AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence

  • Home
  • AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence
AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence
AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence
AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence
AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence
AI-Powered Phishing in 2025: How Indian Enterprises Can Fight Back with FortiGate and SOC Intelligence

In the first half of 2025, India’s Computer Emergency Response Team (CERT-In) logged a sharp rise in AI-generated phishing campaigns targeting mid-market and enterprise organisations. Unlike the poorly-worded bulk emails of a decade ago, today’s lures are indistinguishable from legitimate vendor correspondence—correct logos, personalised salutations, plausible invoice numbers, and even synthetic voice notes to back up the written bait. For Indian enterprise IT and security leaders, the old email-gateway perimeter is no longer enough.

Why AI-Powered Phishing Is a Different Problem

Traditional phishing relied on scale: send a million emails and a fraction of recipients will click. AI-powered phishing inverts that model. Large language models can scrape a target’s LinkedIn profile, press releases, and industry associations to craft a message that references a genuine supplier relationship, a recent tender, or an upcoming regulatory deadline. Defenders face a signal-to-noise problem: the malicious email looks and reads exactly like a legitimate one.

The threat is compounding across several dimensions:

  • Generative text bypass: Static signature-based filters trained on historical phishing vocabulary miss brand-new, contextually coherent lures.
  • Voice and deepfake escalation: Attackers follow an email with a synthetic voice call impersonating a CFO or procurement lead, dramatically increasing wire-transfer authorisation rates.
  • Supply-chain pivot: Rather than targeting large enterprises directly, adversaries compromise a smaller vendor’s email infrastructure and send malicious payloads from a trusted domain your gateway already whitelists.
  • Multi-stage payloads: Initial attachments may be entirely benign; the actual malware retrieves itself from a cloud storage link hours or days after delivery, evading sandbox detonation timeouts.

The Indian Enterprise Risk Landscape

India’s digital economy is a high-value target for several structural reasons. Rapid cloud adoption by manufacturing, BFSI, and logistics companies has outpaced security maturity in many organisations. The Digital Personal Data Protection (DPDP) Act, 2023 now places explicit accountability on data fiduciaries; a successful phishing attack that leads to a breach can trigger mandatory CERT-In reporting within six hours and potential regulatory action under DPDP. At the same time, legacy on-premises infrastructure and multi-vendor network estates create seams in visibility that attackers know how to exploit.

The RBI has issued multiple advisories on vishing (voice phishing) campaigns targeting banking customers and fintech employees. SEBI-regulated entities face similar threats aimed at extracting MNPI or gaining access to trading platforms. In manufacturing, IP theft via spear-phishing is a growing concern as Indian companies scale up R&D operations.

How FortiGate Provides First-Line Defence

PJ Networks deploys FortiGate Next-Generation Firewalls as the core enforcement layer for enterprise clients. For AI-powered phishing, the relevant FortiGate capabilities are:

FortiMail Integration and Sandboxing

FortiMail—deployed in conjunction with FortiGate—applies AI-assisted analysis to inspect message structure, header anomalies, sending infrastructure reputation, and embedded URLs in real time. Suspicious attachments are detonated in FortiSandbox, which can detect delayed-retrieval payloads by extending observation windows and monitoring outbound callback behaviour.

DNS Sinkholing and Category Filtering

FortiGate’s DNS filter intercepts lookups to newly registered domains, fast-flux infrastructure, and categorised phishing hosts. Because AI-generated campaigns often lean on freshly registered lookalike domains (e.g., vendor-invoice[.]in registered the morning of an attack), catching the lookup before the payload lands is a material defensive win.

SSL/TLS Deep Inspection

More than 85% of phishing payloads now travel over HTTPS. FortiGate’s SSL inspection decrypts and re-inspects traffic inline, feeding full URL paths and file content into the Intrusion Prevention System and Web Filter engines without creating blind spots on encrypted channels.

