



Generative AI has fundamentally changed the economics of phishing. Until 2023, mass-phishing campaigns were distinguishable by broken grammar, implausible sender names, and generic lures. Today, threat actors use large-language models to craft hyper-personalised spear-phishing emails at industrial scale—harvesting context from LinkedIn, company newsrooms, and regulatory filings to produce messages that look as if they were written by a colleague, a SEBI relationship manager, or the CIO’s executive assistant.
For Indian enterprises, the threat is especially acute. India’s rapid digitisation—UPI, GST portals, SEBI disclosures, DPDP notifications—has created a rich public corpus that attackers mine to make lures credible. CERT-In’s 2024 annual report flagged phishing and business email compromise as the two most commonly reported incident categories. The question is no longer whether your organisation will be targeted; it is whether your controls can keep pace with adversaries who now iterate faster than most human security teams.
Traditional phishing relied on volume—blast millions of generic emails and hope a fraction of recipients clicked. AI-powered phishing inverts this model. Attackers now:
Two frameworks frame the compliance obligation for Indian enterprises when a phishing attack succeeds:
Under CERT-In’s 2022 directions (amended 2023), organisations must report incidents—including phishing attacks that result in data exfiltration or system compromise—within six hours of detection. For a phishing attack that triggers a credential harvest or wire-transfer fraud, the clock starts the moment your SOC identifies it. Six hours sounds generous until you factor in log collection, evidence preservation, containment, and stakeholder notification. Without automated detection and a rehearsed response playbook, organisations routinely miss the window and face regulatory scrutiny.
The Digital Personal Data Protection Act 2023 requires data fiduciaries to notify the Data Protection Board and affected data principals in the event of a personal data breach. A phishing attack that exposes employee, customer, or patient records triggers DPDP obligations in addition to CERT-In reporting. Organisations that lack adequate controls—email authentication, endpoint protection, SIEM visibility—face compounded regulatory risk: the breach itself plus evidence of deficient security posture.
Understanding the attack chain helps security teams identify the right control points.
Attackers scrape LinkedIn for employee names and roles, pull company filings from the MCA portal, and monitor news for events (mergers, audits, leadership changes) that create plausible pretexts. AI tools aggregate and summarise this data in minutes.
An LLM generates a personalised email that references the target’s role, recent company events, and a credible call to action—clicking a link, opening an attachment, or initiating a payment. Tone, vocabulary, and even signature style match the impersonated sender.
Attackers register lookalike domains (e.g., pjnetworks-helpdesk.com instead of pjnetworks.com), obtain free TLS certificates, and configure redirect chains to evade URL filtering. The landing page may be a pixel-perfect clone of a corporate VPN portal or payment gateway.
Emails arrive in targets’ inboxes. Because the content is contextually relevant and grammatically clean, recipients are far more likely to interact. Credentials are harvested in real time and immediately used—often within minutes—before the victim or SOC becomes aware.
With valid credentials, attackers access cloud applications, corporate email, and internal systems. They establish persistence, escalate privileges, and exfiltrate data or deploy ransomware—completing the kill chain before detection in many cases.
No single control stops AI phishing. The effective defence is a layered architecture that raises the cost and complexity of every stage of the attack chain.
A surprising proportion of Indian enterprises still lack DMARC enforcement. Without it, attackers can spoof your own domain to target your suppliers, customers, or staff. Enforce DMARC at p=reject, configure DKIM signing for all outbound mail streams, and monitor aggregate reports weekly. This is foundational and non-negotiable.
Signature-based filtering is insufficient. Solutions that apply behavioural analysis—examining writing style, sender reputation, link redirection chains, and attachment sandboxing—detect AI-generated lures that no signature database covers. FortiMail, which PJ Networks deploys and manages, combines ML-based content analysis with real-time threat intelligence feeds and integration with FortiSandbox for zero-day attachment detonation.
Credential theft loses most of its value if MFA is enforced. FIDO2/WebAuthn hardware keys are phishing-resistant; TOTP and push-based MFA reduce risk but remain vulnerable to real-time relay attacks (adversary-in-the-middle). Prioritise FIDO2 for privileged accounts and executive roles.
