AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC

  • Home
  • AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC
AI-Powered Phishing Attacks in 2026: How Indian Enterprises Can Fight Back with FortiMail and Managed SOC

Phishing has always been the attacker’s weapon of first resort. But 2026 is different. Generative AI has collapsed the cost of producing highly personalised, grammatically perfect, culturally localised lure emails — in any Indian language — to near zero. What once required a skilled social engineer now runs at cloud-API prices. The result: Indian enterprises are facing a wave of AI-crafted spear-phishing and Business Email Compromise (BEC) attempts that legacy email gateways were never designed to stop.

This post walks through what AI-assisted phishing looks like in practice, why traditional filters are failing, what a layered email-security and SOC response looks like, and how PJ Networks helps clients operationalise it end-to-end.

Why AI Changes the Phishing Threat Calculus

Classic phishing detection depended on tell-tale signals: awkward grammar, generic salutations, suspicious sender domains, and recycled lure templates. Security teams trained employees to spot these cues, and gateway filters catalogued known-bad signatures.

Generative AI strips away most of those signals:

  • Perfect language quality. Large language models produce fluent English, Hindi, Tamil, Gujarati, and Marathi text indistinguishable from a native speaker. Employees who learned to spot typos as red flags lose that heuristic entirely.
  • Deep personalisation at scale. Scraped LinkedIn profiles, company websites, and public regulatory filings give attackers enough context to craft emails that reference the recipient’s actual role, current projects, or reporting manager — at zero marginal cost per target.
  • Dynamic payload variation. AI-generated campaigns mutate subject lines, body text, and attachment names continuously, evading signature-based detection.
  • Voice and video cloning for hybrid attacks. BEC campaigns in 2025-26 increasingly pair an AI-generated email with a synthetic voice call that mimics the CFO — reinforcing urgency to transfer funds or share credentials.

CERT-In’s quarterly advisories through late 2025 and early 2026 have repeatedly flagged spear-phishing as the dominant initial access vector across Indian critical infrastructure and BFSI incidents. The threat is not theoretical.

What AI Phishing Looks Like: Common Attack Patterns

Pattern 1: Vendor Impersonation with Legitimate-Looking Domains

Attackers register lookalike domains — swapping characters, adding hyphens, or using country-code TLDs — and send emails that exactly mirror a vendor’s visual identity. With AI generating the body copy, even a finance team member who “knows” the vendor can be deceived into approving a fraudulent invoice. Indian mid-market and enterprise organisations that rely on email-based payment approvals are particularly exposed.

Pattern 2: HR and Payroll Redirect Attacks

A common pattern targets HR portals and payroll systems. An AI-crafted email arrives from what appears to be an employee, requesting a bank account change before the next salary run. The request cites plausible life events and uses correct internal terminology scraped from public job descriptions. Without multi-factor verification workflows, these attacks succeed at an alarming rate.

Pattern 3: Executive Compromise and BEC

Attackers monitor publicly available executive communications — LinkedIn posts, earnings call transcripts, press releases — and craft emails that mimic writing style and ongoing business context. A forged thread from the “Managing Director” requesting urgent wire transfer to a new vendor account for a live project is extraordinarily difficult for a junior accounts executive to challenge.

Pattern 4: Phishing-as-a-Service Targeting Indian Verticals

Underground markets now offer AI phishing toolkits pre-configured for Indian banking portals, GST portals, MCA21, and popular ERP systems used by Indian enterprises. These lower the barrier further, extending sophisticated attacks to opportunistic criminal groups.

Why Traditional Email Gateways Are No Longer Enough

Most organisations still rely on a combination of spam filters, domain reputation checks, and URL sandboxing. These controls remain necessary — but they are no longer sufficient:

  • No malicious attachment, no malicious URL. Many AI phishing campaigns use clean emails that simply direct the recipient to call a number or reply — bypassing link scanners entirely.
  • Legitimate infrastructure. Attackers increasingly send from compromised legitimate Microsoft 365 or Google Workspace tenants, carrying valid DKIM and SPF records that reputation filters pass.
  • Zero-day social engineering. AI-generated lures have no prior signature in threat-intelligence feeds. By the time a signature is published, the campaign has concluded.

Effective defence requires moving from reactive signature-matching to behavioural analysis, communication-graph anomaly detection, and human-in-the-loop SOC triage for high-risk messages.

