



In 2026, phishing is no longer the poorly-worded, grammatically suspicious email of five years ago. Generative AI has fundamentally changed the threat landscape: attackers now spin up hyper-personalised lure emails in seconds, scraping LinkedIn profiles, company websites, and public financial filings to craft messages that are contextually accurate, grammatically flawless, and alarmingly convincing. For Indian enterprises — already navigating the DPDP Act’s reporting mandates and CERT-In’s six-hour incident notification window — the rise of AI-powered phishing represents one of the most urgent challenges of this decade.
This post unpacks how the threat has evolved, what detection gaps remain in legacy email gateways, and how a layered stack combining FortiMail, AI-driven threat intelligence, and SOAR automation gives your security team a fighting chance.
Traditional phishing relied on volume: cast a million hooks and a few fish bite. GenAI has inverted that economics. With tools now readily available on dark-web forums, threat actors can:
In the Indian context, threat actors are increasingly targeting mid-market manufacturers, logistics firms, and financial services companies using Business Email Compromise (BEC) that references real GST numbers, valid CIN data from MCA filings, or recently announced mergers — all harvested automatically from public sources. The average BEC wire fraud loss in India has climbed significantly year-on-year, and the sophistication of the lures is the primary driver.
Many Indian enterprises still rely on basic spam filters or cloud email platforms with built-in protection. These are table stakes — not a defence posture. The gaps are structural:
Reputation lists and known-bad domains block yesterday’s infrastructure. Attackers using freshly registered domains, compromised legitimate accounts, or trusted cloud storage links (SharePoint, Google Drive) for payload delivery bypass these controls entirely. A 2025 industry report found that over 60% of successful BEC attacks involved no malicious attachment or URL — just a well-crafted request to transfer funds or share credentials.
If your gateway cannot answer “does this email match how this sender normally communicates, and is this request pattern unusual for this recipient?” you are flying blind. Legacy filters have no per-user communication graph; they evaluate each email in isolation.
Traditional threat intelligence feeds update every few hours. AI-generated phishing campaigns spin up, harvest credentials, and pivot to new infrastructure in under an hour. The intelligence is stale before it arrives.
When a malicious email lands in a mailbox before detection, many gateways have no ability to reach in and delete it. The burden falls on the end-user to not click — an unreliable last line of defence.
Fortinet’s FortiMail platform — which PJ Networks deploys and manages for enterprise clients — addresses these gaps through a multi-layer inspection architecture that combines reputation, content analysis, AI-based detection, and integration with the broader Fortinet Security Fabric.
FortiMail’s machine-learning models are trained on billions of email samples and updated continuously via FortiGuard threat intelligence. Rather than relying on static signatures, the engine analyses message structure, header anomalies, link obfuscation patterns, and attachment behaviour to assign a probabilistic risk score. This means novel GenAI-crafted emails — even those with no prior threat history — can be flagged based on behavioural signals invisible to signature engines.
FortiMail’s display-name analysis and lookalike-domain detection specifically target CEO fraud and finance-team impersonation — the scenarios most commonly exploited in AI-generated BEC. It checks DMARC/DKIM/SPF alignment, detects domain variations (pjnetwörks.com vs pjnetworks.com), and flags requests matching high-risk BEC patterns such as urgent fund transfers or credential requests from “executive” senders.
For attachments and URLs, FortiMail integrates with FortiSandbox for safe detonation. Suspicious files are executed in an isolated environment; malicious behaviour — registry changes, outbound C2 callbacks, lateral movement attempts — is detected before the email is released to the recipient’s inbox.
When a threat is discovered after delivery — through a FortiGuard intelligence update, an SOC investigation, or a user report — FortiMail can perform automated or admin-triggered post-delivery retraction, removing the message from all impacted mailboxes across the organisation.
Email security does not exist in isolation. A phishing email that bypasses detection, delivers a credential stealer, and results in an account compromise needs to be detected, correlated, and responded to — fast. This is where the platform we deploy and operate for clients, PrahiX Ora (built by PrahiX Tech Pvt Ltd), becomes critical to the overall security posture.
