AI-Powered Phishing in 2026: How Indian Enterprises Can Fight Back

  • Home
  • AI-Powered Phishing in 2026: How Indian Enterprises Can Fight Back
AI-Powered Phishing in 2026: How Indian Enterprises Can Fight Back

Generative AI has fundamentally changed the phishing threat landscape. In 2024 and 2025 we saw the first wave of AI-crafted spear-phishing emails that bypassed conventional Secure Email Gateways — and by 2026, that capability is now table-stakes for any moderately funded threat actor. For Indian enterprise security teams, the implications are severe. Attackers can now craft highly personalised, grammatically flawless lures in Hindi, Telugu, Tamil, or Marathi at industrial scale, targeting finance controllers, HR managers, and C-level executives with uncanny accuracy.

This post walks through what AI-powered phishing looks like in practice, why legacy defences are struggling, and the concrete steps Indian CISOs and IT leaders can take — from email gateway hardening to FortiMail deployment to 24/7 SOC surveillance — to protect their organisations.

What Has Changed: AI-Augmented Phishing Anatomy

Traditional phishing relied on mass-blast, obviously templated emails. Detection was relatively straightforward: look for typos, unfamiliar sender domains, generic salutations, and suspicious hyperlinks. AI has dismantled each of those signals one by one.

Personalisation at Scale

Large Language Models can now ingest a target’s LinkedIn profile, public press releases, recent regulatory filings, and news mentions to craft a contextually rich email. A phishing email to an Indian CFO might reference the company’s latest SEBI filing, name their actual auditor, and request a fund transfer under a plausible internal approval workflow — all in fluent English or even Hinglish. The attacker spends seconds; the SOC analyst spends minutes trying to rule it out.

Deepfake Audio and Video Lures

Several publicly reported incidents in 2025 involved deepfake voice calls — a threat actor impersonating a senior executive to instruct a finance team to approve a wire transfer. When combined with an AI-drafted email “follow-up,” the social engineering chain is devastatingly convincing. Indian BPO and BFSI firms have been disproportionately targeted, given their high-value transaction volumes and large distributed workforces.

Evasion of Legacy SEGs

AI-generated phishing emails score low on traditional rule-based filters because they lack the classic indicators: no mass-blast patterns, no known-bad domains in the first send, no attachment-based payload in the opening email. The payload arrives in a later stage — a benign-looking OneDrive or SharePoint link that redirects to a credential harvester after the initial inspection window has passed (a technique sometimes called “time-delayed redirection”).

The Indian Enterprise Context: Amplifying Factors

Several factors make Indian enterprises particularly attractive targets and add complexity to defence:

  • Rapid digital transformation: Cloud adoption accelerated during and after the pandemic. Hybrid work means more entry points, more SaaS credentials in scope, and more reliance on email-based workflows that attackers exploit.
  • DPDP Act compliance pressure: The Digital Personal Data Protection Act, 2023 imposes strict obligations around breach notification and personal data security. A successful phishing compromise leading to a data breach now carries regulatory consequence — not just reputational damage.
  • CERT-In 6-hour reporting window: Under CERT-In’s April 2022 directions, organisations must report incidents to India’s cyber security regulator within six hours of becoming aware. That window is extremely tight. If the SOC does not detect and triage a Business Email Compromise (BEC) within hours, the organisation may be in breach of reporting obligations before it even understands the scope of the attack.
  • Shortage of skilled analysts: The global cybersecurity talent gap is especially pronounced in India. Many mid-market enterprises simply do not have the in-house SOC capacity to monitor email telemetry 24/7 alongside network and endpoint events.

Why Traditional Email Security Is No Longer Enough

A basic Secure Email Gateway (SEG) filters on known malicious URLs, attachment hashes, and sender reputation. These controls remain necessary but are no longer sufficient. Consider the attack chain:

  1. The attacker registers a lookalike domain (e.g., pjnetworks-india.com) days or weeks before the campaign. By send time, it has a neutral reputation score.
  2. The initial email carries no malicious payload — just a plausible business request and a link to a legitimate cloud storage service.
  3. The cloud storage link hosts a document containing a macro or a credential harvester redirect, injected after the SEG has scanned and cleared the email.
  4. The target clicks, enters credentials, and the attacker has valid session tokens — bypassing MFA if the attacker uses an adversary-in-the-middle proxy (AiTM phishing).

