



Generative AI has fundamentally changed the phishing threat landscape. In 2024 and 2025 we saw the first wave of AI-crafted spear-phishing emails that bypassed conventional Secure Email Gateways — and by 2026, that capability is now table-stakes for any moderately funded threat actor. For Indian enterprise security teams, the implications are severe. Attackers can now craft highly personalised, grammatically flawless lures in Hindi, Telugu, Tamil, or Marathi at industrial scale, targeting finance controllers, HR managers, and C-level executives with uncanny accuracy.
This post walks through what AI-powered phishing looks like in practice, why legacy defences are struggling, and the concrete steps Indian CISOs and IT leaders can take — from email gateway hardening to FortiMail deployment to 24/7 SOC surveillance — to protect their organisations.
Traditional phishing relied on mass-blast, obviously templated emails. Detection was relatively straightforward: look for typos, unfamiliar sender domains, generic salutations, and suspicious hyperlinks. AI has dismantled each of those signals one by one.
Large Language Models can now ingest a target’s LinkedIn profile, public press releases, recent regulatory filings, and news mentions to craft a contextually rich email. A phishing email to an Indian CFO might reference the company’s latest SEBI filing, name their actual auditor, and request a fund transfer under a plausible internal approval workflow — all in fluent English or even Hinglish. The attacker spends seconds; the SOC analyst spends minutes trying to rule it out.
Several publicly reported incidents in 2025 involved deepfake voice calls — a threat actor impersonating a senior executive to instruct a finance team to approve a wire transfer. When combined with an AI-drafted email “follow-up,” the social engineering chain is devastatingly convincing. Indian BPO and BFSI firms have been disproportionately targeted, given their high-value transaction volumes and large distributed workforces.
AI-generated phishing emails score low on traditional rule-based filters because they lack the classic indicators: no mass-blast patterns, no known-bad domains in the first send, no attachment-based payload in the opening email. The payload arrives in a later stage — a benign-looking OneDrive or SharePoint link that redirects to a credential harvester after the initial inspection window has passed (a technique sometimes called “time-delayed redirection”).
Several factors make Indian enterprises particularly attractive targets and add complexity to defence:
A basic Secure Email Gateway (SEG) filters on known malicious URLs, attachment hashes, and sender reputation. These controls remain necessary but are no longer sufficient. Consider the attack chain:
pjnetworks-india.com) days or weeks before the campaign. By send time, it has a neutral reputation score.Defending against this chain requires controls at multiple layers: pre-delivery (domain reputation, sender authentication), post-delivery (URL re-evaluation, sandboxing), and detection-and-response (correlating email events with identity and endpoint telemetry in real time).
PJ Networks deploys and manages Fortinet FortiMail as a cornerstone of enterprise email security. FortiMail goes substantially beyond a basic SEG:
FortiMail combines AI/ML-based content analysis, FortiGuard threat intelligence (updated in real time), sender domain reputation, and SPF/DKIM/DMARC enforcement. Critically, it performs URL rewriting and time-of-click re-evaluation — so even if a link was clean at delivery, clicking it triggers a fresh sandbox check against the latest threat intelligence. This directly addresses the time-delayed redirection technique described above.
FortiMail includes heuristics specifically tuned for BEC — detecting display-name spoofing, lookalike domains, and impersonation of internal executives. For Indian enterprises where wire transfer fraud via email is a known risk vector, this protection is directly relevant.
Because FortiMail shares threat intelligence with FortiGate next-generation firewalls, FortiAnalyzer, and FortiSIEM, a malicious indicator discovered in the email stream can be automatically pushed to network-layer controls within minutes — not after a human analyst has reviewed it. This Fabric integration is a meaningful operational advantage for organisations that have already standardised on Fortinet.
FortiMail can be deployed as an on-premises appliance, a virtual machine, or a cloud-hosted service (FortiMail Cloud). For Indian enterprises with data localisation considerations under the DPDP Act, on-premises or private-cloud options allow email metadata and logs to remain in-country — supporting compliance without sacrificing protection capability.
