AI-Powered Phishing Attacks in 2025: How Indian Enterprises Can Stay Ahead

  • Home
  • AI-Powered Phishing Attacks in 2025: How Indian Enterprises Can Stay Ahead
AI-Powered Phishing Attacks in 2025: How Indian Enterprises Can Stay Ahead

Phishing has been a persistent threat for two decades, but 2025 has brought a step change in sophistication that is catching Indian enterprises off guard. Generative AI now lets adversaries craft hyper-personalised lure emails at industrial scale — cloning internal writing styles, forging believable invoice threads, and even synthesising audio deepfakes of senior executives to authorise wire transfers. For Indian CISOs managing complex, multi-site environments, the threat is no longer “someone clicked a bad link.” It is “our CFO heard the MD’s voice and moved ₹4 crore.”

This post examines how AI-augmented phishing works, what makes Indian enterprises particularly exposed, and what a layered defence — spanning email security, endpoint detection, SOC vigilance, and employee awareness — looks like in practice.

Why AI Changes the Phishing Calculus

Traditional phishing relied on volume: send ten million generic emails and hope a fraction slip through. Spam filters learned to catch the obvious patterns — misspelled domains, generic greetings, suspicious attachments. Today’s AI-assisted campaigns invert that model.

  • Contextual personalisation at scale: Large language models can ingest publicly available data — LinkedIn profiles, press releases, annual reports, social media — and generate targeted spear-phishing emails that read as authentic internal communication.
  • Voice and video deepfakes: A sub-30-second audio clip of an executive is enough to clone their voice. Attackers phone a finance manager, impersonating the CFO, and request an urgent RTGS transfer. Several Indian conglomerates have reported losses running into crores through this vector in the past 18 months.
  • Multi-channel campaigns: Attackers chain email, WhatsApp, and LinkedIn messages to build false trust before the actual credential-harvesting link arrives. Each channel adds apparent legitimacy.
  • Living-off-the-land delivery: Instead of attaching malicious executables, modern campaigns abuse legitimate cloud services — Google Drive, SharePoint, DocuSign-alike portals — making gateway-level URL filtering far less effective.

Why Indian Enterprises Are in the Crosshairs

India is not simply a large market for phishing — it has specific structural characteristics that raise exposure.

Rapid Digital Adoption Without Proportionate Security Maturity

The pace of cloud adoption, UPI integration, and remote work expansion across Indian enterprises has outrun security investments for many organisations. Mid-market companies in sectors like manufacturing, logistics, and real estate often have modern ERP systems but rely on legacy email gateways and minimal SOC coverage.

Complex Vendor Ecosystems

The Indian enterprise supply chain is characterised by layered sub-contracting. An attacker compromising a tier-3 vendor’s email domain can send convincing invoices to a tier-1 enterprise. DPDP Act obligations notwithstanding, many vendors have limited incident response capabilities, making the lateral exposure difficult to contain.

CERT-In 6-Hour Reporting Window

The CERT-In Directions of 2022, as updated, require organisations to report qualifying cyber incidents — including phishing compromises that result in data exfiltration — within six hours of detection. Most Indian enterprises are not yet equipped to detect, triage, and report within this window without automated tooling. An undetected credential harvest that leads to a data breach can quickly become a regulatory issue on top of the operational damage.

Low MFA Penetration on Legacy Systems

Despite policy mandates, a significant share of enterprise applications — particularly ERP systems deployed five or more years ago — remain protected only by password. Credential phishing against these portals remains highly effective because there is no second factor to bypass.

The Anatomy of a Modern AI-Phishing Campaign Against an Indian Enterprise

A realistic attack chain in 2025 looks like this:

  1. Reconnaissance: The attacker uses OSINT automation to map the target’s org chart (LinkedIn), financial relationships (BSE/NSE filings, tender portals), and email naming conventions (pattern inference from public addresses).
  2. Lure construction: An LLM drafts a thread that mimics an ongoing vendor conversation, complete with realistic invoice numbering and appropriate department-specific language. The email originates from a convincingly spoofed or lookalike domain.
  3. Delivery and credential harvest: The email contains a link to a legitimate-looking SharePoint or DocuSign portal — actually a reverse proxy (adversary-in-the-middle style) that captures session cookies in real time, defeating even TOTP-based MFA.
  4. Lateral movement: Using the harvested session, the attacker accesses the finance portal or ERP, escalates privileges via internal phishing to a domain admin account, and establishes persistence.
  5. Exfiltration or fraud: Depending on the objective — ransomware pre-positioning, Business Email Compromise fraud, or data exfiltration for sale — the campaign monetises within 24–72 hours.