Defending against this chain requires controls at multiple layers: pre-delivery (domain reputation, sender authentication), post-delivery (URL re-evaluation, sandboxing), and detection-and-response (correlating email events with identity and endpoint telemetry in real time).

FortiMail: Advanced Email Security for Indian Enterprises

PJ Networks deploys and manages Fortinet FortiMail as a cornerstone of enterprise email security. FortiMail goes substantially beyond a basic SEG:

Multi-Layer Antiphishing Engine

FortiMail combines AI/ML-based content analysis, FortiGuard threat intelligence (updated in real time), sender domain reputation, and SPF/DKIM/DMARC enforcement. Critically, it performs URL rewriting and time-of-click re-evaluation — so even if a link was clean at delivery, clicking it triggers a fresh sandbox check against the latest threat intelligence. This directly addresses the time-delayed redirection technique described above.

Business Email Compromise Detection

FortiMail includes heuristics specifically tuned for BEC — detecting display-name spoofing, lookalike domains, and impersonation of internal executives. For Indian enterprises where wire transfer fraud via email is a known risk vector, this protection is directly relevant.

Integrated with the Fortinet Security Fabric

Because FortiMail shares threat intelligence with FortiGate next-generation firewalls, FortiAnalyzer, and FortiSIEM, a malicious indicator discovered in the email stream can be automatically pushed to network-layer controls within minutes — not after a human analyst has reviewed it. This Fabric integration is a meaningful operational advantage for organisations that have already standardised on Fortinet.

Deployment Flexibility

FortiMail can be deployed as an on-premises appliance, a virtual machine, or a cloud-hosted service (FortiMail Cloud). For Indian enterprises with data localisation considerations under the DPDP Act, on-premises or private-cloud options allow email metadata and logs to remain in-country — supporting compliance without sacrificing protection capability.

Combining FortiMail with 24/7 SOC: Why Integration Matters

Technology alone is insufficient. AI-generated phishing is sophisticated enough that some attacks will inevitably reach the inbox. What matters then is how fast an organisation detects and contains.

PJ Networks operates a 24/7 NOC/SOC that integrates email telemetry from FortiMail alongside network events from FortiGate, endpoint events, and identity logs. When FortiMail flags a suspicious email — or when a user reports a suspected phish — our SOC analysts triage it against the wider threat picture in real time. Did the sender domain appear in any DNS queries across the network in the last 24 hours? Has any endpoint made an outbound connection to the linked infrastructure? Is there lateral movement evidence consistent with a successful credential harvest?

That correlation is what converts a phishing detection into a contained incident. Without it, even a capable email security platform generates alerts that queue up for a morning review — long after the attacker has moved.

PrahiX Ora: Unified SecOps That Ties the Threat Picture Together

For organisations that want end-to-end visibility beyond just email, PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd that PJ Networks deploys and operates for clients. It brings together four capabilities that are directly relevant to combating AI-powered phishing:

SIEM — Log and Event Correlation: Ora’s SIEM ingests logs from FortiMail, FortiGate, Active Directory, cloud identity providers, and other sources. Correlation rules mapped to the MITRE ATT&CK framework — specifically the Initial Access and Credential Access tactics most relevant to phishing — surface attack storylines graphically, showing the analyst how an email event connects to a subsequent credential use attempt. For compliance, Ora supports tiered retention (hot/cold/archive) aligned to CERT-In’s direction for 180-day in-country log retention, which is non-negotiable for regulated Indian enterprises.

NMS — Network Observability: When a user clicks a phishing link, the first network event is typically a DNS query followed by an outbound HTTP/S connection to attacker infrastructure. Ora’s NMS provides unified observability across firewalls, switches, and WAN/SD-WAN links, with ML-based anomaly detection that can flag unusual outbound connection patterns in near real time. For organisations with multi-vendor network estates — common in Indian enterprises where NOC visibility is often fragmented across teams — this unified view is operationally critical.