Technology alone is insufficient. AI-generated phishing is sophisticated enough that some attacks will inevitably reach the inbox. What matters then is how fast an organisation detects and contains.
PJ Networks operates a 24/7 NOC/SOC that integrates email telemetry from FortiMail alongside network events from FortiGate, endpoint events, and identity logs. When FortiMail flags a suspicious email — or when a user reports a suspected phish — our SOC analysts triage it against the wider threat picture in real time. Did the sender domain appear in any DNS queries across the network in the last 24 hours? Has any endpoint made an outbound connection to the linked infrastructure? Is there lateral movement evidence consistent with a successful credential harvest?
That correlation is what converts a phishing detection into a contained incident. Without it, even a capable email security platform generates alerts that queue up for a morning review — long after the attacker has moved.
For organisations that want end-to-end visibility beyond just email, PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd that PJ Networks deploys and operates for clients. It brings together four capabilities that are directly relevant to combating AI-powered phishing:
SIEM — Log and Event Correlation: Ora’s SIEM ingests logs from FortiMail, FortiGate, Active Directory, cloud identity providers, and other sources. Correlation rules mapped to the MITRE ATT&CK framework — specifically the Initial Access and Credential Access tactics most relevant to phishing — surface attack storylines graphically, showing the analyst how an email event connects to a subsequent credential use attempt. For compliance, Ora supports tiered retention (hot/cold/archive) aligned to CERT-In’s direction for 180-day in-country log retention, which is non-negotiable for regulated Indian enterprises.
NMS — Network Observability: When a user clicks a phishing link, the first network event is typically a DNS query followed by an outbound HTTP/S connection to attacker infrastructure. Ora’s NMS provides unified observability across firewalls, switches, and WAN/SD-WAN links, with ML-based anomaly detection that can flag unusual outbound connection patterns in near real time. For organisations with multi-vendor network estates — common in Indian enterprises where NOC visibility is often fragmented across teams — this unified view is operationally critical.
Video Surveillance (VMS): For manufacturing, retail, and multi-site Indian enterprises, Ora’s video surveillance (VMS) module integrates physical security camera management (ONVIF, Hikvision, Dahua) with network security operations under a single pane. While phishing is a digital threat, physical security breaches — such as a threat actor gaining building access through a social engineering pretext — are sometimes a companion to cyber attacks. Seeing both domains in one operations view removes the blind spot between IT security and physical security teams.
SOAR — Automated Response: This is perhaps the most directly relevant capability for phishing response. When a phishing incident is confirmed, a manual response process — isolating the affected endpoint, resetting credentials, blocking the sender domain on FortiMail, pushing the malicious IP to the FortiGate blocklist — can take 30–60 minutes. Under CERT-In’s 6-hour reporting window, that delay is costly. Ora’s SOAR automates these response actions via pre-built playbooks and connectors, including direct integration with FortiGate to push blocklists automatically. The analyst approves or reviews; the platform executes. That automation is what makes the CERT-In timeline realistic for most organisations, not a stretch goal.
If your organisation is dealing with alert fatigue or wants to explore how this platform maps to your current environment, PJ Networks can walk you through a scoped deployment assessment.
Combating AI-powered phishing is not a single-product problem. Here is a prioritised checklist for Indian enterprise security teams:
p=reject policy for your primary sending domain — this prevents attackers from spoofing your domain to target your own employees or partners.AI has given threat actors capabilities that were previously available only to nation-state actors — personalisation at scale, evasion of signature-based controls, and deepfake-augmented social engineering. For Indian enterprises, the combination of DPDP Act obligations, CERT-In reporting timelines, and a lean security workforce makes this a genuinely high-stakes challenge.
The answer is not a single product — it is a layered architecture: FortiMail for email-layer protection, ZTNA for identity-centric access control, a 24/7 NOC/SOC for human-in-the-loop response, and a unified SecOps platform like PrahiX Ora to correlate events and automate response at the speed the threat demands.
PJ Networks helps Indian enterprises design, deploy, and operate this architecture. If you are currently evaluating your email security posture or want to understand how your existing Fortinet investment can be extended to address AI-powered phishing, reach out to our team for a no-obligation consultation.