



Phishing is no longer the clunky, typo-riddled scam it once was. In 2026, threat actors are deploying large language models to craft hyper-personalised spear-phishing emails that are grammatically flawless, contextually aware, and frighteningly convincing. For Indian enterprises — many of whom still rely on legacy secure email gateways tuned for yesterday’s threat landscape — this shift represents an urgent, material risk that demands immediate attention.
This post breaks down how AI-driven phishing works, what makes Indian organisations especially vulnerable, and the practical steps CISOs and IT heads can take right now to close the gap.
Traditional phishing campaigns were a numbers game: send millions of generic lures, harvest a small percentage of credentials, repeat. Detection was relatively straightforward — look for suspicious domains, poor grammar, mismatched sender names.
The new generation of attacks is fundamentally different. Adversaries use generative AI tools to:
The practical result: even security-aware employees are being fooled. A 2026 threat intelligence report by a leading global vendor noted a 340% increase in AI-assisted spear-phishing detections compared to 2024 — and that figure only captures what defenders caught.
India’s enterprise landscape has several structural factors that make AI-phishing particularly dangerous:
India’s boardrooms are highly hierarchical, and employees are culturally conditioned to act quickly on instructions from senior leadership without lengthy verification chains. AI-generated emails impersonating a CFO or Managing Director — requesting an urgent NEFT transfer or a confidential document — exploit this dynamic with devastating efficiency. Business Email Compromise losses in India crossed ₹1,200 crore in reported incidents in 2025 alone; the real number, accounting for under-reporting, is almost certainly far higher.
The Digital Personal Data Protection Act, 2023 places explicit accountability on data fiduciaries for breaches caused by inadequate security measures. A successful phishing attack that exposes customer PII or sensitive personal data carries regulatory, reputational, and financial consequences under the Act. The fact that an attacker used sophisticated AI is not a defence — the obligation is on the organisation to deploy commensurate controls.
Many mid-size and large Indian enterprises run a patchwork of on-premise Exchange servers, Microsoft 365 tenants, Google Workspace seats, and legacy mail relays — sometimes simultaneously. Each seam in this architecture is a potential policy gap that attackers probe. A message that passes SPF/DKIM on one relay may bypass additional scanning on another.
Under the CERT-In directions of April 2022, phishing incidents that result in data compromise must be reported within six hours. Organisations without automated detection and evidence collection pipelines routinely miss this window — and the penalties for late reporting are escalating.
Understanding the attack chain helps defenders choose the right countermeasures:
No single control stops AI-powered phishing. Effective defence is a stack:
Fortinet’s FortiMail platform, combined with FortiSandbox, provides a purpose-built layer for organisations that want deep content inspection without sacrificing mail latency. FortiMail’s AI-driven anti-phishing engine scores messages against hundreds of behavioural signals — not just known-bad URLs — including domain age, sender reputation drift, linguistic anomalies, and header inconsistencies that indicate AI-generated text. The FortiSandbox integration detonates suspicious attachments and URLs in an isolated environment before delivery.
For organisations running Microsoft 365 or Google Workspace, FortiMail can act as a journalling and re-scanning layer, adding a second inspection pass that native security tooling frequently misses.
A surprising proportion of Indian enterprises have published SPF records but never moved DMARC from p=none (monitor only) to p=quarantine or p=reject. This means the policy exists on paper but provides zero enforcement. Moving to a reject policy — carefully, with monitoring — closes the door on spoofed sender domains entirely.
For high-risk actions — wire transfers above a threshold, sensitive data requests, changes to vendor banking details — a mandatory out-of-band verification step (a phone call to a pre-established number, or a hardware token approval) breaks the attacker’s kill chain regardless of how convincing the email is.
Annual phishing simulations using 2019-era lure templates are no longer sufficient. Awareness programmes need to include AI-generated examples, executive impersonation scenarios, and multi-step attack simulations. The goal is not to trick employees into failure but to build genuine pattern recognition for the latest techniques.
