see the same pattern: first building trust, and then asking for sensitive information.
The Story Behind the Figures
Anyone who thinks this is only recognisable when money is requested quickly underestimates how sophisticated such approaches have become. In a concrete anonymous testimony from a well-known director who was recently contacted via LinkedIn, everything started with a profile that aligned strikingly well with his experience. Reference was made to sector expertise, international context and experience in governance in a way that seemed almost tailor-made. The fact that elements were also included that did not entirely correspond with his actual background initially still seemed explainable: the mandate sought would, after all, require a combination of experiences. What followed was not one crude mistake but a series of small plausible steps through which information was gathered and trust was created. The objective: a file full of data directly usable for identity fraud, or worse, for blackmail.
The first real hesitation did not arise because of one major inconsistency, but because of a series of smaller signals. The remuneration presented was exceptionally high by Belgian standards (but given that it concerned a NED mandate for a large international organisation and the fake recruiter was from the US not impossible). The identity of the underlying organisation remained shielded. Before further information would be shared, a non-disclosure agreement first had to be signed. Thereafter, a second phase would follow in which the candidate had to explain his added value in detail, clarify recent experiences and substantiate his suitability on the merits. All of this was presented as normal within a discretion-sensitive search process. The communication remained extremely proper and professional. That is precisely where the danger lies. Not in one flagrant request, but in an accumulation of seemingly reasonable steps. An introductory meeting. A request for a biography or CV. Questions about current mandates, specific responsibilities and strategic files. The suggestion that an external communication/governance professional could be engaged to document the candidacy professionally and provide further support. Even the request that the candidate personally finance that support was embedded in a narrative of independence and due care.
For those familiar with executive search, much of this (though not all) does not sound absurd per se. That is precisely why this form of fraud works. It does not prey on naivety, but on professional habits. It uses the codes of discretion, reputation and selection to obtain information that should never fall into the wrong hands.
In the case/estimony to which I refer, (where no client name had yet been mentioned in the initial contacts) the approached director ultimately became alert because of a combination of elements and the discussion with and investigation by a local search professional: a slightly too generous remuneration, a strange asymmetry in the way the expertise was presented, the insistence on working with a professional executive writer who would optimise the bio (read sought-after data) for the client, a small anomaly in the documents themselves, and ultimately an inconspicuous error in the email address (one letter different in the name). In the meantime, the investigation by the consulted search professional also showed that the office in the US existed and that there was also someone bearing the recruiter’s name, as well as the proposed executive ghostwriter, but that these could not be linked to one another. When, on the advice of the professional, the candidate director asked a number of critical questions before sharing further information, the communication stopped immediately. There was no clarification, no correction, no follow-up. The contact disappeared as abruptly as it had begun. The recruiter did not really exist, the office name had been “borrowed”.
This is more than an uncomfortable reality. It shows how small the difference can sometimes be between healthy professional curiosity and a process in which one gradually discloses confidential information step by step. Even before money is involved, the damage can already be considerable. Information about career, identity, network, board context or internal sensitivities is in itself already usable for identity fraud, targeted manipulation, blackmail or a subsequent attack on the organisations in which the Director holds mandates.
Too many directors remain insufficiently aware of this, and too few directors make it discussable because of inhibiting shame. Too many boards continue to treat this as an IT issue, something for the CISO or the cybersecurity lead. That is a misconception. What is at stake here is not only the technical protection of systems, but the personal, professional and financial exposure of directors themselves and, by extension, the reputation and operational security of the organisations with which they and their executives are involved.
Think the scenario through. A director, in the belief that he is in a legitimate selection process, shares sensitive personal data and professionally relevant information with a fraudster posing as a credible intermediary. That information can be used for identity fraud in the name of that director, for subsequent social manipulation, or as a stepping stone towards an even more credible attack on colleagues, employees or financial processes. The damage therefore does not stop with the individual. It seeps through to the board, the organisation and the stakeholders who place their trust in that board.
Yet this vulnerability rarely appears structurally on the agenda. There is attention for operational cyber risks, for GDPR, for broad compliance obligations. But the very specific vulnerability of the director as a personal target of social manipulation often receives insufficient attention in the governance conversation. It is a blind spot that is becoming increasingly difficult to justify.
Credible, Discreet, Professional and Fraudulent. What can Help?
A few Principles That Every Director, Every Board Should Make Their own
- Always verify through an independent channel. Anyone claiming to act on behalf of a reputable company or search firm must also be externally verifiable. Call the official number on the website, confirm that the contact person is known there and speak with them -never rely exclusively on contact details or links provided by the sender themselves.
- Do not regard “this feels credible” as a control mechanism. Precisely because this fraud is now built in a flawless, personalised, sophisticated and patient manner, an approach that feels professional or trustworthy is in itself no guarantee whatsoever. Distrust the feeling of credibility.
- Do not share sensitive personal data at an early stage. A copy of an identity document, detailed personal data, or sensitive information about ongoing mandates and internal files have no place in an initial contact phase, even when the request is courteous, professional and perfectly phrased.
- Treat this as a board issue, not merely as an IT risk. This belongs on the agenda of the Board. Boards must explicitly determine how directors and senior executives are prepared for this type of social manipulation, how incidents are prevented and reported, and which reflexes are expected in the event of doubt.
- Make reporting a reflex. Suspicious cases should not be concealed out of shame. Report them to the relevant platforms, competent authorities and internally within the organisation. Only in this way can a realistic picture emerge of the nature and scale of the risk and can it be effectively contained.
In Conclusion
The next time an interesting mandate or vacancy appears in your inbox, written exactly to measure, with the right tone and the right name underneath, the right reflex may not be enthusiasm but caution. Take that extra minute. Call. Verify. Doubt.
Because the most insidious aspect of this fraud is not that it is amateurishly disguised. It is that it feels exactly as a genuine opportunity would feel. And that is what makes it so effective with people who have the most to lose, and for fraudsters, the most to offer.
About the Author
Hilde Vanderschelden is a Mercuri Urval Board and CEO Practice Expert, an independent non-executive director, chair of the remuneration and nomination committee of Gezinszorg Villers VZW, and a jury member of the Board of the Year Award for non-listed companies organised by De Bestuurder. In addition, she is a Group Director at Mercuri Urval, where, as a Belgian expert, she forms part of the Global CEO & Board Practice and the ESG Practice.
Mercuri Urval is an international Executive Search and Leadership Advisory firm, founded in Sweden and active on the Belgian market for fifty years. With her combination of board practice, governance expertise and experience in executive search, she advises leaders, directors and organisations on questions relating to appointment, succession, leadership and board effectiveness. This article was written following her support to an experienced and highly regarded director in assessing a sophisticated spearphishing approach presenting itself as a credible board mandate process.
To find our mote about this topic, visit the AESC Recruitment Fraud Alert: What Clients and Candidates Should Know page here: https://www.aesc.org/recruitment-fraud-alert/