A Layered Defence: FortiMail, DMARC, and 24/7 SOC

Layer 1: FortiMail — Advanced Threat Protection at the Gateway

Fortinet’s FortiMail integrates multiple detection engines that complement traditional reputation filtering:

  • Sandbox detonation (FortiSandbox integration). Attachments and URLs are detonated in a contained environment; verdict-based delivery holds suspicious mail for analyst review.
  • Outbreak protection. FortiGuard Labs’ real-time threat intelligence feeds push new signatures within minutes of campaign detection globally — reducing the window during which novel lures reach inboxes.
  • Impersonation detection. FortiMail analyses sender display names, reply-to addresses, and header chains against known executive identities and trusted vendor lists, flagging mismatches before delivery.
  • Content disarm and reconstruction (CDR). Documents are stripped of active content (macros, embedded scripts, OLE objects) and rebuilt as clean copies — removing the threat even if a malicious attachment slips past other checks.
  • DMARC, DKIM, and SPF enforcement with reporting. FortiMail enforces and generates aggregate DMARC reports, giving security teams visibility into all sources sending on their domain — essential for discovering shadow-IT email use and detecting domain spoofing attempts against partners.

Layer 2: DMARC at a Verified Enforcement Level

Many Indian enterprises still have DMARC at p=none — monitoring only, with no rejection of spoofed mail. Moving to p=quarantine or p=reject closes the spoofing vector for your own domain. PJ Networks typically executes this in a phased programme: audit authorised sending sources, resolve DKIM alignment for each, then escalate policy. The full cycle typically takes six to twelve weeks for complex organisations with multiple ESPs, CRMs, and marketing automation platforms sending on behalf of the domain.

Layer 3: 24/7 SOC — Human Analysis for What Machines Miss

Gateway controls catch the bulk of commodity phishing. The AI-assisted, targeted campaigns that get through require SOC analyst triage. PJ Networks’ managed SOC provides:

  • Alert ingestion from FortiMail, endpoint telemetry, and identity systems (Azure AD / Google Workspace) into a unified view.
  • Priority-based triage: user-reported suspicious emails are re-analysed by analysts with full header forensics and cross-referenced against active campaign intelligence.
  • Rapid containment: when a phishing email is confirmed, the SOC mass-quarantines all copies across the tenant, resets compromised credentials, and initiates session revocation — all within the incident response SLA.
  • CERT-In 6-hour reporting support: documented incident timelines and IoC extraction to meet statutory reporting obligations under the CERT-In 2022 directions.

Employee Awareness: Still Essential, Now Different

The calculus on security awareness training has shifted. Telling employees to “look for bad grammar” is not just ineffective — it is actively misleading. Modern awareness programmes must teach different signals:

  • Process verification, not content inspection. Any email requesting a payment change, credential entry, or file download should trigger an out-of-band verification call — regardless of how legitimate the email looks.
  • Slow down on urgency. AI phishing relies heavily on manufactured urgency. Training that builds a reflex to pause and verify on any “urgent” financial or credential request is the most transferable skill.
  • Report-don’t-delete culture. Every suspicious email reported (even if it turns out to be benign) feeds the SOC and improves detection. A low-friction “Report Phishing” button integrated with the SOC workflow is worth the investment.
  • Simulated phishing with AI-quality lures. Awareness simulations should now use AI-generated, personalised lures — not generic templates — to accurately calibrate employee resilience against what attackers actually send.

PrahiX Ora: Unified SecOps Visibility Across Email, Network, and Endpoints

Email is the initial access vector — but phishing attacks don’t stop at the inbox. Once credentials are harvested or a malicious attachment executes, the attacker moves laterally, escalates privileges, and exfiltrates data. Containing a phishing-initiated compromise requires correlating email gateway alerts with network telemetry, endpoint behaviour, and identity-system signals in real time. This is where the platform we deploy and operate for clients — PrahiX Ora, built by PrahiX Tech Pvt Ltd — becomes operationally critical.

SIEM — Cross-source correlation with MITRE ATT&CK mapping. PrahiX Ora ingests logs from FortiMail, FortiGate, endpoint agents, Active Directory, and cloud identity providers. Correlation rules are mapped to MITRE ATT&CK techniques — so when a phishing email leads to a suspicious login from a new geography (T1078 – Valid Accounts) followed by an internal reconnaissance scan (T1046 – Network Service Scanning), the SIEM builds a graph-based attack storyline and surfaces it as a prioritised alert rather than three disconnected events. Tiered retention (hot/cold/archive) also supports CERT-In’s direction on 180-day in-country log retention without the cost of keeping everything on fast storage.

