



Phishing has always been the attacker’s favourite first move. But the version arriving in corporate inboxes today is qualitatively different from the poorly-worded “Nigerian prince” emails of a decade ago. Generative AI has removed every friction point that once helped defenders filter signal from noise: grammatical errors, awkward phrasing, generic salutations, and copy-pasted templates are all gone. What lands now is a hyper-personalised, contextually accurate email that reads as if it was written by someone who knows the recipient’s role, their organisation’s ongoing projects, and even their internal jargon — because, increasingly, it was synthesised from publicly available LinkedIn profiles, annual reports, press releases, and social media.
For Indian enterprise IT and security leaders, this is not a hypothetical threat. CERT-In’s advisories through 2024 and 2025 document a sharp uptick in targeted phishing campaigns against the BFSI, pharma, and critical infrastructure sectors. The attack surface is wide: large workforces, high volumes of legitimate vendor communications, and the ongoing digitisation of business processes all create ideal conditions for social-engineering attacks to succeed.
This post breaks down how AI-powered phishing works, what the specific risks are for Indian organisations, and — critically — what a layered defensive architecture looks like when you move beyond legacy email filtering.
The economics of phishing changed the moment large language models became accessible. Where a sophisticated spear-phishing campaign once required a skilled social engineer spending hours researching a target and crafting bespoke lures, the same output can now be generated in minutes by an AI model fed with OSINT (open-source intelligence) scraped from public sources.
Automated tools scrape LinkedIn for employee names, titles, and tenure; parse company filings for project names and financial data; and harvest email patterns from breach databases. This intelligence feeds into LLM prompts that generate convincing, contextualised spear-phishing emails — at a volume that makes targeting every mid-level employee of a large organisation entirely feasible.
Email is only part of the picture. AI voice-cloning tools can replicate a senior leader’s voice from a few seconds of publicly available audio. Attackers combine a convincing email with a follow-up call from a “cloned” voice to authorise a fraudulent wire transfer — a pattern that has appeared in documented incidents in the UK, UAE, and increasingly in India. The attack is a direct evolution of business email compromise (BEC), accelerated by AI.
AI-generated phishing content is also specifically optimised to evade signature-based and reputation-based email security tools. Because each email is unique — no shared template, no reused malicious URL — hash-based blocklists provide no protection. Attackers are additionally using legitimate hosting infrastructure (SharePoint links, Google Docs, Cloudflare Workers) to redirect victims after the initial email clears the gateway.
Several structural factors amplify phishing risk in the Indian enterprise context:
There is no single control that defeats AI-generated phishing. The correct approach is a defence-in-depth stack where each layer catches what the previous one misses.
A next-generation email security gateway — PJ Networks deploys FortiMail for enterprise clients — does significantly more than legacy anti-spam filters. FortiMail’s sandboxing capability detonates suspicious attachments and URLs in an isolated environment before delivery, catching zero-day malware payloads. AI/ML-based impersonation detection analyses display name spoofing, lookalike domain names, and sender behaviour anomalies. Domain-based Message Authentication, Reporting, and Conformance (DMARC), combined with DKIM and SPF enforcement, prevents trivial domain spoofing — still the most common vector because many Indian organisations have not yet fully deployed these controls.
Outbound email scanning is equally important: if an attacker compromises an internal mailbox and uses it to phish employees or partners, outbound filtering detects unusual sending patterns and can quarantine the session.
Many phishing attacks succeed not at the email stage but at the link stage: a clean-looking email carries a link to a legitimate hosting platform, which then redirects to the malicious payload after the email gateway has already cleared it. FortiGate NGFW with FortiGuard URL categorisation and deep SSL inspection evaluates links at the point of click, even when the destination redirects through multiple hops. Blocking access to newly registered domains — a high-signal indicator of attacker infrastructure — catches a significant fraction of AI-generated phishing lures before the credential harvesting page loads.
Even when a phishing attack successfully harvests credentials, ZTNA limits the blast radius. By enforcing device posture checks, identity verification, and granular application-level access policies at every session — rather than granting broad network access on VPN connection — ZTNA prevents a stolen username and password from becoming a full network compromise. PJ Networks’ ZTNA deployments integrate with FortiGate and FortiClient to provide this continuous verification without degrading legitimate user productivity.
Technology controls alone are insufficient without human expertise watching for anomalies that rules miss. PJ Networks’ 24/7 Security Operations Centre monitors endpoints, email platforms, identity providers, and network traffic for indicators of phishing compromise — unusual login locations, credential stuffing patterns, mailbox forwarding rules created by unauthorised sessions, and lateral movement following a successful initial access. When an alert fires, the SOC team triages, investigates, and escalates within SLA, providing the contextualised human judgement that differentiates a genuine incident from a false positive.
One of the most common challenges enterprise clients describe is alert fatigue: individual security tools generate hundreds of events per day, but without correlation and context, the SOC analyst cannot determine which events represent a coordinated phishing-to-compromise chain and which are benign noise. This is the core problem that PrahiX Ora — a unified SecOps platform built by PrahiX Tech Pvt Ltd, which PJ Networks deploys and operates for clients — is designed to solve.