Even with valid credentials, attackers should not gain blanket access to the network. ZTNA enforces continuous verification—device posture, identity, location, time of access—and limits lateral movement by granting access only to specific applications, not the entire network segment. PJ Networks’ ZTNA deployments routinely reduce the blast radius of credential compromise from network-wide to a handful of scoped applications.
Generic phishing simulations using 2018-era templates no longer reflect what employees actually encounter. Effective programmes now use AI-generated lures in simulations—the same techniques attackers use—so employees practise recognising the real thing. Combine simulations with micro-training modules triggered immediately after a near-miss click.
Detecting and responding to AI phishing at the speed the threat demands requires more than point products—it requires a unified operations platform that correlates signals across email, endpoint, network, and identity in real time. PrahiX Ora, built by PrahiX Tech Pvt Ltd and deployed and operated by PJ Networks for our managed clients, provides exactly that unified SecOps capability.
SIEM – Correlation Across Every Signal Source: A phishing campaign leaves traces across multiple systems: email gateway logs, proxy logs, endpoint telemetry, Active Directory authentication events, and cloud application audit trails. PrahiX Ora’s SIEM ingests these streams, applies correlation rules mapped to MITRE ATT&CK tactics (particularly Initial Access T1566 and Credential Access T1556), and reconstructs the full attack storyline as a graph—showing which user clicked, what credential was harvested, and where it was subsequently used. Tiered hot/cold/archive retention supports CERT-In’s direction that logs be retained in-country for 180 days, ensuring your evidence chain is intact when regulators ask.
NMS – Network-Level Anomaly Detection: Phishing is rarely a standalone event. Once credentials are compromised, attackers move laterally—and that movement shows up as anomalies on the network: unusual port access, unexpected east-west traffic between systems that normally don’t communicate, DNS queries to newly registered domains. PrahiX Ora’s NMS provides unified observability across firewalls, switches, wireless APs, and WAN/SD-WAN links. ML-based anomaly detection flags deviations from baseline behaviour, and LLDP/CDP topology discovery means even complex multi-vendor estates—the reality for most Indian enterprises—are visible under a single operations pane.
Video Surveillance (VMS) – Physical Correlations: Physical access and cyber access are increasingly correlated in sophisticated attacks. Insider threats and social engineering sometimes involve physical presence—a contractor plugging in a rogue device, or an attacker who tailgates into a server room after stealing an access badge via a phishing-obtained identity. PrahiX Ora’s video surveillance (VMS) module, compatible with ONVIF, Hikvision, and Dahua camera systems, brings physical security events into the same operations view as network and cyber events. For manufacturing sites, retail chains, and multi-site enterprises, this unified view supports investigations that would otherwise require manually correlating badge-access logs with network logs across separate systems.
SOAR – Automated Response Within the CERT-In Window: CERT-In’s six-hour reporting window is achievable only with automation. When PrahiX Ora’s SIEM detects a confirmed phishing-originated credential compromise, the SOAR module executes pre-approved playbook steps within seconds: disabling the compromised account in Active Directory, pushing the attacker’s IP and domain to the FortiGate blocklist, isolating the affected endpoint from the network, and generating a draft incident report populated with the relevant log evidence. The security analyst reviews and approves rather than starting from scratch. That difference—automation handling the mechanical steps so humans handle the decisions—is what makes the six-hour window realistic rather than aspirational. If your team is managing phishing incidents manually today, we recommend scheduling a PrahiX Ora demonstration to see what automated response looks like in practice.
Technology controls are necessary but not sufficient. You need a documented, rehearsed playbook that your team can execute under pressure. Here is a framework:
PJ Networks operates 24/7 NOC and SOC services for Indian enterprises, covering FortiGate NGFW management, FortiMail, SD-WAN, and ZTNA deployments, with PrahiX Ora as the unified SecOps backbone for managed clients. Our SOC analysts are trained specifically on AI phishing patterns, with detection rules updated as new techniques emerge.
If your organisation wants a phishing risk assessment, an email architecture review, or a demonstration of what automated incident response looks like in practice, our security advisory team is available for a no-obligation conversation. The threat is evolving faster than point products can track—the right response is a managed, layered, continuously updated security posture.
AI phishing is not a future threat. It is the current threat. The organisations that respond fastest—with better controls and faster detection—are the ones that contain breaches before they become headlines.