AI-Powered Phishing in 2026: How Indian Enterprises Can Fight Back with FortiMail and SOAR

  • Home
  • AI-Powered Phishing in 2026: How Indian Enterprises Can Fight Back with FortiMail and SOAR
AI-Powered Phishing in 2026: How Indian Enterprises Can Fight Back with FortiMail and SOAR

In 2026, phishing is no longer the poorly-worded, grammatically suspicious email of five years ago. Generative AI has fundamentally changed the threat landscape: attackers now spin up hyper-personalised lure emails in seconds, scraping LinkedIn profiles, company websites, and public financial filings to craft messages that are contextually accurate, grammatically flawless, and alarmingly convincing. For Indian enterprises — already navigating the DPDP Act’s reporting mandates and CERT-In’s six-hour incident notification window — the rise of AI-powered phishing represents one of the most urgent challenges of this decade.

This post unpacks how the threat has evolved, what detection gaps remain in legacy email gateways, and how a layered stack combining FortiMail, AI-driven threat intelligence, and SOAR automation gives your security team a fighting chance.

The New Face of AI-Powered Phishing

Traditional phishing relied on volume: cast a million hooks and a few fish bite. GenAI has inverted that economics. With tools now readily available on dark-web forums, threat actors can:

  • Clone writing style: Feed a few public emails or press releases from a target executive and generate a lure that mirrors their cadence perfectly.
  • Automate spear-phishing at scale: Personalise thousands of emails per hour — each referencing the recipient’s recent project, their manager’s name, a real invoice number — for the cost of a few API tokens.
  • Bypass legacy signature detection: Every generated email is unique; hash-based and pattern-based filters have nothing to match.
  • Defeat language-quality heuristics: Older email security products flagged poor grammar as a risk signal. That signal is now meaningless.

In the Indian context, threat actors are increasingly targeting mid-market manufacturers, logistics firms, and financial services companies using Business Email Compromise (BEC) that references real GST numbers, valid CIN data from MCA filings, or recently announced mergers — all harvested automatically from public sources. The average BEC wire fraud loss in India has climbed significantly year-on-year, and the sophistication of the lures is the primary driver.

Why Legacy Email Gateways Fall Short

Many Indian enterprises still rely on basic spam filters or cloud email platforms with built-in protection. These are table stakes — not a defence posture. The gaps are structural:

1. Signature and Reputation-Only Filtering

Reputation lists and known-bad domains block yesterday’s infrastructure. Attackers using freshly registered domains, compromised legitimate accounts, or trusted cloud storage links (SharePoint, Google Drive) for payload delivery bypass these controls entirely. A 2025 industry report found that over 60% of successful BEC attacks involved no malicious attachment or URL — just a well-crafted request to transfer funds or share credentials.

2. No Behavioural Baselining

If your gateway cannot answer “does this email match how this sender normally communicates, and is this request pattern unusual for this recipient?” you are flying blind. Legacy filters have no per-user communication graph; they evaluate each email in isolation.

3. Delayed Threat Intelligence Feeds

Traditional threat intelligence feeds update every few hours. AI-generated phishing campaigns spin up, harvest credentials, and pivot to new infrastructure in under an hour. The intelligence is stale before it arrives.

4. No Post-Delivery Remediation

When a malicious email lands in a mailbox before detection, many gateways have no ability to reach in and delete it. The burden falls on the end-user to not click — an unreliable last line of defence.

FortiMail: Layered Email Security Built for Modern Threats

Fortinet’s FortiMail platform — which PJ Networks deploys and manages for enterprise clients — addresses these gaps through a multi-layer inspection architecture that combines reputation, content analysis, AI-based detection, and integration with the broader Fortinet Security Fabric.

AI-Assisted Threat Detection

FortiMail’s machine-learning models are trained on billions of email samples and updated continuously via FortiGuard threat intelligence. Rather than relying on static signatures, the engine analyses message structure, header anomalies, link obfuscation patterns, and attachment behaviour to assign a probabilistic risk score. This means novel GenAI-crafted emails — even those with no prior threat history — can be flagged based on behavioural signals invisible to signature engines.

Impersonation and BEC Detection

FortiMail’s display-name analysis and lookalike-domain detection specifically target CEO fraud and finance-team impersonation — the scenarios most commonly exploited in AI-generated BEC. It checks DMARC/DKIM/SPF alignment, detects domain variations (pjnetwörks.com vs pjnetworks.com), and flags requests matching high-risk BEC patterns such as urgent fund transfers or credential requests from “executive” senders.

Sandbox Detonation

For attachments and URLs, FortiMail integrates with FortiSandbox for safe detonation. Suspicious files are executed in an isolated environment; malicious behaviour — registry changes, outbound C2 callbacks, lateral movement attempts — is detected before the email is released to the recipient’s inbox.

Post-Delivery Remediation

When a threat is discovered after delivery — through a FortiGuard intelligence update, an SOC investigation, or a user report — FortiMail can perform automated or admin-triggered post-delivery retraction, removing the message from all impacted mailboxes across the organisation.

PrahiX Ora: Closing the Loop with Unified SecOps

Email security does not exist in isolation. A phishing email that bypasses detection, delivers a credential stealer, and results in an account compromise needs to be detected, correlated, and responded to — fast. This is where the platform we deploy and operate for clients, PrahiX Ora (built by PrahiX Tech Pvt Ltd), becomes critical to the overall security posture.