PrahiX Ora is a unified SecOps platform integrating SIEM, NMS, video surveillance (VMS), and SOAR under a single operational pane. Here is how each pillar contributes to email-threat defence:
When FortiMail logs a suspicious email event, Ora’s SIEM ingests that log alongside authentication events, endpoint telemetry, and network flow data. Correlation rules mapped to the MITRE ATT&CK framework — Initial Access via Phishing (T1566), Credential Access (T1110), Lateral Movement — automatically stitch these disparate signals into a graph-based attack storyline, giving the analyst a single view of the threat chain rather than scattered alerts.
For Indian enterprises, this matters directly in the context of CERT-In’s direction on 180-day in-country log retention: Ora’s tiered retention architecture (hot/cold/archive) keeps logs accessible and audit-ready without ballooning on-premises storage costs — supporting compliance with that retention direction without operational friction.
Once credentials are harvested, attackers often move fast — logging in from unexpected geographies, pivoting to internal systems, exfiltrating data. Ora’s NMS layer provides unified observability across firewalls (including FortiGate), switches, APs, and WAN/SD-WAN links. ML-based anomaly detection flags unusual traffic volumes, unexpected protocol use, or new east-west flows that emerge after a suspected compromise — exactly the signal your SOC needs to catch lateral movement before it reaches crown-jewel systems. In multi-vendor estates where NOC visibility has historically been fragmented across vendor-specific dashboards, Ora’s LLDP/CDP topology discovery and network path tracing give the operations team a coherent picture.
For manufacturing plants, retail chains, and multi-site enterprises, a sophisticated attack may blend digital and physical vectors — a phished credential used at a server-room access terminal, or a social engineering visit timed with a spear-phishing campaign. Ora’s video surveillance (VMS) module, supporting ONVIF/Hikvision/Dahua camera management with video analytics, brings physical and network security events into a single operations view. Correlating a badge-access anomaly with a simultaneous unusual login alert is now a workflow, not a manual investigation.
CERT-In’s six-hour incident reporting window is not aspirational — it is a compliance requirement. When a phishing campaign results in a confirmed breach, the clock starts immediately. Manual triage, manual ticket creation, manual stakeholder notifications, and manual firewall rule pushes will not fit inside six hours at scale.
Ora’s SOAR module provides playbook automation with pre-built connectors. When a phishing incident is confirmed — say, FortiMail flags a credential-harvesting URL and the SIEM correlates a successful login from a foreign IP — an automated playbook can: disable the compromised account in Active Directory, push a blocklist entry to FortiGate via FortiOS API, notify the CISO and compliance team, open a tracked incident ticket, and begin generating the CERT-In report template — all within minutes of detection. Automation is what makes the six-hour window realistic.
For Indian enterprise IT leaders assessing their readiness, here is a practical framework to evaluate and close gaps:
p=reject? This is the single most effective control against domain spoofing.India’s Digital Personal Data Protection Act introduces a new layer of urgency. A successful phishing attack that results in unauthorised access to personal data held by your organisation triggers notification obligations to the Data Protection Board and, in many cases, to affected data principals. The combination of CERT-In’s six-hour reporting window and the DPDP Act’s breach notification requirements means that slow incident response is no longer just a security failure — it is a regulatory one.
FortiMail’s tamper-evident audit trails and PrahiX Ora’s log retention and incident documentation capabilities help organisations evidence their security posture and support compliance with both frameworks. The goal is not just to prevent breaches, but to demonstrate — in documented, auditable form — that your controls were proportionate and your response was timely.
PJ Networks operates as a managed security services provider serving Indian enterprises from our 24/7 NOC/SOC. Our email security practice combines FortiMail deployment and tuning with active monitoring, threat intelligence subscription through FortiGuard, and incident response coordination. For organisations that require a unified SecOps view, we deploy and operate PrahiX Ora — providing SIEM, NMS, video surveillance (VMS), and SOAR capabilities under a single managed service.
If your current email security posture is built on reputation filters alone, or if you have not tested your incident response timeline against the CERT-In six-hour requirement, now is the time to close those gaps. The threat actors are not waiting.
Speak with a PJ Networks security engineer about a no-obligation FortiMail assessment or a SOAR readiness review aligned to CERT-In and DPDP Act requirements. Contact us through pjnetworks.com.