AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC

  • Home
  • AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and 24/7 SOC

Phishing has always been the attacker’s favourite entry point—cheap to launch, hard to stop, and devastatingly effective. But in 2026, the threat has evolved dramatically. Generative AI now lets even low-skill threat actors craft hyper-personalised, grammatically perfect spear-phishing emails in seconds. The era of obvious “Dear Customer” scams is over; what replaces it is something far more dangerous: AI-generated pretexts so convincing that they fool not just employees but increasingly, enterprise email security gateways trained on older threat signatures.

For Indian enterprises—already under pressure from the DPDP Act, CERT-In’s mandatory incident reporting, and a rapidly expanding attack surface—AI-assisted phishing represents a category-1 threat. This post breaks down how these attacks work in 2026, what Indian organisations are getting wrong, and the layered defence architecture that actually stops them.

How AI Has Transformed Phishing

Traditional phishing relied on volume: send millions of generic lures and hope a small percentage clicked. AI changes the economics entirely. With access to LinkedIn profiles, public financial disclosures, press releases, and leaked data from previous breaches, attackers can now feed an LLM a target’s name, title, and business context and receive a bespoke email that references their CEO by name, quotes a real vendor relationship, or mimics the writing style of an internal communications template.

Attack Patterns We’re Seeing in 2026

  • CEO fraud 2.0: AI-cloned executive writing styles used to authorise wire transfers or credential resets—indistinguishable from authentic correspondence without deep header analysis.
  • Vendor impersonation: Fake invoices from suppliers the target actually uses, with correct logo, GST numbers pulled from public registries, and plausible invoice amounts.
  • Regulatory lure campaigns: Fake CERT-In advisories or DPDP compliance notices with malicious PDF attachments or credential-harvesting portals—particularly effective against IT and legal teams under compliance pressure.
  • Multi-stage Business Email Compromise (BEC): Initial AI email establishes rapport; a follow-up requests a small, plausible action; a third-stage email delivers the real payload or financial request.
  • QR code phishing (Quishing): Embedding malicious QR codes in otherwise clean email bodies to bypass URL-scanning gateways—a technique that spiked in late 2025 and remains prevalent.

Why Legacy Email Gateways Are Failing

Most enterprise email security products were designed around signature-based detection and URL/attachment sandboxing. AI-generated phishing breaks both assumptions:

  • No malicious URLs in the initial email—just a persuasive message and a phone number or QR code.
  • No known-bad attachments—documents are clean until the victim enables macros or follows an embedded instruction.
  • Sender reputation is clean because attackers use lookalike domains registered days before the campaign, or compromise legitimate cloud mail infrastructure.
  • AI-generated prose produces no linguistic tells—grammar is perfect, context is accurate, urgency is calibrated to the target’s role.

The result: gateway-only defences have measurable gaps. According to threat intelligence aggregators, BEC losses globally exceeded $55 billion cumulatively through 2023 (FBI IC3 data), and the trajectory in 2025-2026 points sharply upward—particularly for Asia-Pacific targets where SMBs and mid-market firms often lack advanced email security tooling.

The Indian Context: Why This Matters More Here

India’s enterprise landscape amplifies the risk in several ways:

DPDP Act Liability

Under India’s Digital Personal Data Protection Act, 2023, a phishing-induced breach that exposes personal data of employees or customers is a notifiable event. Organisations must report to the Data Protection Board within prescribed timelines and demonstrate reasonable security safeguards. An email security gap that permitted the breach becomes exhibit A in any enforcement action. Penalties can reach ₹250 crore for significant failures.

CERT-In’s 6-Hour Reporting Mandate

CERT-In’s April 2022 directions require covered entities to report cyber incidents—including phishing attacks that result in data exposure or system compromise—within six hours of detection. For most organisations, that window is impossibly tight without automated detection and pre-built response workflows. AI-enhanced phishing that slips past the gateway and establishes a foothold may not be detected for days—long past the reporting deadline.

