



Phishing has never been more dangerous — or more intelligent. Across India’s enterprise landscape, security teams are facing a new generation of attacks where the lure is personalised at scale, the sender domain passes every authentication check, and the malicious payload arrives only after the target’s geolocation and device fingerprint have been quietly assessed. Welcome to AI-powered phishing, and the urgent question Indian CISOs now face: are your defences built for yesterday’s threat or today’s?
Classic phishing relied on volume. Attackers blasted millions of identical emails and waited for a fraction of a percent to click. Spam filters, awareness training, and basic email authentication (SPF, DKIM, DMARC) blunted that approach significantly over the past decade.
Large Language Models changed the economics. An attacker today can feed a target’s LinkedIn profile, public news mentions, and leaked data into an LLM and generate a highly contextualised lure — one that references the recipient’s recent project, their manager’s name, or a regulation their company is currently navigating — in seconds and at effectively zero marginal cost. The same infrastructure that powers consumer chatbots is now being weaponised to make every phishing email feel like it was hand-crafted by someone who intimately knows the target.
In the Indian context, threat intelligence feeds monitored by PJ Networks’ SOC have flagged several recurring patterns through 2025 and into 2026:
Email authentication alone — even a fully deployed DMARC policy with p=reject — does not protect against lookalike domains, freshly registered domains with clean reputations, or legitimate cloud services (SharePoint, Google Drive, Dropbox) used as hosting for the actual payload. Awareness training is valuable but degrades quickly and cannot keep pace with lures generated at AI speed and updated daily.
Secure Email Gateways (SEGs) that rely on URL reputation and known-bad sender lists are reactive by design: they block what was bad yesterday. AI-generated campaigns frequently use infrastructure that has never appeared in threat feeds before, and the link embedded in the email may resolve to a benign page until it detects a corporate IP range, browser fingerprint, or operating system — then redirect to the real payload. This technique, known as cloaking, specifically defeats static link-scan approaches used by many legacy SEGs.
The volume problem has also inverted. In the old model, security teams had to process thousands of identical phishing emails. In the AI model, they face dozens of unique, highly contextualised messages, each requiring judgment rather than pattern matching. Detection tools trained on volume anomalies simply do not flag low-volume, high-precision campaigns.
Fighting AI-assisted phishing requires controls at multiple layers simultaneously. No single product closes every gap, and the gaps that matter most are the ones between tools.
Deploy an email security solution — such as FortiMail, which PJ Networks configures and manages for clients across India — that analyses email body semantics, sender reputation across multiple threat feeds, embedded URL behaviour (including sandbox detonation), and header anomalies simultaneously. FortiMail’s AI-based anti-spam and anti-phishing engine assigns composite risk scores rather than matching against static lists, which helps catch zero-reputation domains carrying AI-generated lures.
Key configurations for Indian enterprises:
p=reject on all outbound domains. An attacker cannot spoof your domain if your policy is enforced and monitored.Even after an email lands in the inbox, the attack is only realised when a user clicks and the payload loads. DNS-layer filtering (via FortiGate’s DNS filter or a dedicated DNS security service) intercepts the resolution request before the browser connects to the malicious host. Because many AI-phishing campaigns use freshly registered domains, applying risk policies to newly-observed domains — holding or quarantining resolution for 24–48 hours after registration — provides material protection at minimal user-experience cost.
When a credential is successfully phished, the attacker’s next goal is lateral movement — pivoting from the compromised account to high-value systems: financial applications, HR data, source code, customer databases. Traditional VPN-based access, once credentials are stolen, provides broad network reachability that attackers exploit within minutes of gaining access. ZTNA architectures, by contrast, grant access at the application level only, and continuously verify device posture and identity context before each session.
PJ Networks deploys and operates FortiGate-based ZTNA for enterprise clients across manufacturing, financial services, and technology sectors, shrinking the blast radius of a successful credential compromise to the specific applications the victim’s role requires — nothing more. In practice this means that even if an attacker obtains a valid session, they face another authentication and posture check before they can reach the next tier.
Traditional annual phishing simulation drills are necessary but insufficient against AI-generated campaigns. The cadence matters: monthly micro-simulations with immediate, contextualised feedback loops are far more effective at building lasting reflexes than a single annual exercise. Simulations should now include quishing scenarios (QR code-based), voice-phishing (vishing) test calls using AI-cloned voice samples, and lures constructed to mimic the prose style and context of messages the target actually receives.
Consider integrating threat-informed content into training: when your SOC observes a new campaign pattern targeting Indian enterprises in your sector, update simulation templates to match within days — not months. The training must evolve at least as fast as the threat.
Detection is not prevention. When a phishing email defeats your controls — and statistically, some will — the speed of detection and containment determines the breach’s ultimate scope. A credential compromised and exploited within the first hour causes exponentially more damage than one detected at the two-hour mark. This is where your SOC capability becomes the decisive variable.