SIEM with Attack Storyline Reconstruction: Ora’s SIEM ingests logs from FortiGate, FortiMail, endpoint agents, identity providers, cloud workloads, and custom application sources. Correlation rules mapped to the MITRE ATT&CK framework automatically group related events — a suspicious email delivery, a link click, a new browser session from an anomalous location, and a mailbox rule creation — into a single attack storyline that the analyst can review at a glance rather than hunting across six separate consoles. Tiered log retention (hot, cold, and archive tiers) supports CERT-In’s direction on 180-day in-country log retention without requiring clients to over-provision expensive primary storage.
NMS for Full Network Visibility: Phishing attacks frequently pivot from the initially compromised endpoint to the broader network. Ora’s Network Management System provides unified observability across FortiGate firewalls, switches, wireless access points, and WAN/SD-WAN links. LLDP/CDP topology discovery and ML-based anomaly detection surface unusual east-west traffic flows — a signal that a compromised workstation is beginning lateral movement — at a stage where containment is still straightforward. This is especially valuable in multi-vendor estates where NOC visibility is otherwise fragmented across multiple vendor-specific dashboards.
Video Surveillance (VMS) for Physical-Digital Correlation: In manufacturing, retail, and multi-site enterprise deployments, a sophisticated attacker may combine a phishing compromise with physical access — tailgating into a server room, inserting a rogue device, or photographing sensitive material. Ora’s video surveillance (VMS) module integrates ONVIF, Hikvision, and Dahua cameras with video analytics, placing physical security events on the same operational timeline as network and endpoint alerts. A card-swipe anomaly correlated with a concurrent network login from an unfamiliar device is a much stronger indicator than either event in isolation.
SOAR for CERT-In Compliance: CERT-In’s 6-hour incident reporting window is genuinely demanding. Meeting it requires that detection, triage, scope assessment, and initial notification all complete within six hours of an incident occurring — not six hours after the morning shift arrives. Ora’s SOAR module automates initial response actions: isolating a compromised endpoint, pushing a blocklist update to FortiGate, suspending an Active Directory account pending investigation, and auto-populating the incident report template with all structured data collected to that point. This automation is what makes the CERT-In timeline realistic at scale. If your current process relies on manual steps at each stage, a tabletop exercise mapping actual clock times typically reveals significant gaps before any remediation even begins.
For clients who want to see how the platform fits their environment, PJ Networks can arrange a demonstration of Ora’s correlation and SOAR capabilities mapped to their specific technology stack. More information is available at ora.prahix.com.
While a full managed security programme provides the deepest protection, there are concrete steps every Indian enterprise should validate regardless of current security maturity:
p=none policy is not protection — it only monitors. Set p=quarantine or p=reject for your primary domain, and audit all sending sources before doing so.Despite best defences, some phishing attacks will succeed. The difference between a contained incident and a major breach is almost always the speed and quality of the response in the first few hours.
When a user reports clicking a suspicious link or entering credentials on an unexpected page, the immediate priorities are: disable the account and invalidate session tokens before the attacker can use them; determine whether any additional access was obtained; preserve evidence for forensic analysis and CERT-In reporting; and notify affected parties under your incident response plan. None of this can be done effectively when the SIEM, endpoint telemetry, and identity logs are spread across disconnected tools — which is precisely why the architecture investment upstream matters so much when the clock is running.
Not every enterprise starts from the same baseline. Organisations in early stages of security maturity should prioritise DMARC enforcement, MFA deployment, and staff awareness training — these deliver the highest risk reduction per rupee spent. Those with existing controls in place should focus on correlation: ensuring that email security, endpoint, identity, and network events are visible in a single platform and mapped to a common framework like MITRE ATT&CK so that multi-stage attacks are detected as campaigns, not as isolated noise.
For enterprises operating under CERT-In reporting obligations or managing sensitive data under the DPDP Act, the ability to detect, scope, and report a phishing-to-breach incident within the mandatory window is no longer optional — it is a compliance requirement. Automation is the only practical way to meet that window at scale.
AI-powered phishing is not a future threat — it is the operational reality facing Indian enterprise security teams today. The attackers’ efficiency advantage has grown substantially, but so has the capability of the defensive architecture available to defenders who invest in it. Layered email security, FortiGate NGFW with SSL inspection, ZTNA, and a 24/7 SOC operating a unified platform like PrahiX Ora significantly raise the cost and complexity of a successful phishing campaign against a well-defended organisation.
The organisations that will be most exposed over the next 12–18 months are those still relying on point-in-time controls — a legacy email gateway here, an endpoint agent there — without the correlation and automation needed to detect and respond at the speed AI-enabled attackers now operate.
Talk to PJ Networks: Whether you need a rapid assessment of your phishing defences, a DMARC deployment, or a managed SOC providing 24/7 monitoring, our team is ready to discuss your environment and recommend a right-sized programme. Visit pjnetworks.com to get in touch.