



A chief financial officer at a mid-sized Bengaluru manufacturer received an email last quarter that looked exactly like a message from their bank’s relationship manager. The language was impeccable, the signature block matched, and even the footer carried the bank’s correct regulatory disclaimer. The only giveaway — caught by an alert analyst reviewing a flagged alert — was a single-pixel mismatch in the sender domain.
That email was generated by a large language model. Welcome to the era of AI-powered phishing — the fastest-evolving threat vector facing Indian enterprises right now.
Traditional phishing relied on volume: blast millions of poorly written emails and hope a small percentage of recipients clicked. Detection was correspondingly simple — look for spelling errors, generic salutations, suspicious attachments.
AI-generated spear-phishing operates on an entirely different logic:
India’s digital economy has expanded faster than its security posture in many sectors. Several factors make Indian enterprises particularly attractive targets:
India processes over 15 billion UPI transactions per month. Finance teams at mid-market companies often authorise wire transfers through informal channels — a WhatsApp confirmation, a forwarded email. Attackers know this and craft scenarios that fit the pattern exactly.
The Digital Personal Data Protection Act, 2023, is driving organisations to rapidly expand their IT infrastructure. New cloud subscriptions, new SaaS onboarding, new vendor relationships — all create fresh phishing surfaces. An attacker who monitors a company’s DPDP-related job postings knows exactly which SaaS platforms are being evaluated.
India’s manufacturing and pharma export sectors rely on complex supplier ecosystems. A compromised email at Tier-2 or Tier-3 supplier can be used to redirect payments across the entire supply chain. CERT-In has issued advisories on exactly this threat pattern.
The cybersecurity workforce gap in India means many enterprises run lean SOC teams. An AI-assisted attacker can generate thousands of variants of the same phishing email in minutes; an under-resourced team cannot triage them all manually.
Legacy Secure Email Gateways (SEGs) rely heavily on signature-based detection and reputation scoring. Against AI-generated phishing, these controls are necessary but no longer sufficient. The 2025 threat requires a layered defence:
Modern email security platforms — including FortiMail, which PJ Networks deploys and manages — use machine-learning models trained on communication-pattern baselines. Rather than asking “does this email look like spam?” they ask “does the writing style, header metadata, sending infrastructure, and content deviate from this sender’s established pattern?” That behavioural approach catches AI-generated mails that pass every traditional content filter.
Many Indian organisations have published SPF and DKIM records but leave DMARC in monitoring-only mode (p=none) for years. That is not protection — it is wishful thinking. Strict DMARC enforcement (p=reject) combined with BIMI visual branding is now the baseline expectation for organisations that want inbox providers to treat their outbound mail as legitimate and block spoofed variants.
AI-generated phishing is increasingly sent from compromised legitimate accounts — suppliers, partners, even customers. Traditional IP reputation scoring will not catch these. Trust scoring must incorporate domain-age signals, header anomalies, and cross-tenant threat intelligence feeds.
The irony of the AI phishing era is that the best defence for human-targeted attacks remains human awareness — but the training content must also level up. Generic “look for spelling mistakes” training is counterproductive: it gives employees false confidence when the email they receive has no mistakes at all. Simulation programmes should now include AI-generated spear-phishing drills that test whether recipients notice contextual rather than grammatical anomalies.
No payment instruction above a threshold — especially to a new beneficiary or a changed bank account — should be authorised based on email alone. A mandatory callback to a known number (not one in the email) takes thirty seconds and blocks the most common BEC scenario entirely.
India’s CERT-In Directions of April 2022 require organisations to report cyber incidents — including phishing attacks that result in data compromise — within six hours of detection. AI-powered phishing complicates this timeline in two ways:
Organisations that cannot detect and contain a phishing compromise quickly enough to meet the six-hour reporting obligation need to rethink their SOC capabilities — not just their email filters.
When a phishing email is clicked, the email gateway is only the first line of detection. The real question is what happens next — credential theft, lateral movement, data exfiltration, or command-and-control check-in. Detecting and stopping that progression requires a platform that correlates signals across every layer of the environment. PrahiX Ora is the unified SecOps platform that PJ Networks deploys and operates for clients.
SIEM: Ora’s SIEM ingests log and event data from email gateways, endpoints, identity providers (Active Directory, Azure AD), firewalls, and cloud workloads into a single correlation engine. Correlation rules are mapped to MITRE ATT&CK — so when FortiMail flags a suspicious email and minutes later an endpoint makes an outbound connection to a known C2 domain, Ora reconstructs the attack storyline graphically. For Indian enterprises, this matters beyond detection: CERT-In’s 180-day in-country log retention direction requires that every alert, event, and correlated incident be stored in a compliant, queryable archive. Ora’s tiered hot/cold/archive retention model is designed with exactly that regulatory expectation in mind.
NMS: Phishing campaigns often include a network reconnaissance phase after the initial credential harvest. Ora’s Network Management System provides unified observability across firewalls, switches, wireless APs, and WAN/SD-WAN links — making it possible to spot anomalous lateral movement or unusual DNS queries that suggest post-compromise activity. LLDP/CDP topology discovery and ML-based anomaly detection mean the platform can flag deviations from normal traffic baselines even in complex, multi-vendor environments where NOC visibility is otherwise fragmented.
Video Surveillance (VMS): For manufacturing plants, retail chains, and multi-site estates where physical and network security converge, Ora’s video surveillance (VMS) capability integrates ONVIF/Hikvision/Dahua camera management with video analytics under the same operations view. A phishing-enabled insider threat — someone who gains access to a facility using credentials obtained via social engineering — shows up in both the network log and the physical access record, correlated in one platform.
SOAR: The six-hour CERT-In reporting window is only achievable with automation. Ora’s SOAR module includes pre-built playbooks for phishing response — isolating compromised endpoints, revoking active sessions, pushing updated IP and domain blocklists directly to FortiGate firewalls, and assembling the incident evidence package needed for CERT-In notification. Manual SOC workflows cannot reliably hit that timeline; automation can. If your team is manually triaging phishing alerts and manually assembling incident reports, that is the first process the SOAR module replaces.
If you want to understand how PrahiX Ora fits your specific environment, reach out to PJ Networks for an assessment conversation.
If you are an IT leader or CISO at an Indian enterprise, here is a prioritised action list for the AI phishing threat:
PJ Networks helps Indian enterprises build and operate layered email security stacks — from FortiMail gateway configuration and DMARC enforcement to 24/7 SOC monitoring that connects email alerts to broader threat intelligence. Our managed ZTNA deployments ensure that even when an attacker obtains valid credentials, they cannot freely traverse an organisation’s internal network.
The AI phishing threat is real, it is escalating, and it is specifically targeting the channels that Indian enterprises rely on most. If you would like to assess your current posture or review your incident response readiness against CERT-In timelines, contact PJ Networks for a structured conversation with our security team.