



Phishing has always been the attacker’s favourite door. It is cheap, scalable, and disturbingly effective. But in 2025, something has changed at the root. Generative AI tools—the same technology powering productivity assistants—have given threat actors the ability to craft hyper-personalised, grammatically flawless lures at industrial scale. For Indian enterprises, where rapid digital adoption has expanded the attack surface faster than security maturity, this is not a distant problem. It is landing in inboxes today.
Traditional phishing campaigns were easy to spot: generic greetings, broken English, implausible urgency. Security awareness training taught employees to look for exactly those tells. AI-generated phishing eliminates them.
Modern campaigns now feature:
The result is a class of attack that defeats perimeter email filtering alone—and demands a layered, behavioural defence-in-depth approach.
India’s corporate sector presents a particularly attractive target. Several factors converge:
In 2024 alone, CERT-In processed thousands of phishing incident reports across banking, insurance, and manufacturing sectors. In 2025, threat intelligence sources indicate the volume and sophistication of these campaigns has continued to accelerate, with AI-assisted lures now accounting for a growing share of observed phishing kits.
Understanding the kill chain helps defenders disrupt it early.
Attackers harvest the target organisation’s email format (e.g., firstname.lastname@company.in) from LinkedIn, company websites, and leaked datasets. Generative AI tools then synthesise personalised lure content from this data at scale—one operator, thousands of bespoke emails.
Emails arrive from compromised legitimate domains (to pass SPF/DKIM checks) or from newly registered lookalike domains aged past reputation blacklists. Attachments are often password-protected archives—bypassing attachment scanners—with the password embedded in the email body so only a human (or an AI lure-reader) can open them.
Clicking the link lands the victim on a pixel-perfect clone of the corporate identity provider login page (Microsoft, Okta, Google). Real-time adversary-in-the-middle (AiTM) proxies capture not just credentials but live session tokens, bypassing MFA entirely. Alternatively, the payload drops a commodity RAT or an infostealer—enough to harvest VPN credentials and internal tool tokens.
Armed with a valid session, attackers move laterally through Microsoft 365 tenants, exfiltrate data to cloud storage, set inbox rules to hide their activity, and may trigger BEC wire-transfer requests before defenders notice anything unusual.
No single control stops AI-powered phishing. The defence must be layered, automated, and continuously tuned.
Fortinet’s FortiMail provides deep content inspection, sandboxing of suspicious attachments, and AI-assisted spam scoring. Critically, it enforces DMARC reject policies—blocking spoofed domains that attempt to impersonate your organisation. For organisations still on p=none DMARC policies, moving to enforcement is the highest-leverage quick win available.
Traditional VPN grants broad network access once credentials are verified. Zero Trust Network Access (ZTNA) decouples identity from access: every application session is independently authorised based on device posture, user role, and risk signals—even if an attacker holds a valid credential. PJ Networks deploys and operates ZTNA for clients using the FortiGate ZTNA fabric, reducing the blast radius of any compromised account to the minimum necessary access scope.
Standard OTP-based MFA is defeated by AiTM proxy attacks. Phishing-resistant options—FIDO2 hardware tokens, Windows Hello for Business, or certificate-based authentication—cannot be intercepted by a proxy because the credential is bound to the legitimate domain. For organisations where hardware tokens are not yet feasible across the workforce, number-matching MFA in Microsoft Authenticator is a meaningful interim hardening step.
Even when a credential and a session token are stolen, attackers leave behavioural traces: impossible travel, new device enrolments, atypical access-time patterns, unusual SharePoint or OneDrive download volumes. A staffed 24/7 SOC analysing identity telemetry in near-real-time can detect and contain these incidents before data exfiltration is complete. PJ Networks operates a 24/7 NOC/SOC service combining automated alerting with analyst-in-the-loop triage.
Annual phishing simulations no longer reflect the real threat. Effective 2025 awareness programmes send AI-generated simulated lures (using the same tools attackers use), personalised to each employee’s role and public footprint, with immediate teachable-moment feedback. The goal is conditioning reflexes—verify before you click, call before you wire—not just knowledge transfer.
Phishing campaigns generate signals across multiple layers simultaneously: email gateway logs, identity provider audit events, endpoint telemetry, network flow records. Correlating these signals manually is the bottleneck that lets attackers dwell undetected. This is the problem the platform we deploy and operate for clients—PrahiX Ora, built by PrahiX Tech Pvt Ltd—is designed to solve.
PrahiX Ora is a unified SecOps platform with four integrated pillars, each directly relevant to phishing-related incident detection and response:
If your organisation is dealing with fragmented security tooling and struggling to get correlated visibility across email, identity, network, and endpoint, we can walk you through how we deploy and operate the PrahiX Ora platform for clients of similar scale.
India’s regulatory environment adds legal weight to what is already a business-critical security problem.
Under the CERT-In Directions (April 2022), organisations must report cybersecurity incidents—including data breaches resulting from phishing—within six hours of becoming aware of them. AI-powered phishing attacks that result in credential theft and data exfiltration qualify. Organisations without automated detection and documented incident response procedures will find this six-hour window extremely difficult to meet.
The Digital Personal Data Protection (DPDP) Act, 2023 reinforces the accountability framework. Data Fiduciaries must implement “reasonable security safeguards” to protect personal data. A phishing breach that exposes employee PII, customer records, or financial data will be scrutinised against whether proportionate technical controls were in place. Demonstrating layered email security, MFA enforcement, ZTNA access controls, and continuous SOC monitoring supports compliance with these safeguards—though implementing these controls does not guarantee compliance and organisations should seek legal counsel on their specific obligations.
Key regulatory takeaway: Phishing is not just a security risk. It is a regulatory trigger. The six-hour CERT-In reporting clock starts when you become aware—which means your detection capability determines your compliance exposure.
If you are reviewing your phishing defences today, here are the highest-priority actions:
AI-powered phishing is not a future threat. It is the present reality for Indian enterprise security teams. The same generative AI capabilities that are reshaping business productivity have lowered the cost and raised the quality of adversarial campaigns to levels that make traditional perimeter defences insufficient on their own.
The response must be equally multi-layered: technical controls at the email gateway, identity, and network layers; automated detection and response through a 24/7 SOC; and an incident response capability fast enough to meet regulatory reporting obligations.
PJ Networks specialises in deploying and operating exactly this kind of defence for Indian enterprises—FortiGate NGFW and FortiMail for perimeter hardening, ZTNA for access control, and 24/7 NOC/SOC services backed by the PrahiX Ora unified SecOps platform. If you would like to assess your current phishing resilience or discuss how these services can be tailored to your environment, reach out to our team.