2026-09-16 · Security · 9 min read
The Recruiter Who Claimed to Maintain My Open Source Project
Five recruitment emails, five Gmail accounts, and a recruiter claiming to maintain my own project. A closer look revealed a corporate-looking sender address that was only a display name.
A recruiter offering me a Staff Backend Engineer role at Stripe included this sentence in the email:
I build and maintain open-source and web projects, including Mouzi, a privacy-first cross-platform desktop application built with Rust, Tauri, React and TypeScript.
Mouzi is my project. Reading a stranger introduce it as their own was an odd way to receive a job pitch.
That email was one of five suspicious recruitment messages I received between September 13 and 15, 2026. They came from five different Gmail accounts. The senders used familiar company names, mentioned technologies from my public work and asked to discuss opportunities.
The Mouzi sentence was the obvious mistake. A less obvious detail was in the sender field: a corporate-looking email address had been entered as the display name. The actual address was a Gmail account.
This account reflects the messages and replies available on September 16. The names and affiliations below are claims made in those emails. I have not verified who controlled the accounts.
I replied to Anna to see where the conversation would go
The first message arrived on September 13 from someone calling herself Anna Tice and claiming to be part of Robert Half's recruitment team. It mentioned TypeScript, React, Node.js, Rust and Tauri.
Those were relevant technologies. The role itself was much less specific. There was no identifiable client, job reference or link to an opening.
The next day, another message arrived under the same name, this time about software and QA engineering. It came from a different Gmail address.
I decided to play along. I wanted to see what would happen if I asked for details someone handling a real recruitment process should be able to discuss.
I replied that I might be interested and asked for the full job description, Robert Half reference number, client or company name, location or time zone, employment type, compensation range and a link on Robert Half's website.
There was no answer to those questions.
On September 15, a fresh message arrived from "Anna", with another slightly different pitch and a third Gmail account. It did not continue the conversation I had started.
I replied out of curiosity, but there is no need to bait a suspicious sender to check an offer. Contacting the company through independently found details is a more useful way to establish whether the person represents it.
The Stripe pitch included my own project description
Later in the sequence, someone presenting himself as Gregory Crenshaw, founder and CEO of Vantage Talent Search, contacted me about a confidential Staff Backend Engineer opening at Stripe.
The message mentioned San Francisco or remote work and total compensation of $350,000 to $575,000.
I would not dismiss a senior engineering opportunity solely because of a large compensation figure. The sender details and the writing gave me better reasons to doubt this one.
The passage about Mouzi described my application, using the correct technology stack, but put the description in the recruiter's voice. Whoever assembled the message had failed to keep track of whose work they were describing.
That evening, a nearly identical pitch arrived from another Gmail account. It carried the same signature and the same Mouzi passage.
The corporate address was just a display name
The first Stripe pitch displayed this as its sender name:
gregorycrenshaw@vantagetalentsearch.com
It looked like an email address because it was written as one. But that text occupied the display-name part of the From field.
The address attached to it ended in @gmail.com.
Here is the relevant structure, with part of the Gmail username shortened:
From: "gregorycrenshaw@vantagetalentsearch.com"
<cgregor...@gmail.com>
| Part of the sender field | What it contained |
| --- | --- |
| Display name | gregorycrenshaw@vantagetalentsearch.com |
| Mailbox address | cgregor...@gmail.com |
Email syntax allows a display name alongside a mailbox address. The display name normally contains something like a person's name or an organisation. It can also contain text that resembles another address. The distinction is part of the email message format described in RFC 5322.
In this case, the company domain appeared in the label. It was not the domain of the mailbox in the From address.
The later message used a different display name, brights.@vantagetalentsearch.com, attached to yet another Gmail account, while retaining the Gregory signature.
You do not need to read an RFC to catch this. Expand the sender details and read the complete From address, rather than relying on the name shown in the inbox list. If a separate Reply-To address is present, inspect that too. A difference can have a legitimate explanation, but it is another detail to check.
SPF, DKIM and DMARC all passed
The authentication results in these five messages showed passes for SPF, DKIM and DMARC. The domain involved was gmail.com.
That result made sense:
- SPF checks whether the sending server is authorised for the domain being checked.
- DKIM verifies a cryptographic signature associated with a signing domain.
- DMARC requires a passing SPF or DKIM result whose domain aligns with the domain in the message's
Fromaddress.
These are checks on email authentication. They do not establish that the account holder works for a particular recruitment agency or has permission to recruit for Stripe. Google's sender guidelines explain these mechanisms and domain alignment.
Here, the actual From address was Gmail, and the authentication passed for Gmail. The corporate-looking display name did not turn that into authentication for Vantage Talent Search.
There was no need to defeat DMARC to make the name look corporate. The mismatch was visible once I opened the sender details.
Knowing my stack did not verify the sender
A message mentioning Rust, Tauri and Mouzi is more relevant to me than a generic offer addressed to "Dear candidate". It is also easy to construct from public information.
My project's description and technology stack are public. Including them in an email does not demonstrate a relationship with me, access to private information or any authority to recruit.
The first-person mistake suggests that the personalisation was assembled badly. It could have come from copying a profile description, filling a template incorrectly or generating text with AI. The email alone does not tell me which.
I also cannot establish that the Anna messages and the Gregory messages came from the same operator. Similar timing and tactics are not enough to identify the people behind the accounts.
What I can establish is narrower: five messages from five Gmail accounts, repeated claims about company affiliations, a corporate-looking display name attached to a different mailbox, and no answer to my request for verifiable job details.
That was enough for me to stop treating the contact as credible.
What I would check before sending anything back
The most useful checks do not require specialist tools.
- Read the complete sender address. Check the domain after the
@, including its spelling. A familiar company name elsewhere in the field proves nothing about that domain. A custom domain also needs checking. - Verify the person through an independent route. Find the agency or employer's official website yourself and use its published contact details. A job may be confidential or not publicly listed, so the absence of an advert is not conclusive. The claimed agency relationship should still be something you can investigate.
- Ask for enough detail to identify the opportunity. A role description, reference number, location and employment arrangement give you something concrete to check. Repeated fresh pitches that ignore those questions are a reason to stop.
- Treat requests for money or sensitive information as a separate decision. Do not pay an unknown sender to enter a recruitment process or hand over passwords and login codes. An early request for identity documents or banking information also deserves independent verification.
- Verify the contact before running a technical assessment. A repository, installer or terminal command from an unknown recruiter is still code supplied by a stranger. The words "coding exercise" do not make it safe to run on a machine containing your credentials and work.
Gmail by itself is not evidence of fraud. Independent recruiters and small businesses can use it legitimately. In these messages, it appeared alongside unverified corporate affiliations, changing accounts and evasive or inconsistent communication.
Robert Half's own fraud warning lists generic email accounts, vague job descriptions and requests for unnecessary personal information among the warning signs. It also says candidates will not be charged a fee to work with the company.
Keep the original message if you report it
Use your mail provider's phishing-reporting option and, where relevant, notify the impersonated company through its official contact channel.
Save the original message with its headers, ideally as an EML file. A screenshot can show what made the email persuasive, but it does not preserve the same information about how the message arrived. Remove your address and unrelated personal details from any screenshots you publish.
In Poland, suspicious incidents can be submitted through CERT Polska's reporting form, linked from its official contact page.
The messages I received had not yet asked me to pay, disclose login details or execute a file. I cannot say what the next step would have been. That uncertainty does not make the earlier identity problems disappear.
The sentence about Mouzi made the pitch easy to remember. The sender field is the detail I would check even in a much better-written email: the apparent company address was only a name someone had typed.