GST and Financial System Exposure

India’s GST portal, income-tax e-filing system, and banking integrations are frequent phishing targets. Attackers impersonate GSTN notices or banking alerts with remarkable accuracy because the official communications templates are publicly known. A finance team member who clicks a fake GSTN refund-status link has potentially handed over their credentials to an actor who can file fraudulent returns or initiate account-level fraud.

A Layered Defence Architecture That Works

Stopping AI-powered phishing requires multiple, complementary controls—no single product is sufficient. Here is the architecture we deploy at PJ Networks for enterprise clients:

Layer 1: FortiMail — Advanced Email Security Gateway

Fortinet’s FortiMail goes beyond legacy signature scanning. Key capabilities relevant to AI phishing defence:

  • FortiGuard Antispam + AI/ML content inspection: Behavioural analysis of message content, sender patterns, and header anomalies—not just signature matching.
  • Impersonation detection: Identifies display-name spoofing and lookalike domain attacks even when the sending IP is clean.
  • Outbreak protection: Quarantines messages matching emerging campaign patterns within minutes of FortiGuard intelligence updates—before traditional signatures are published.
  • Sandboxing via FortiSandbox integration: Detonates suspicious attachments and URLs in an isolated environment, catching zero-day payloads that evade static analysis.
  • DMARC, DKIM, SPF enforcement: Blocks sender-spoofed email at the gateway. This alone eliminates a large class of BEC attempts.
  • Encrypted traffic inspection: Analyses TLS-wrapped SMTP traffic to catch exfiltration attempts even when the channel is encrypted.

We configure FortiMail in MTA mode for full visibility and control, with policy sets tuned to the client’s sector—stricter for finance, legal, and HR teams who are primary BEC targets.

Layer 2: DMARC, DKIM, and SPF — The Non-Negotiable Baseline

Every Indian enterprise we audit has at least one sending domain with a missing or permissive DMARC record. A p=reject DMARC policy prevents external parties from receiving emails spoofed as your domain—closing the most common BEC vector. Implementing DMARC properly requires:

  • SPF records covering all legitimate sending sources (including SaaS tools, marketing platforms, ERP systems).
  • DKIM signing on all outbound mail.
  • DMARC starting at p=none (monitoring) and progressing to p=quarantine then p=reject over 4–6 weeks as reporting data confirms coverage.
  • DMARC reporting (RUA/RUF) routed to a monitoring service for ongoing visibility.

Layer 3: User Awareness — Simulation, Not Just Training

Security awareness training without simulated phishing campaigns is table-stakes compliance, not real defence. We run quarterly AI-generated phishing simulations—using the same LLM-assisted pretexting techniques attackers use—to test whether employees apply what they’ve learned. Reporting rates and click rates over time are KPIs reviewed with our clients’ IT leadership.

Layer 4: Endpoint and Identity Controls

  • MFA everywhere: Phishing-resistant MFA (FIDO2/hardware keys for privileged accounts) ensures that even a successful credential harvest doesn’t yield account access.
  • Conditional access: Zero Trust Network Access (ZTNA) policies that evaluate device health, location, and behaviour before granting access—so a compromised credential used from an unusual device triggers a step-up challenge.
  • Privileged Access Workstations (PAW): Finance, HR, and IT admin tasks performed only from hardened, monitored endpoints.

PrahiX Ora: Unified SecOps for Phishing Detection and Response

Even the best gateway and endpoint controls won’t catch every phishing email—some will reach inboxes, some users will click, and some will result in credential compromise. The question then becomes: how quickly can you detect and contain the breach?

For many Indian organisations, the honest answer is “days to weeks”—because alerts from FortiMail, FortiGate, Active Directory, and endpoint tools exist in separate consoles, with no unified view and no automated correlation. That gap is where breaches become breaches.