PrahiX Ora is a unified SecOps platform integrating SIEM, NMS, video surveillance (VMS), and SOAR under a single operational pane. Here is how each pillar contributes to email-threat defence:

SIEM: Correlate Email Events with the Broader Kill Chain

When FortiMail logs a suspicious email event, Ora’s SIEM ingests that log alongside authentication events, endpoint telemetry, and network flow data. Correlation rules mapped to the MITRE ATT&CK framework — Initial Access via Phishing (T1566), Credential Access (T1110), Lateral Movement — automatically stitch these disparate signals into a graph-based attack storyline, giving the analyst a single view of the threat chain rather than scattered alerts.

For Indian enterprises, this matters directly in the context of CERT-In’s direction on 180-day in-country log retention: Ora’s tiered retention architecture (hot/cold/archive) keeps logs accessible and audit-ready without ballooning on-premises storage costs — supporting compliance with that retention direction without operational friction.

NMS: Catch the Network Side of a Successful Phish

Once credentials are harvested, attackers often move fast — logging in from unexpected geographies, pivoting to internal systems, exfiltrating data. Ora’s NMS layer provides unified observability across firewalls (including FortiGate), switches, APs, and WAN/SD-WAN links. ML-based anomaly detection flags unusual traffic volumes, unexpected protocol use, or new east-west flows that emerge after a suspected compromise — exactly the signal your SOC needs to catch lateral movement before it reaches crown-jewel systems. In multi-vendor estates where NOC visibility has historically been fragmented across vendor-specific dashboards, Ora’s LLDP/CDP topology discovery and network path tracing give the operations team a coherent picture.

Video Surveillance (VMS): Physical Security in the Same Operations View

For manufacturing plants, retail chains, and multi-site enterprises, a sophisticated attack may blend digital and physical vectors — a phished credential used at a server-room access terminal, or a social engineering visit timed with a spear-phishing campaign. Ora’s video surveillance (VMS) module, supporting ONVIF/Hikvision/Dahua camera management with video analytics, brings physical and network security events into a single operations view. Correlating a badge-access anomaly with a simultaneous unusual login alert is now a workflow, not a manual investigation.

SOAR: The 6-Hour Window Demands Automation

CERT-In’s six-hour incident reporting window is not aspirational — it is a compliance requirement. When a phishing campaign results in a confirmed breach, the clock starts immediately. Manual triage, manual ticket creation, manual stakeholder notifications, and manual firewall rule pushes will not fit inside six hours at scale.

Ora’s SOAR module provides playbook automation with pre-built connectors. When a phishing incident is confirmed — say, FortiMail flags a credential-harvesting URL and the SIEM correlates a successful login from a foreign IP — an automated playbook can: disable the compromised account in Active Directory, push a blocklist entry to FortiGate via FortiOS API, notify the CISO and compliance team, open a tracked incident ticket, and begin generating the CERT-In report template — all within minutes of detection. Automation is what makes the six-hour window realistic.

Building a Phishing-Resilient Architecture: A Practical Checklist

For Indian enterprise IT leaders assessing their readiness, here is a practical framework to evaluate and close gaps:

  • Email Gateway: Does your gateway perform AI-assisted content scoring, behavioural analysis, and BEC-specific impersonation detection — or only signature/reputation checks?
  • Sandbox Integration: Are suspicious attachments and URLs detonated in isolation before reaching end-user inboxes?
  • DMARC Policy: Is your domain publishing a DMARC policy at p=reject? This is the single most effective control against domain spoofing.
  • Post-Delivery Retraction: Can your team remove a malicious email from all mailboxes after the fact — within minutes, not hours?
  • Log Correlation: Are email security events correlated with authentication, endpoint, and network logs — or are they siloed in a separate console?
  • Incident Playbooks: Is your phishing response documented, tested, and automated to the degree that the CERT-In six-hour window is consistently achievable?
  • Log Retention: Are email and security logs retained for 180 days in India as per CERT-In’s direction, with tamper-evident storage?
  • Security Awareness: Is phishing simulation training running quarterly with metrics tracked at the department level?

The DPDP Act Dimension

India’s Digital Personal Data Protection Act introduces a new layer of urgency. A successful phishing attack that results in unauthorised access to personal data held by your organisation triggers notification obligations to the Data Protection Board and, in many cases, to affected data principals. The combination of CERT-In’s six-hour reporting window and the DPDP Act’s breach notification requirements means that slow incident response is no longer just a security failure — it is a regulatory one.

FortiMail’s tamper-evident audit trails and PrahiX Ora’s log retention and incident documentation capabilities help organisations evidence their security posture and support compliance with both frameworks. The goal is not just to prevent breaches, but to demonstrate — in documented, auditable form — that your controls were proportionate and your response was timely.

How PJ Networks Can Help

PJ Networks operates as a managed security services provider serving Indian enterprises from our 24/7 NOC/SOC. Our email security practice combines FortiMail deployment and tuning with active monitoring, threat intelligence subscription through FortiGuard, and incident response coordination. For organisations that require a unified SecOps view, we deploy and operate PrahiX Ora — providing SIEM, NMS, video surveillance (VMS), and SOAR capabilities under a single managed service.

If your current email security posture is built on reputation filters alone, or if you have not tested your incident response timeline against the CERT-In six-hour requirement, now is the time to close those gaps. The threat actors are not waiting.

Speak with a PJ Networks security engineer about a no-obligation FortiMail assessment or a SOAR readiness review aligned to CERT-In and DPDP Act requirements. Contact us through pjnetworks.com.

Leave a Reply

Your email address will not be published. Required fields are marked *