



In the first half of 2025, India’s Computer Emergency Response Team (CERT-In) logged a sharp rise in AI-generated phishing campaigns targeting mid-market and enterprise organisations. Unlike the poorly-worded bulk emails of a decade ago, today’s lures are indistinguishable from legitimate vendor correspondence—correct logos, personalised salutations, plausible invoice numbers, and even synthetic voice notes to back up the written bait. For Indian enterprise IT and security leaders, the old email-gateway perimeter is no longer enough.
Traditional phishing relied on scale: send a million emails and a fraction of recipients will click. AI-powered phishing inverts that model. Large language models can scrape a target’s LinkedIn profile, press releases, and industry associations to craft a message that references a genuine supplier relationship, a recent tender, or an upcoming regulatory deadline. Defenders face a signal-to-noise problem: the malicious email looks and reads exactly like a legitimate one.
The threat is compounding across several dimensions:
India’s digital economy is a high-value target for several structural reasons. Rapid cloud adoption by manufacturing, BFSI, and logistics companies has outpaced security maturity in many organisations. The Digital Personal Data Protection (DPDP) Act, 2023 now places explicit accountability on data fiduciaries; a successful phishing attack that leads to a breach can trigger mandatory CERT-In reporting within six hours and potential regulatory action under DPDP. At the same time, legacy on-premises infrastructure and multi-vendor network estates create seams in visibility that attackers know how to exploit.
The RBI has issued multiple advisories on vishing (voice phishing) campaigns targeting banking customers and fintech employees. SEBI-regulated entities face similar threats aimed at extracting MNPI or gaining access to trading platforms. In manufacturing, IP theft via spear-phishing is a growing concern as Indian companies scale up R&D operations.
PJ Networks deploys FortiGate Next-Generation Firewalls as the core enforcement layer for enterprise clients. For AI-powered phishing, the relevant FortiGate capabilities are:
FortiMail—deployed in conjunction with FortiGate—applies AI-assisted analysis to inspect message structure, header anomalies, sending infrastructure reputation, and embedded URLs in real time. Suspicious attachments are detonated in FortiSandbox, which can detect delayed-retrieval payloads by extending observation windows and monitoring outbound callback behaviour.
FortiGate’s DNS filter intercepts lookups to newly registered domains, fast-flux infrastructure, and categorised phishing hosts. Because AI-generated campaigns often lean on freshly registered lookalike domains (e.g., vendor-invoice[.]in registered the morning of an attack), catching the lookup before the payload lands is a material defensive win.
More than 85% of phishing payloads now travel over HTTPS. FortiGate’s SSL inspection decrypts and re-inspects traffic inline, feeding full URL paths and file content into the Intrusion Prevention System and Web Filter engines without creating blind spots on encrypted channels.
FortiGuard Labs continuously publishes updated intelligence on phishing infrastructure, malware signatures, and behaviour indicators. FortiGate appliances consume these feeds automatically, shrinking the window between attacker infrastructure standing up and your firewall blocking it.
Technical controls alone cannot close the gap. AI-generated phishing campaigns are designed to probe for the specific moment a gateway is misconfigured, a rule set is stale, or an analyst is overwhelmed by alert volume. PJ Networks’ 24/7 NOC/SOC model addresses each of these failure modes:
Even with the best gateway and SOC coverage, a sophisticated AI-crafted lure may occasionally succeed. Zero Trust Network Access (ZTNA) limits what an attacker can do with a stolen credential. Rather than granting broad VPN-style access to the corporate network, ZTNA enforces continuous, per-session authentication and authorisation, restricting lateral movement to only the specific applications and data the legitimate user is entitled to access.
PJ Networks deploys Fortinet’s ZTNA solution, integrated with FortiGate and FortiAuthenticator. Key architectural points:
Understanding a phishing attack in isolation is not enough. Security teams need to see the complete attack timeline—from the initial email delivery to the first beacon call to any lateral movement—stitched together across logs from firewalls, endpoints, email gateways, and identity providers. PrahiX Ora is the unified SecOps platform we deploy and operate for clients to provide exactly this visibility.
PrahiX Ora is built by PrahiX Tech Pvt Ltd; PJ Networks is its primary field deployment and operations partner. The platform integrates four capability pillars that are directly relevant to AI-powered phishing response:
Ora’s SIEM module ingests logs from FortiGate, FortiMail, endpoint agents, identity providers, and cloud access logs into a centralised pipeline. Correlation rules mapped to the MITRE ATT&CK framework automatically tag and cluster related events—so a suspicious email delivery, a sandbox alert, and a DNS lookup to a new domain three hours later are presented as a single attack storyline rather than three independent alerts. For Indian organisations, this matters operationally: CERT-In’s direction on 180-day in-country log retention is met by Ora’s tiered retention architecture (hot, cold, and archive storage), keeping forensic data available for post-incident investigation without ballooning on-premises storage costs.
Many Indian enterprise networks are multi-vendor by history—legacy Cisco routing infrastructure alongside FortiGate firewalls and third-party wireless access points. Ora’s Network Management System provides unified observability across this heterogeneous estate using LLDP/CDP topology discovery and ML-based anomaly detection. When a phishing-delivered RAT begins beaconing, anomalous outbound traffic patterns surface in the NMS before they register as a full alert, giving analysts early warning. Auto-healing policies can quarantine a suspicious network segment without waiting for manual intervention.
Phishing is not always purely digital. Insider-threat scenarios often involve a physical access event—a visitor in a server room, a USB drop in a car park—paired with a malicious email. Ora’s video surveillance (VMS) module manages ONVIF, Hikvision, and Dahua cameras with integrated video analytics, bringing physical and network security events into a single operations view. For manufacturing plants, retail chains, and multi-site enterprises, this convergence closes a blind spot that siloed physical-security and IT-security teams cannot cover independently.
CERT-In’s requirement to report a cyber incident within six hours of detection is ambitious when response actions are manual. Ora’s SOAR module changes the calculus with pre-built playbook automation and connectors to FortiGate and other enforcement points. When the SIEM identifies a credential compromise following a phishing event, an automated playbook can simultaneously: disable the affected Active Directory account, push a blocklist update to FortiGate for the attacker’s known C2 infrastructure, isolate the affected endpoint, and open a timestamped incident ticket—all within minutes. Analysts focus on triage and executive communication rather than running scripts. That is what makes a six-hour reporting window achievable rather than aspirational.
If you are reviewing your organisation’s posture against AI-powered phishing, the following checklist is a useful starting point:
PJ Networks designs, deploys, and operates managed security infrastructure for Indian enterprises across manufacturing, BFSI, logistics, healthcare, and IT/ITeS sectors. Our service stack—FortiGate NGFW, FortiMail, ZTNA, and 24/7 NOC/SOC operations supported by the PrahiX Ora platform—is specifically assembled for the threat environment Indian organisations face today.
We do not sell technology and leave clients to operate it. Every deployment comes with continuous monitoring, policy tuning, threat intelligence operationalisation, and direct CERT-In compliance support. If your organisation is re-evaluating its phishing defence posture in light of the AI-generated threat wave, we are happy to conduct a no-obligation assessment of your current email security and gateway configuration.
To speak with a PJ Networks security architect, contact us at pjnetworks.com/contact.