The window between initial credential compromise and containment is where the CERT-In 6-hour reporting clock starts ticking — and where most organisations lose the race.

A Layered Defence: What Actually Works

1. Email Gateway Hardening (FortiMail)

A next-generation secure email gateway should be doing more than spam filtering in 2025. FortiMail, deployed as part of PJ Networks’ managed email security service, applies sandboxed URL detonation, AI-based sender behaviour analysis, DMARC/DKIM/SPF enforcement, and lookalike domain detection. Critically, it should be configured to quarantine — not just flag — messages from domains registered in the last 30 days, a strong signal of phishing infrastructure.

2. MFA Everywhere, Phishing-Resistant Where Possible

Push-based TOTP MFA is necessary but not sufficient against session-hijacking proxies. Organisations should prioritise FIDO2/WebAuthn (hardware keys or passkeys) for privileged accounts — finance approvers, IT admins, executive assistants — as these credentials are cryptographically bound to the legitimate domain and cannot be relayed by a proxy.

3. ZTNA Over VPN for Remote Access

Traditional VPN grants network-level access after a single authentication event — a wide blast radius if credentials are phished. Zero Trust Network Access (ZTNA), as delivered through FortiGate and Fortinet’s ZTNA framework, continuously evaluates device posture and user context before allowing access to each specific application. A phished credential alone is insufficient to traverse the environment.

4. 24/7 SOC with Behavioural Detection

Phishing detection at the gateway catches many campaigns — but not all. A credential harvest via a reverse proxy may produce no malware signature at all. What it does produce is behavioural anomalies: a login from an unusual geography, an unusual volume of email forwarding rules being set, access to the ERP at 2 AM on a Sunday. A staffed 24/7 SOC with UEBA (User and Entity Behaviour Analytics) rules is the backstop.

5. Tabletop Exercises and Phishing Simulations

Technology controls are necessary but not sufficient. Quarterly simulated phishing campaigns — specifically targeting finance, HR, and executive assistant roles — keep human vigilance calibrated. The goal is not to punish failures but to measure and reduce the click rate over time, and to build the muscle memory of “verify by phone before acting on an unusual request.”

PrahiX Ora: Unified SecOps Visibility Across the Kill Chain

A phishing campaign that bypasses the email gateway and steals a session cookie will leave traces — but only if the SOC has the visibility and automation to act on them quickly enough. This is where we deploy and operate PrahiX Ora for our clients: a unified SecOps platform built by PrahiX Tech Pvt Ltd that collapses the tooling sprawl that typically slows SOC response.

SIEM — Correlating signals across the kill chain: The platform’s SIEM ingests logs from FortiGate, FortiMail, Active Directory, ERP access logs, and cloud platforms into a single correlation engine. Detection rules mapped to MITRE ATT&CK — specifically T1566 (Phishing), T1539 (Steal Web Session Cookie), and T1071 (Application Layer Protocol) — fire enriched alerts rather than raw log lines. When an adversary sets unusual inbox-forwarding rules post-compromise, the graph-based attack storyline reconstruction surfaces it as part of a coherent attack thread, not an isolated event. For CERT-In compliance, the platform supports tiered log retention — hot, cold, and archive tiers — supporting the 180-day in-country log retention direction so your evidence trail is intact if regulators ask.

NMS — Seeing the network move: Phishing is often the entry point for a broader intrusion. The Network Management System provides unified observability across FortiGate firewalls, switches, APs, and WAN/SD-WAN links. LLDP/CDP topology discovery and network path tracing mean that when a compromised endpoint begins lateral scanning, ML-based anomaly detection flags it before it becomes a full incident. For multi-vendor estates where NOC visibility is fragmented across separate consoles, this unified view is operationally significant.

Video surveillance (VMS) — Closing the physical loop: Social engineering attacks do not always begin digitally. An adversary may tailgate into a facility to physically insert a rogue device, or conduct physical reconnaissance before a targeted spear-phishing campaign. The video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras with video analytics, bringing physical and network security under a single operations view — particularly valuable for manufacturing, retail, and multi-site estates where physical access events should be correlated with network anomalies.