The platform we deploy and operate for clients is PrahiX Ora, built by PrahiX Tech Pvt Ltd. It brings four capabilities under one SecOps roof that are directly relevant to phishing response:

SIEM — Detect the post-click footprint: Ora’s SIEM ingests logs from FortiMail, FortiGate, endpoints, Active Directory, and cloud services, correlating events against MITRE ATT&CK techniques. When a user clicks a phishing link and the endpoint initiates an outbound connection to a C2 server, the SIEM surfaces that as a linked attack storyline—not three disconnected alerts in three separate tools. Tiered retention (hot/cold/archive) keeps logs available for the full 180 days that CERT-In’s in-country retention direction requires, with query performance maintained on hot-tier data for active investigations.

NMS — See lateral movement across your network: After a phishing foothold is established, attackers move laterally. Ora’s Network Management System provides unified observability across firewalls, switches, access points, and WAN/SD-WAN links. ML-based anomaly detection flags unusual east-west traffic patterns—a workstation that suddenly begins connecting to domain controllers it has never touched, for example—enabling SOC analysts to triage lateral movement before the attacker reaches high-value systems. In multi-vendor estates where NOC visibility is otherwise fragmented, this unified topology view is transformative.

Video Surveillance (VMS) — Physical and logical, one operations view: For manufacturing, retail, and multi-site clients, Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras alongside network security feeds. A phishing-enabled credential theft that leads to a physical access attempt—badge cloning, tailgating—can be correlated with network events in a single operations view. Physical and network security no longer live in siloed dashboards.

SOAR — Meet the 6-hour CERT-In window: CERT-In’s 6-hour incident reporting requirement is only realistic if large parts of the initial response are automated. Ora’s SOAR module provides playbook automation with pre-built connectors that can push blocklists to FortiGate the moment a phishing campaign’s IOCs are identified, disable compromised Active Directory accounts, isolate endpoints, and pre-populate the CERT-In report template with structured incident data. Automation is what makes 6-hour reporting a process rather than a fire drill.

If your organisation is managing FortiGate, FortiMail, and a mix of other security tools across a fragmented NOC/SOC environment, PrahiX Ora is worth a conversation. Reach out to PJ Networks to understand how we deploy and operate the platform for clients in your sector.

Incident Response Checklist: AI Phishing Suspected

If you suspect an AI-generated phishing email has reached your users or resulted in a click:

  1. Immediately quarantine: Pull the suspect email from all mailboxes (FortiMail quarantine management or Microsoft Purview) before further spread.
  2. Identify the blast radius: How many users received it? Did anyone click? Did anyone enter credentials?
  3. Reset affected credentials: Force password reset and revoke all active sessions for any account that may have been compromised.
  4. Check FortiGate logs: Look for outbound connections to the domain/IP referenced in the phishing email in the last 24–72 hours.
  5. Isolate compromised endpoints: If a device downloaded a payload or exhibits unusual process behaviour, isolate it from the network immediately.
  6. Document for CERT-In: Begin populating the incident report. If personal data is involved, assess DPDP Act notification obligations in parallel.
  7. Conduct a post-incident review: How did the email bypass controls? What DMARC/SPF gaps were exploited? Update gateway policies and simulation templates accordingly.

Conclusion: Defence Must Evolve as Fast as the Attack

AI-powered phishing is not a future threat—it is the present reality for Indian enterprise IT teams. The good news is that the defensive toolkit has also matured: FortiMail’s AI-assisted detection, properly enforced DMARC, phishing-resistant MFA, ZTNA conditional access, and unified SecOps through platforms like PrahiX Ora form a layered architecture that can detect and contain even sophisticated, AI-generated campaigns.

The organisations that will suffer the most in 2026 are those still relying on a single email gateway and annual security awareness training. The ones that will stay resilient are those that treat email security as a multi-layer programme—continuously tested, monitored 24/7, and integrated into a broader SOC response capability.

PJ Networks helps Indian enterprises design, deploy, and operate exactly this kind of layered defence—from FortiMail configuration and DMARC enforcement to 24/7 NOC/SOC monitoring and CERT-In-ready incident response. If your current email security posture hasn’t been audited in the last 12 months, speak to our team about a no-obligation assessment.

Leave a Reply

Your email address will not be published. Required fields are marked *