Phishing that harvests credentials is only dangerous if those credentials grant meaningful access. Multi-factor authentication — ideally FIDO2 phishing-resistant tokens rather than OTP — eliminates the value of stolen passwords for most access scenarios. ZTNA policies that enforce least-privilege access limit the blast radius even when credentials are compromised.
Detecting and responding to an AI-phishing incident requires visibility across multiple data sources simultaneously — email gateway logs, endpoint telemetry, DNS query logs, identity provider events, and firewall traffic. Piecing these together manually during a live incident is simply not realistic within CERT-In’s six-hour reporting window.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner, and we operate the platform across our managed security client base.
SIEM: Ora’s SIEM ingests log streams from FortiMail, FortiGate, Microsoft 365 audit logs, Azure AD sign-in events, and endpoint detection tools into a single correlation engine. Detection rules are mapped to MITRE ATT&CK — the initial-access and credential-access tactics most relevant to phishing appear as prioritised alerts, not buried in noise. When a phishing campaign is detected, Ora’s graph-based attack storyline reconstruction stitches together the email delivery event, the credential submission, the subsequent login from an unusual geography, and the lateral movement attempt into a single, readable attack narrative. Crucially, Ora’s tiered retention architecture (hot, cold, and archive storage) supports CERT-In’s direction on 180-day in-country log retention — evidence is available when needed, without inflating operational storage costs.
NMS: Phishing that leads to lateral movement shows up in network flows. Ora’s network management system provides unified observability across FortiGate firewalls, switches, access points, and SD-WAN links. LLDP/CDP topology discovery means the platform knows the network’s actual shape — so an anomalous east-west connection between a workstation and a server that have never communicated before triggers an alert automatically. ML-based anomaly detection distinguishes the occasional legitimate outlier from the sustained C2 beaconing pattern that follows a successful credential compromise.
Video Surveillance (VMS): In manufacturing, retail, and multi-site enterprises, physical and logical security are increasingly correlated. Ora’s video surveillance (VMS) module — supporting ONVIF, Hikvision, and Dahua cameras — allows SOC analysts to correlate a physical access event (a contractor badge-swipe at an unusual hour) with the network activity from that workstation, providing context that pure SIEM analysis misses. This unified operations view is especially relevant for organisations investigating insider-assisted phishing, where an external attacker coordinates with a physical presence on site.
SOAR: The response side is where Ora’s value is most immediate. Pre-built playbooks automate the containment actions that matter: pushing attacker IP addresses and domains to FortiGate blocklists, disabling compromised AD accounts, quarantining affected mailboxes, and assembling the incident evidence package for CERT-In reporting. The six-hour reporting window is achievable when the platform is automating evidence collection and notification drafts — it is simply not realistic when analysts are manually pivoting across seven consoles and writing tickets by hand.
If your organisation is dealing with fragmented visibility across a multi-vendor estate and wants to understand what a managed deployment of Ora looks like in practice, we are happy to walk through a reference architecture. Contact PJ Networks to arrange a discussion.
Use this as a starting-point audit for your organisation:
p=reject for all owned domains (not just the primary)AI-powered phishing is not a future risk — it is the dominant attack vector today, and the sophistication gap between attacker capability and defender tooling is widening at organisations that have not refreshed their email security architecture in the last 18 to 24 months.
Indian enterprises face a dual obligation: managing the direct financial and operational risk of a successful phishing compromise, and meeting the DPDP Act and CERT-In compliance obligations that a data-exposing incident triggers. These two drivers, taken together, make the case for investment in modern email security and unified SecOps visibility compelling — and urgent.
PJ Networks works with Indian enterprise clients to deploy and manage layered email security (including FortiMail), ZTNA, and unified SecOps through the PrahiX Ora platform. If you would like to discuss a security architecture review or a gap assessment against the checklist above, reach out to our team.