Investigating a phishing incident that has progressed past the inbox requires correlating data from multiple sources simultaneously: email gateway logs, DNS query logs, endpoint telemetry, Active Directory authentication events, firewall traffic logs, and sometimes physical access records. In most Indian enterprise environments those sources sit in separate consoles — NOC, SOC, IT helpdesk — and correlation is done manually, often too slowly to contain the incident before significant damage is done.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner, and it is the platform we deploy and operate for clients who need cohesive visibility across their full security stack without maintaining a separate tool for every data source.
SIEM: Ora ingests logs from FortiMail, FortiGate, Active Directory, endpoint agents, cloud services, and web proxies into a centralised pipeline with correlation rules mapped to the MITRE ATT&CK framework. When a user clicks a phishing link, the resulting DNS query, outbound HTTP connection, and subsequent authentication event are stitched into a graph-based attack storyline — giving the SOC analyst a single narrative rather than disconnected log lines to manually correlate under pressure. Tiered retention (hot, cold, archive) helps organisations evidence their compliance with CERT-In’s 180-day in-country log retention direction, ensuring that months-old events remain quickly retrievable during an investigation or regulatory enquiry without the cost of keeping everything on primary storage.
NMS: Unified observability across FortiGate firewalls, managed switches, wireless APs, and WAN/SD-WAN links means the NOC sees anomalous traffic patterns — such as a spike in outbound DNS queries or unusual data transfer volumes from a single workstation post-click — in context alongside normal network baselines. ML-based anomaly detection flags deviations without requiring manual threshold tuning for every device, and auto-healing policies can isolate a suspected endpoint before a human analyst has even opened the alert. This capability is particularly valuable for multi-vendor estates where NOC visibility is otherwise fragmented across half a dozen separate dashboards, each requiring different credentials and workflows.
Video Surveillance (VMS): For clients with physical security requirements — manufacturing sites, retail chains, corporate campuses with multiple buildings — Ora’s video surveillance (VMS) pillar brings ONVIF/Hikvision/Dahua camera management and video analytics under the same operations view as network and security telemetry. A tailgating incident captured on camera can now be correlated with an access-card anomaly and a concurrent credential authentication alert, giving the security team a complete picture of a potential insider or physical-cyber combined attack without switching between platforms. This convergence is increasingly relevant as threat actors combine physical and cyber vectors in targeted enterprise attacks.
SOAR: The platform’s playbook automation includes pre-built connectors that can push blocklists directly to FortiGate the moment a malicious domain or IP is confirmed — no manual CLI session required, no waiting for an analyst to be available at 3 AM. This matters acutely in the Indian regulatory context: CERT-In’s 6-hour incident reporting window for significant cyber incidents is only achievable if your containment and evidence-collection steps are automated. Manual processes simply cannot meet that timeline reliably, especially for incidents that surface outside business hours. Ora’s SOAR layer makes the 6-hour window realistic rather than aspirational.
If your SOC today relies on manually correlating logs across isolated tools, we would welcome a conversation about what a unified platform deployment looks like for your environment and scale. Reach out to the PJ Networks team or explore platform capabilities at ora.prahix.com.
India’s Digital Personal Data Protection Act, 2023 places explicit obligations on data fiduciaries to implement “reasonable security safeguards” to prevent personal data breaches. A successful phishing attack that results in exfiltration of customer or employee personal data is precisely the kind of incident the DPDP Act is designed to address — and the kind that now carries potential financial consequences alongside reputational damage. While no security posture can guarantee zero incidents, organisations that cannot demonstrate proportionate, documented controls face significant exposure when a breach is investigated by the Data Protection Board.
CERT-In’s April 2022 direction on cyber incident reporting mandates that covered entities report cybersecurity incidents — including data breaches and credential compromises — within six hours of detection. The phishing scenarios most likely to trigger this obligation are also the ones most likely to escalate quickly: a C-suite account compromise, ransomware deployed from a phishing email, or mass exfiltration of customer records. Organisations that have not invested in detection and response capabilities may struggle to even detect the incident within six hours, let alone prepare and submit a compliant report.
Our layered security approach, including Ora’s SIEM and SOAR capabilities, is designed to support compliance with both DPDP Act obligations and CERT-In reporting requirements — helping your team detect faster, contain sooner, and evidence your response comprehensively.
p=reject on all outbound domains. SPF and DKIM configured and monitored via DMARC aggregate reports.PJ Networks provides 24/7 managed NOC and SOC services from India, combining FortiGate-based network security, FortiMail email protection, ZTNA deployment, and the PrahiX Ora unified SecOps platform into a cohesive managed service. We work with Indian enterprises across financial services, manufacturing, healthcare, and technology sectors — helping security teams build postures that are proportionate, auditable, and operationally sustainable without requiring a large in-house specialist headcount.
If AI-powered phishing is on your threat radar — and in 2026, it absolutely should be — we would welcome the opportunity to review your current email security architecture and SOC monitoring coverage. Contact the PJ Networks team to schedule a complimentary assessment and discuss what a managed security programme looks like for your organisation.
The threat is getting smarter every quarter. Your defences need to keep pace. PJ Networks is here to help you stay ahead.