



Phishing has always been the attacker’s favourite entry point—cheap to launch, hard to stop, and devastatingly effective. But in 2026, the threat has evolved dramatically. Generative AI now lets even low-skill threat actors craft hyper-personalised, grammatically perfect spear-phishing emails in seconds. The era of obvious “Dear Customer” scams is over; what replaces it is something far more dangerous: AI-generated pretexts so convincing that they fool not just employees but increasingly, enterprise email security gateways trained on older threat signatures.
For Indian enterprises—already under pressure from the DPDP Act, CERT-In’s mandatory incident reporting, and a rapidly expanding attack surface—AI-assisted phishing represents a category-1 threat. This post breaks down how these attacks work in 2026, what Indian organisations are getting wrong, and the layered defence architecture that actually stops them.
Traditional phishing relied on volume: send millions of generic lures and hope a small percentage clicked. AI changes the economics entirely. With access to LinkedIn profiles, public financial disclosures, press releases, and leaked data from previous breaches, attackers can now feed an LLM a target’s name, title, and business context and receive a bespoke email that references their CEO by name, quotes a real vendor relationship, or mimics the writing style of an internal communications template.
Most enterprise email security products were designed around signature-based detection and URL/attachment sandboxing. AI-generated phishing breaks both assumptions:
The result: gateway-only defences have measurable gaps. According to threat intelligence aggregators, BEC losses globally exceeded $55 billion cumulatively through 2023 (FBI IC3 data), and the trajectory in 2025-2026 points sharply upward—particularly for Asia-Pacific targets where SMBs and mid-market firms often lack advanced email security tooling.
India’s enterprise landscape amplifies the risk in several ways:
Under India’s Digital Personal Data Protection Act, 2023, a phishing-induced breach that exposes personal data of employees or customers is a notifiable event. Organisations must report to the Data Protection Board within prescribed timelines and demonstrate reasonable security safeguards. An email security gap that permitted the breach becomes exhibit A in any enforcement action. Penalties can reach ₹250 crore for significant failures.
CERT-In’s April 2022 directions require covered entities to report cyber incidents—including phishing attacks that result in data exposure or system compromise—within six hours of detection. For most organisations, that window is impossibly tight without automated detection and pre-built response workflows. AI-enhanced phishing that slips past the gateway and establishes a foothold may not be detected for days—long past the reporting deadline.
India’s GST portal, income-tax e-filing system, and banking integrations are frequent phishing targets. Attackers impersonate GSTN notices or banking alerts with remarkable accuracy because the official communications templates are publicly known. A finance team member who clicks a fake GSTN refund-status link has potentially handed over their credentials to an actor who can file fraudulent returns or initiate account-level fraud.
Stopping AI-powered phishing requires multiple, complementary controls—no single product is sufficient. Here is the architecture we deploy at PJ Networks for enterprise clients:
Fortinet’s FortiMail goes beyond legacy signature scanning. Key capabilities relevant to AI phishing defence:
We configure FortiMail in MTA mode for full visibility and control, with policy sets tuned to the client’s sector—stricter for finance, legal, and HR teams who are primary BEC targets.
Every Indian enterprise we audit has at least one sending domain with a missing or permissive DMARC record. A p=reject DMARC policy prevents external parties from receiving emails spoofed as your domain—closing the most common BEC vector. Implementing DMARC properly requires:
p=none (monitoring) and progressing to p=quarantine then p=reject over 4–6 weeks as reporting data confirms coverage.Security awareness training without simulated phishing campaigns is table-stakes compliance, not real defence. We run quarterly AI-generated phishing simulations—using the same LLM-assisted pretexting techniques attackers use—to test whether employees apply what they’ve learned. Reporting rates and click rates over time are KPIs reviewed with our clients’ IT leadership.
Even the best gateway and endpoint controls won’t catch every phishing email—some will reach inboxes, some users will click, and some will result in credential compromise. The question then becomes: how quickly can you detect and contain the breach?
For many Indian organisations, the honest answer is “days to weeks”—because alerts from FortiMail, FortiGate, Active Directory, and endpoint tools exist in separate consoles, with no unified view and no automated correlation. That gap is where breaches become breaches.
The platform we deploy and operate for clients is PrahiX Ora, built by PrahiX Tech Pvt Ltd. It brings four capabilities under one SecOps roof that are directly relevant to phishing response:
SIEM — Detect the post-click footprint: Ora’s SIEM ingests logs from FortiMail, FortiGate, endpoints, Active Directory, and cloud services, correlating events against MITRE ATT&CK techniques. When a user clicks a phishing link and the endpoint initiates an outbound connection to a C2 server, the SIEM surfaces that as a linked attack storyline—not three disconnected alerts in three separate tools. Tiered retention (hot/cold/archive) keeps logs available for the full 180 days that CERT-In’s in-country retention direction requires, with query performance maintained on hot-tier data for active investigations.
NMS — See lateral movement across your network: After a phishing foothold is established, attackers move laterally. Ora’s Network Management System provides unified observability across firewalls, switches, access points, and WAN/SD-WAN links. ML-based anomaly detection flags unusual east-west traffic patterns—a workstation that suddenly begins connecting to domain controllers it has never touched, for example—enabling SOC analysts to triage lateral movement before the attacker reaches high-value systems. In multi-vendor estates where NOC visibility is otherwise fragmented, this unified topology view is transformative.
Video Surveillance (VMS) — Physical and logical, one operations view: For manufacturing, retail, and multi-site clients, Ora’s video surveillance (VMS) module manages ONVIF/Hikvision/Dahua cameras alongside network security feeds. A phishing-enabled credential theft that leads to a physical access attempt—badge cloning, tailgating—can be correlated with network events in a single operations view. Physical and network security no longer live in siloed dashboards.
SOAR — Meet the 6-hour CERT-In window: CERT-In’s 6-hour incident reporting requirement is only realistic if large parts of the initial response are automated. Ora’s SOAR module provides playbook automation with pre-built connectors that can push blocklists to FortiGate the moment a phishing campaign’s IOCs are identified, disable compromised Active Directory accounts, isolate endpoints, and pre-populate the CERT-In report template with structured incident data. Automation is what makes 6-hour reporting a process rather than a fire drill.
If your organisation is managing FortiGate, FortiMail, and a mix of other security tools across a fragmented NOC/SOC environment, PrahiX Ora is worth a conversation. Reach out to PJ Networks to understand how we deploy and operate the platform for clients in your sector.
If you suspect an AI-generated phishing email has reached your users or resulted in a click:
AI-powered phishing is not a future threat—it is the present reality for Indian enterprise IT teams. The good news is that the defensive toolkit has also matured: FortiMail’s AI-assisted detection, properly enforced DMARC, phishing-resistant MFA, ZTNA conditional access, and unified SecOps through platforms like PrahiX Ora form a layered architecture that can detect and contain even sophisticated, AI-generated campaigns.
The organisations that will suffer the most in 2026 are those still relying on a single email gateway and annual security awareness training. The ones that will stay resilient are those that treat email security as a multi-layer programme—continuously tested, monitored 24/7, and integrated into a broader SOC response capability.
PJ Networks helps Indian enterprises design, deploy, and operate exactly this kind of layered defence—from FortiMail configuration and DMARC enforcement to 24/7 NOC/SOC monitoring and CERT-In-ready incident response. If your current email security posture hasn’t been audited in the last 12 months, speak to our team about a no-obligation assessment.