Threat Intelligence Sharing via FortiGuard

FortiGuard Labs continuously publishes updated intelligence on phishing infrastructure, malware signatures, and behaviour indicators. FortiGate appliances consume these feeds automatically, shrinking the window between attacker infrastructure standing up and your firewall blocking it.

Why 24/7 NOC/SOC Coverage Is Non-Negotiable

Technical controls alone cannot close the gap. AI-generated phishing campaigns are designed to probe for the specific moment a gateway is misconfigured, a rule set is stale, or an analyst is overwhelmed by alert volume. PJ Networks’ 24/7 NOC/SOC model addresses each of these failure modes:

  • Continuous rule tuning: Threat intelligence is only valuable if it is operationalised. Our SOC team reviews FortiGate policy exceptions, whitelists, and bypass rules on a rolling basis so attackers cannot exploit outdated allow-list entries.
  • Behavioural anomaly triage: A user logging in from Chennai at 09:00 IST and then accessing a SharePoint folder from Frankfurt at 09:05 IST is a credential-compromise indicator that rules alone will not surface. Human analysts reviewing UEBA outputs make the call.
  • Incident containment under CERT-In timelines: The six-hour mandatory reporting window under CERT-In’s 2022 directions is extremely narrow. A staffed SOC with pre-approved containment runbooks—isolate the endpoint, revoke the credential, block the C2 domain—can act within minutes, not hours.
  • Executive and finance desk protection: Spear-phishing against CFOs and authorised signatories warrants enhanced monitoring. Our SOC maintains watch on high-privilege accounts and flags anomalous access patterns for immediate escalation.

ZTNA: Containing the Blast Radius After a Credential Is Stolen

Even with the best gateway and SOC coverage, a sophisticated AI-crafted lure may occasionally succeed. Zero Trust Network Access (ZTNA) limits what an attacker can do with a stolen credential. Rather than granting broad VPN-style access to the corporate network, ZTNA enforces continuous, per-session authentication and authorisation, restricting lateral movement to only the specific applications and data the legitimate user is entitled to access.

PJ Networks deploys Fortinet’s ZTNA solution, integrated with FortiGate and FortiAuthenticator. Key architectural points:

  • Device posture checks at every session establishment—unmanaged or non-compliant devices are blocked before they touch internal resources.
  • Micro-segmentation policies that prevent an attacker who compromises an accounts-payable workstation from pivoting to ERP systems or development environments.
  • Application-level access logging that gives the SOC a clear trail for forensic reconstruction—critical for DPDP breach notification obligations.

PrahiX Ora: Unified SecOps Visibility Across the Kill Chain

Understanding a phishing attack in isolation is not enough. Security teams need to see the complete attack timeline—from the initial email delivery to the first beacon call to any lateral movement—stitched together across logs from firewalls, endpoints, email gateways, and identity providers. PrahiX Ora is the unified SecOps platform we deploy and operate for clients to provide exactly this visibility.

PrahiX Ora is built by PrahiX Tech Pvt Ltd; PJ Networks is its primary field deployment and operations partner. The platform integrates four capability pillars that are directly relevant to AI-powered phishing response:

SIEM: Attack Storyline Reconstruction

Ora’s SIEM module ingests logs from FortiGate, FortiMail, endpoint agents, identity providers, and cloud access logs into a centralised pipeline. Correlation rules mapped to the MITRE ATT&CK framework automatically tag and cluster related events—so a suspicious email delivery, a sandbox alert, and a DNS lookup to a new domain three hours later are presented as a single attack storyline rather than three independent alerts. For Indian organisations, this matters operationally: CERT-In’s direction on 180-day in-country log retention is met by Ora’s tiered retention architecture (hot, cold, and archive storage), keeping forensic data available for post-incident investigation without ballooning on-premises storage costs.

