



In early 2026, a senior finance executive at a Bengaluru-headquartered manufacturing group received a WhatsApp voice note. The voice — unmistakably his CFO’s — instructed him to urgently wire ₹3.2 crore to a vendor account. The CFO was, in reality, on a flight with his phone switched off. The voice was a deepfake, synthesised from publicly available earnings-call recordings in under four hours using off-the-shelf AI tooling. The transfer went through before anyone noticed.
This is not a hypothetical. Incidents of this type are being reported with increasing frequency across Indian banking, manufacturing, and IT services sectors. The convergence of large language models (LLMs), voice-cloning APIs, and commodity phishing infrastructure has crossed a threshold: attackers no longer need nation-state resources to mount highly convincing, personalised attacks at scale.
Modern AI-assisted social engineering is not simply a “better phishing email.” It operates across multiple layers:
LLMs can ingest a target organisation’s public footprint — LinkedIn profiles, press releases, MCA filings, regulatory disclosures, earnings call transcripts — and generate detailed, accurate social graphs of the organisation within minutes. Attackers know your reporting lines, your vendors, your ongoing projects, and your language patterns before they send a single message.
Traditional phishing relied on generic templates. AI-generated spear-phishing crafts messages that reference real internal projects, mimic individual writing styles, and arrive through channels the target actually uses. A procurement manager might receive a purchase-order query that correctly names the supplier relationship, the contract reference number (scraped from a public tender portal), and the approving officer’s name.
Voice cloning models now require as little as fifteen seconds of clean audio to produce a convincing facsimile. Combined with real-time voice conversion, attackers can conduct live phone calls impersonating known individuals. Video deepfakes, while computationally heavier, are increasingly used in “executive verification” scenarios during wire-transfer fraud. Text-based personas — fake employees, fake vendors, fake auditors — are generated and maintained across weeks-long email threads.
AI-assisted campaigns automatically rotate sending infrastructure, rephrase lures to evade signature-based filters, and test deliverability against common gateway stacks before the campaign goes live. The cost of iterating an attack has dropped to near zero.
India’s threat surface carries several characteristics that amplify exposure to AI-assisted social engineering:
As described in the opening example: AI voice clones impersonate executives, auditors, or regulators to authorise fraudulent transactions or extract credentials. Mitigation requires out-of-band verification protocols — a pre-agreed code word or callback to a registered number — for any instruction involving funds movement or access changes.
Attackers create email personas indistinguishable from real vendors: same domain structure (slight homoglyph substitution), identical email signature blocks, ongoing reference to real contract history. Finance and procurement teams must validate payment-detail changes through direct, independent contact rather than replying to the requesting thread.
Phishing pages are now generated dynamically — personalised to each recipient with their name, their organisation’s real branding pulled from public sources, and context-aware prompts. Legacy URL-filtering is insufficient. Browser-isolation, MFA on all critical systems, and FIDO2/passkey adoption are the effective mitigations.
Financial services companies and large B2B platforms using video-based identity verification face a specific threat: deepfake avatars passing liveness checks. Liveness-detection vendors are in an active arms race with generative-AI tooling; enterprises must treat video verification as one factor, not a standalone proof of identity.
Defending against AI-powered social engineering requires controls at three levels: people, process, and technology.
India’s CERT-In mandate requires organisations to report a broad range of cyber incidents within six hours of detection. AI-powered social engineering incidents — particularly those involving business email compromise, fraudulent fund transfers, or data exfiltration enabled by credential phishing — fall within the reportable categories.
The six-hour window creates two problems for under-resourced security teams: first, detecting that a social engineering event has occurred (the “realisation gap” is often days, not hours); second, assembling the evidence required for a coherent incident report within the reporting window.
Organisations that lack continuous log visibility and automated incident timelines will routinely miss CERT-In deadlines — not from bad intent, but from the practical impossibility of reconstructing events manually under time pressure.
Effective CERT-In compliance requires automated log correlation, pre-built incident-report templates, and a SOC team that can generate a timeline and root-cause hypothesis within hours of a confirmed incident. This is a technology and operational problem, not merely a policy one.
For organisations defending against AI-powered social engineering, visibility and speed are everything. The attacker’s edge is in obfuscation and pace; the defender’s edge must be in detection coverage and automated response. This is where the platform we deploy and operate for clients — PrahiX Ora, built by PrahiX Tech Pvt Ltd — plays a material role in our client engagements.
SIEM with attack storyline reconstruction: Ora’s SIEM ingests logs from email gateways, identity providers, endpoint agents, firewalls, and cloud platforms, correlating events against MITRE ATT&CK rules to reconstruct attack timelines as graph-based storylines rather than flat log tables. When a social engineering event is followed by credential use from an anomalous location, the SIEM surfaces the full chain — not isolated alerts. Ora’s tiered retention architecture (hot, cold, and archive tiers) supports CERT-In’s 180-day in-country log-retention direction, ensuring that historical evidence is available when an incident is discovered weeks after it occurred.
NMS for unified observability: Social engineering often precedes lateral movement across a fragmented network estate. Ora’s network management capability provides a unified observability view across FortiGate firewalls, switches, wireless APs, and WAN/SD-WAN links — with LLDP/CDP topology discovery and ML-based anomaly detection. When a phished user’s device begins scanning internal segments or exfiltrating data over an unusual path, the NMS raises the deviation before it becomes a full-scale breach.
Video surveillance (VMS) for physical context: For manufacturing, retail, and multi-site clients, Ora’s video surveillance (VMS) capability integrates physical camera feeds — ONVIF, Hikvision, Dahua — with network event data under one operational view. When an after-hours badging anomaly correlates with a simultaneous network access event, physical and cyber context arrive together in a single alert, rather than requiring separate investigations by separate teams.
SOAR for CERT-In timeline compliance: The six-hour CERT-In reporting window is where automation earns its keep. Ora’s SOAR playbooks automate the initial response steps that consume the most time: isolating affected accounts, pushing updated blocklists to FortiGate, generating draft incident reports pre-populated with log evidence, and notifying the response team with structured case data. Automation is what makes the six-hour timeline realistic for a lean security team facing a complex incident.
If your organisation is evaluating how to operationalise these capabilities, PJ Networks can provide a readiness assessment and a deployment roadmap tailored to your environment.
No single control defeats AI-powered social engineering. Resilience comes from layering controls so that the failure of any one does not result in catastrophic loss. The following 90-day sequence is designed for Indian enterprise security teams working within realistic budget and resource constraints:
AI-powered social engineering is not a future threat — it is the present threat landscape for Indian enterprises in 2026. The barriers that once limited sophisticated attacks to nation-state actors or well-funded criminal groups have collapsed. The same tools that drive productivity in legitimate AI applications are being weaponised against finance teams, executives, and IT administrators.
The organisations that will limit their exposure are those that treat social engineering as a systemic risk requiring systemic controls — not an awareness problem solved by a quarterly training module. That means verified procedures, layered technical controls, continuous detection, and the operational capacity to respond within hours, not days.
PJ Networks helps Indian enterprises build and operate exactly that capability — from FortiGate-anchored network security and ZTNA deployment, to 24/7 NOC/SOC coverage and incident response. If you are assessing your organisation’s readiness against AI-assisted threats, reach out to our team for a structured conversation.