NMS — Network anomaly detection to catch lateral movement. After initial access, attackers move laterally — and that movement shows up as anomalies in network traffic. Ora’s NMS component provides unified observability across FortiGate firewalls, switches, wireless APs, and WAN/SD-WAN links. ML-based anomaly detection flags unusual east-west traffic patterns that traditional threshold alerts miss: a compromised workstation suddenly probing internal file shares, or a new device appearing on a VLAN it has no business accessing. For multi-vendor environments where NOC visibility is fragmented across separate tools, the LLDP/CDP topology discovery and network path tracing give analysts a single operational picture.

Video Surveillance (VMS) — Physical and digital under one operations view. For manufacturing plants, retail chains, and multi-site enterprises, Ora’s video surveillance (VMS) component — supporting ONVIF, Hikvision, and Dahua camera management with video analytics — brings physical security events into the same operations view. An after-hours credential use that correlates with a CCTV anomaly at the server room door is a far stronger signal than either event alone. This convergence is increasingly relevant as attacks pair physical access with cyber intrusion.

SOAR — Automating response within the CERT-In 6-hour window. When FortiMail detects a confirmed phishing campaign and the SIEM correlates it with successful credential use, the SOAR playbook fires automatically: harvested URLs are pushed as blocklist entries to FortiGate, the affected account is suspended in Active Directory, the user’s active sessions are revoked, and the incident ticket is created with pre-populated IoC evidence — all within minutes. CERT-In’s 6-hour incident reporting window is achievable only with this level of automation; manual response at scale is not fast enough. Pre-built SOAR connectors cover FortiGate, Microsoft 365, Google Workspace, and common ticketing platforms.

If you’d like to see how Ora performs against your current alert volumes and incident response timelines, we’re happy to arrange a demonstration with real-world scenario walkthroughs — reach out to the PJ Networks team.

DPDP Act and CERT-In Compliance Implications

AI-assisted phishing directly intersects with India’s regulatory obligations:

  • Digital Personal Data Protection (DPDP) Act, 2023. A phishing attack that results in credential theft and subsequent exfiltration of personal data constitutes a personal data breach under the DPDP Act. Data Fiduciaries must notify the Data Protection Board within the timeframe specified by the Board. Email security controls, combined with SOC detection and documented incident response, are foundational to evidencing the “reasonable security safeguards” standard the Act requires.
  • CERT-In Directions (2022). Any cyber security incident — including phishing-initiated compromise — must be reported to CERT-In within six hours of detection. The definition of “incident” is broad and includes attempts, not just successful breaches. Organisations must maintain logs sufficient for forensic reconstruction, and those logs must be retained for 180 days within Indian territory.

Meeting both obligations requires not just the right controls, but documented evidence that those controls are in place and operating. PJ Networks provides quarterly security posture reports and incident response documentation specifically structured to support DPDP and CERT-In compliance evidence.

Practical Steps: Where to Start This Week

If your organisation is reviewing email security posture in light of the AI phishing threat, here is a prioritised action list:

  1. Audit your DMARC policy. If it is at p=none, begin the alignment programme to move to enforcement. This closes the most exploitable spoofing vector.
  2. Review FortiMail or gateway configuration. Ensure sandbox integration is active, CDR is enabled for incoming Office documents and PDFs, and impersonation detection is tuned to your executive and vendor lists.
  3. Establish a user-report-to-SOC workflow. A phishing button that routes directly to analyst review — rather than a generic inbox — cuts triage time and improves detection of targeted campaigns.
  4. Update awareness training content. Retire “look for typos” messaging and replace it with process-based verification habits and simulations using AI-quality lures.
  5. Map your incident response runbook to the 6-hour CERT-In window. Identify which steps can be automated and where SOAR can accelerate the timeline.

How PJ Networks Can Help

PJ Networks delivers managed email security built on FortiMail and FortiGate, integrated with our 24/7 NOC/SOC operations centre. We handle FortiMail deployment and policy management, DMARC enforcement programmes, SOC alert triage and incident response, and CERT-In reporting support — so your security team can focus on governance and architecture rather than operational fire-fighting.

We also deploy and operate PrahiX Ora for clients that need unified SIEM, NMS, video surveillance (VMS), and SOAR under a single managed service.

If you are evaluating your organisation’s readiness against AI-powered phishing, PJ Networks offers an email security assessment covering gateway configuration, DMARC policy, SOC integration, and CERT-In alignment. Contact us to schedule a consultation with our security team.

Leave a Reply

Your email address will not be published. Required fields are marked *