NMS: Network Observability Across a Multi-Vendor Estate

Many Indian enterprise networks are multi-vendor by history—legacy Cisco routing infrastructure alongside FortiGate firewalls and third-party wireless access points. Ora’s Network Management System provides unified observability across this heterogeneous estate using LLDP/CDP topology discovery and ML-based anomaly detection. When a phishing-delivered RAT begins beaconing, anomalous outbound traffic patterns surface in the NMS before they register as a full alert, giving analysts early warning. Auto-healing policies can quarantine a suspicious network segment without waiting for manual intervention.

Video Surveillance (VMS): Correlating Physical and Network Events

Phishing is not always purely digital. Insider-threat scenarios often involve a physical access event—a visitor in a server room, a USB drop in a car park—paired with a malicious email. Ora’s video surveillance (VMS) module manages ONVIF, Hikvision, and Dahua cameras with integrated video analytics, bringing physical and network security events into a single operations view. For manufacturing plants, retail chains, and multi-site enterprises, this convergence closes a blind spot that siloed physical-security and IT-security teams cannot cover independently.

SOAR: Making the CERT-In Six-Hour Window Realistic

CERT-In’s requirement to report a cyber incident within six hours of detection is ambitious when response actions are manual. Ora’s SOAR module changes the calculus with pre-built playbook automation and connectors to FortiGate and other enforcement points. When the SIEM identifies a credential compromise following a phishing event, an automated playbook can simultaneously: disable the affected Active Directory account, push a blocklist update to FortiGate for the attacker’s known C2 infrastructure, isolate the affected endpoint, and open a timestamped incident ticket—all within minutes. Analysts focus on triage and executive communication rather than running scripts. That is what makes a six-hour reporting window achievable rather than aspirational.

Practical Steps for Indian Enterprise Security Teams

If you are reviewing your organisation’s posture against AI-powered phishing, the following checklist is a useful starting point:

  • Audit your email gateway configuration. Confirm DMARC, DKIM, and SPF are enforced for both inbound and outbound mail. Impersonation of your own domain by attackers targeting your supply chain is a real attack vector.
  • Enable sandboxing for all attachment types. PDF, Office documents, and archive files are the most common delivery mechanisms. Ensure sandbox observation windows are set to detect delayed-retrieval payloads.
  • Review your SSL inspection policy. Any exemptions (banking sites, healthcare portals) should be documented, justified, and reviewed quarterly. Attackers deliberately host payloads on domains that commonly appear in bypass lists.
  • Implement ZTNA for remote access. Replace legacy SSL VPN with ZTNA, starting with privileged users and finance personnel who are highest-value targets for business email compromise follow-on attacks.
  • Define and rehearse your CERT-In reporting workflow. Know which team member is designated as the point of contact for CERT-In reporting, what templates are available, and which systems will provide the log exports needed for the report.
  • Conduct tabletop exercises specifically on AI-phishing scenarios. Include a scenario where a supplier’s email domain is compromised. Test whether your SOC’s detection playbook would catch a lure arriving from a previously trusted sender.
  • Validate log retention posture. Confirm that logs from all relevant systems—firewall, email, endpoint, identity—are being retained for at least 180 days in an in-country location consistent with CERT-In guidance.

Where PJ Networks Fits

PJ Networks designs, deploys, and operates managed security infrastructure for Indian enterprises across manufacturing, BFSI, logistics, healthcare, and IT/ITeS sectors. Our service stack—FortiGate NGFW, FortiMail, ZTNA, and 24/7 NOC/SOC operations supported by the PrahiX Ora platform—is specifically assembled for the threat environment Indian organisations face today.

We do not sell technology and leave clients to operate it. Every deployment comes with continuous monitoring, policy tuning, threat intelligence operationalisation, and direct CERT-In compliance support. If your organisation is re-evaluating its phishing defence posture in light of the AI-generated threat wave, we are happy to conduct a no-obligation assessment of your current email security and gateway configuration.

To speak with a PJ Networks security architect, contact us at pjnetworks.com/contact.

Leave a Reply

Your email address will not be published. Required fields are marked *