AI-Powered Phishing in 2025: How Indian Enterprises Can Stay Ahead

  • Home
  • AI-Powered Phishing in 2025: How Indian Enterprises Can Stay Ahead
AI-Powered Phishing in 2025: How Indian Enterprises Can Stay Ahead

Phishing has always been the most reliable entry point for attackers. But in 2025, it is no longer the clumsy, misspelled email of a decade ago. Generative AI has industrialised targeted deception, and Indian enterprise security teams are facing a qualitatively different threat — one that demands a rethinking of both awareness training and technical controls.

This post examines how AI-powered phishing works, why Indian organisations are a high-value target, and what practical steps your security operations team can take right now.

How Generative AI Has Changed Phishing

Traditional phishing relied on volume: spray millions of messages and hope a fraction land. Detection was relatively straightforward — poor grammar, suspicious sender domains, generic lures. Those tells are largely gone.

Modern AI-assisted phishing campaigns employ several techniques that make detection significantly harder:

  • Hyper-personalised lures: Attackers scrape LinkedIn, company websites, press releases, and earnings calls to craft emails that reference real colleagues, real projects, and real business language. A CFO receiving a message that references their company’s recent acquisition — using the correct deal name and the name of the legal counsel involved — is far more likely to act on it.
  • Voice and video cloning: Deepfake audio is now accessible to threat actors. Business Email Compromise attacks now sometimes include a follow-up voice note or even a short video clip purportedly from the CEO, raising the confidence threshold for victims dramatically.
  • Real-time adaptive lures: Some adversarial toolkits use LLMs to generate phishing content dynamically based on the target’s response or browsing context — making static signature detection ineffective.
  • Lookalike infrastructure at scale: Generating convincing lookalike domains, SSL certificates, and cloned login portals now takes minutes rather than days.

CERT-In has reported a significant uptick in sophisticated spear-phishing incidents targeting Indian financial services and critical infrastructure. The pattern is consistent with global trends: AI-assisted initial access followed by credential harvesting and lateral movement.

Why Indian Enterprises Are in the Crosshairs

India’s rapid digital transformation has outpaced security maturity in many sectors. Several factors make Indian enterprises particularly attractive targets:

  • UPI and digital payments infrastructure: The scale of digital transactions creates rich credential harvesting opportunities. Compromised finance team credentials can have immediate monetisation value.
  • Hybrid workforce with inconsistent device management: Many organisations still have employees operating on personal devices or under-managed endpoints, expanding the attack surface considerably.
  • Supply chain exposure: Indian IT service providers and BPOs hold credentials and access to dozens of global enterprise environments. Compromising one entity provides leverage across many client environments.
  • DPDP Act pressure: The Digital Personal Data Protection Act 2023 has concentrated minds on compliance, but some organisations are so focused on data residency and consent mechanisms that they are underinvesting in the threat detection and response capabilities that would actually prevent a breach.

The Kill Chain: What Happens After a Successful Phish

Understanding the post-compromise kill chain is essential for building effective detection. A typical AI-assisted phishing attack follows this pattern:

  1. Reconnaissance: OSINT gathering from LinkedIn, company filings, press releases, and dark web data broker purchases to build target profiles.
  2. Lure generation: AI-assisted email and attachment crafting, lookalike domain registration, and SSL certificate provisioning.
  3. Initial access: Credential harvesting via cloned login portal, or malicious attachment delivering a loader or remote access tool.
  4. Persistence: Installation of a remote access tool or abuse of legitimate cloud services (Microsoft 365, Google Workspace) to maintain access without triggering alarms.
  5. Lateral movement: Using harvested credentials to move through the network, escalate privileges, and identify high-value targets such as Active Directory, ERP systems, and treasury platforms.
  6. Exfiltration or ransomware deployment: Either data is exfiltrated quietly for monetisation, or ransomware is detonated after maximising dwell time and blast radius.