Video Surveillance (VMS): For manufacturing, retail, and multi-site Indian enterprises, Ora’s video surveillance (VMS) module integrates physical security camera management (ONVIF, Hikvision, Dahua) with network security operations under a single pane. While phishing is a digital threat, physical security breaches — such as a threat actor gaining building access through a social engineering pretext — are sometimes a companion to cyber attacks. Seeing both domains in one operations view removes the blind spot between IT security and physical security teams.

SOAR — Automated Response: This is perhaps the most directly relevant capability for phishing response. When a phishing incident is confirmed, a manual response process — isolating the affected endpoint, resetting credentials, blocking the sender domain on FortiMail, pushing the malicious IP to the FortiGate blocklist — can take 30–60 minutes. Under CERT-In’s 6-hour reporting window, that delay is costly. Ora’s SOAR automates these response actions via pre-built playbooks and connectors, including direct integration with FortiGate to push blocklists automatically. The analyst approves or reviews; the platform executes. That automation is what makes the CERT-In timeline realistic for most organisations, not a stretch goal.

If your organisation is dealing with alert fatigue or wants to explore how this platform maps to your current environment, PJ Networks can walk you through a scoped deployment assessment.

Practical Steps Indian CISOs Should Take Now

Combating AI-powered phishing is not a single-product problem. Here is a prioritised checklist for Indian enterprise security teams:

Email Authentication Hardening

  • Enforce DMARC with a p=reject policy for your primary sending domain — this prevents attackers from spoofing your domain to target your own employees or partners.
  • Audit all third-party senders in your SPF record; remove stale entries that create alignment failures.
  • Enable BIMI (Brand Indicators for Message Identification) if your mail platform supports it — it adds a visual trust signal for recipients of your outbound emails.

URL Re-evaluation and Sandboxing

  • Ensure your email security solution rewrites and re-evaluates URLs at time of click, not only at delivery. This is the primary control against time-delayed redirection.
  • Enable sandboxing for all Office documents and PDFs, especially from external senders.

User Awareness — Upgraded for the AI Era

  • Traditional phishing simulations that test “did you spot the typo?” are no longer sufficient. Run simulations using AI-quality lures — contextually relevant, well-written, personalised to the target’s role.
  • Train employees specifically on out-of-band verification: if an email requests a fund transfer or a change to payment details, verify by phone using a number from the corporate directory — not from the email itself.
  • Include deepfake audio awareness in your security training. Employees need to know that a voice call can be synthesised.

Identity and MFA Hardening

  • Deploy phishing-resistant MFA (FIDO2 / hardware security keys or passkeys) for high-value accounts — finance, HR, IT administrators. SMS-based OTP and TOTP are both vulnerable to AiTM phishing proxies.
  • Implement Conditional Access policies that flag logins from new devices or unusual geolocations for step-up authentication.

Incident Response Preparedness

  • Document and drill your BEC incident response procedure — specifically, the steps to confirm whether a wire transfer has been executed and how to recall it (time is everything here).
  • Map your CERT-In 6-hour reporting workflow: who declares the incident, who notifies CERT-In, what data goes into the initial report. This should be a documented playbook, not an ad-hoc decision under pressure.

Conclusion: Outpacing the Attacker Requires Automation and Expertise

AI has given threat actors capabilities that were previously available only to nation-state actors — personalisation at scale, evasion of signature-based controls, and deepfake-augmented social engineering. For Indian enterprises, the combination of DPDP Act obligations, CERT-In reporting timelines, and a lean security workforce makes this a genuinely high-stakes challenge.

The answer is not a single product — it is a layered architecture: FortiMail for email-layer protection, ZTNA for identity-centric access control, a 24/7 NOC/SOC for human-in-the-loop response, and a unified SecOps platform like PrahiX Ora to correlate events and automate response at the speed the threat demands.

PJ Networks helps Indian enterprises design, deploy, and operate this architecture. If you are currently evaluating your email security posture or want to understand how your existing Fortinet investment can be extended to address AI-powered phishing, reach out to our team for a no-obligation consultation.

Leave a Reply

Your email address will not be published. Required fields are marked *