SOAR — Making CERT-In’s 6-hour clock achievable: The hardest part of CERT-In compliance is not documentation — it is detection-to-response speed. The SOAR module automates the response actions that would otherwise require manual SOC intervention: isolating a compromised endpoint, pushing an attacker’s IP to the FortiGate blocklist, disabling a compromised AD account, and generating the structured incident log needed for CERT-In notification. Pre-built playbook connectors cover common phishing response scenarios. Without this automation, reliably meeting a 6-hour reporting window across a large, distributed estate is aspirational. With it, it becomes operational.

If your organisation is assessing whether your current SecOps stack can deliver this kind of coordinated response, we are happy to walk through what a PrahiX Ora deployment looks like in an Indian enterprise context.

Practical Steps for CISOs: A 90-Day Hardening Roadmap

For Indian enterprise security leaders looking to address AI-augmented phishing in a structured way, the following phased approach provides a practical starting point.

Days 1–30: Visibility and Baseline

  • Audit email authentication posture: confirm DMARC is in enforced (reject) mode, not monitor-only.
  • Review email gateway configuration for lookalike domain detection and sandboxed URL detonation.
  • Inventory all external-facing authentication portals — ERP, VPN, webmail — and confirm MFA coverage.
  • Run the first simulated phishing exercise against finance and executive assistant roles to establish a baseline click rate.

Days 31–60: Prioritised Remediation

  • Deploy or upgrade to a phishing-resistant MFA credential (FIDO2/passkey) for all privileged accounts.
  • Implement ZTNA for remote access to critical applications, beginning with finance and HR portals.
  • Configure SIEM correlation rules for post-compromise indicators: unusual forwarding rules, impossible travel logins, bulk email sends from internal accounts.
  • Establish an internal incident classification taxonomy aligned to CERT-In reportable events.

Days 61–90: Continuous Improvement

  • Conduct a tabletop exercise simulating a CEO voice deepfake BEC attack — involve finance, legal, and the CISO.
  • Review SOC playbooks for phishing-related incident response; verify automation coverage for the first 30 minutes of an active compromise.
  • Validate log retention configuration against CERT-In’s 180-day direction; confirm logs are stored in-country.
  • Set quarterly cadence for phishing simulations; track and report click-rate reduction to the board.

The Regulatory Imperative: DPDP Act and Phishing

India’s Digital Personal Data Protection Act 2023 creates data fiduciary obligations that phishing attacks directly implicate. A successful credential phish that leads to unauthorised access to personal data — employee records, customer databases, healthcare information — triggers breach notification requirements. Combined with CERT-In’s 6-hour technical incident reporting, organisations face a tight, overlapping compliance timeline in the event of a successful attack.

Importantly, the DPDP Act does not allow organisations to contractually shift liability to a vendor — the data fiduciary is accountable. This means that even if a phishing attack originates through a third-party vendor’s compromised email, the data fiduciary holding the personal data remains responsible for notification and remediation. Third-party risk management programmes, including vendor email security assessments, are no longer optional.

Keeping detailed, timestamped incident logs is also a practical prerequisite for demonstrating compliance. Without automated log retention across all relevant systems, reconstructing what happened — and when — after a compromise is painstaking and often incomplete. This is precisely where tiered SIEM retention helps evidence compliance obligations under both the DPDP Act and CERT-In directions.

How PJ Networks Supports Your Anti-Phishing Posture

PJ Networks delivers managed security services purpose-built for the Indian enterprise environment. Our FortiMail managed email security service covers gateway configuration, ongoing tuning, and threat intelligence updates — without requiring in-house expertise. Our 24/7 NOC/SOC, backed by the PrahiX Ora platform we deploy and operate for clients, provides the continuous monitoring and automated response capability that makes CERT-In compliance achievable rather than aspirational. Where organisations are moving from VPN to ZTNA, our FortiGate and Fortinet ZTNA deployment practice handles the architecture and migration.

AI-augmented phishing is not a future threat — it is the current reality for Indian enterprises. The organisations that manage it well in 2025 will be those that move from perimeter-centric email security to layered, behaviour-aware defences with genuine SOC depth. If you would like a no-obligation assessment of your current email security and SOC coverage, reach out to the PJ Networks team.

Leave a Reply

Your email address will not be published. Required fields are marked *