The window between initial compromise and detection remains dangerously wide for most Indian enterprises. Industry data consistently shows dwell times measured in weeks or months for sophisticated attackers — more than enough time to achieve objectives before any meaningful alert fires.

Technical Controls That Actually Help

No single control eliminates phishing risk. A layered approach is required across email, endpoint, network, and identity.

Email Gateway Hardening

A properly configured secure email gateway is the first line of defence. For organisations running FortiMail, this means enabling FortiGuard Antispam, URL scanning with sandboxing for every link click, and Outbreak Protection updates. Critically, DMARC enforcement — not just monitoring — should be in place for your own domain. This prevents your brand from being spoofed against your own users and partners.

Many Indian organisations have DMARC deployed in p=none monitoring mode and have never progressed to enforcement. This is a gap attackers actively exploit: spoofed emails from your own domain arrive in inboxes with full visual legitimacy. Moving to p=quarantine and then p=reject is one of the highest-impact, lowest-cost steps any organisation can take.

Endpoint Detection with Behavioural Analysis

Signature-based antivirus cannot catch AI-generated payloads on first encounter by definition — the payload has never been seen before. Endpoint detection that uses behavioural heuristics — watching for process injection, unusual parent-child process relationships, and credential access patterns — is essential. FortiEDR provides this capability and integrates with FortiGate’s Security Fabric to share threat intelligence in real time across network and endpoint telemetry.

Multi-Factor Authentication — Properly Deployed

MFA is necessary but not sufficient. Adversary-in-the-middle phishing kits can relay one-time passwords in real time, making push notification MFA bypassable for motivated attackers. Hardware security keys using FIDO2/WebAuthn are resistant to these attacks. Organisations handling sensitive financial or personal data should be migrating critical applications to phishing-resistant MFA now, not after an incident forces the issue.

Zero Trust Network Access

ZTNA replaces the assumption that users inside the corporate perimeter are trusted. Each access request is verified against identity, device health, and contextual signals. When a compromised credential is used from an unmanaged device or an unusual geography, ZTNA policies can deny access or trigger step-up verification — breaking the lateral movement phase of the kill chain before damage spreads.

PJ Networks implements Fortinet’s ZTNA solution as part of managed MSSP deployments, providing continuous verification without the friction and single-point-of-failure risk of traditional VPN architectures.

PrahiX Ora: Unified SecOps for Phishing Detection and Response

One of the hardest problems in phishing defence is not prevention — it is detection and response when prevention fails. That requires correlating signals across email, endpoint, network, and identity in near-real time. For organisations where these telemetry streams live in separate tools with separate consoles, that correlation happens too slowly, if at all.

PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. PJ Networks is its primary field deployment and operations partner — we deploy and operate Ora for clients as part of our managed security service. Ora addresses the detection and response challenge across four integrated pillars:

SIEM — Log correlation and attack storyline reconstruction: Ora ingests logs from email gateways, firewalls, endpoints, Active Directory, and cloud productivity platforms into a single correlation engine. Detection rules mapped to MITRE ATT&CK TTPs fire when phishing-related patterns emerge — for example, credential stuffing against a cloud identity provider shortly after a suspicious email event on the same user account. Ora’s graph-based attack storyline reconstruction links these disparate events into a coherent timeline, dramatically reducing the analyst time needed to understand scope and blast radius.

For Indian enterprises, Ora’s tiered retention architecture (hot/cold/archive) helps evidence compliance with CERT-In’s 180-day in-country log retention direction without requiring organisations to overprovision expensive always-on storage for every log source.

NMS — Network observability for lateral movement detection: After initial compromise, attackers move laterally. Ora’s network management module provides unified observability across FortiGate firewalls, managed switches, wireless access points, and WAN/SD-WAN links. LLDP/CDP-based topology discovery means the platform maintains an accurate map of your network — and ML-based anomaly detection can flag unusual east-west traffic patterns that would be invisible to teams managing multiple separate NOC tools. For multi-vendor estates where NOC visibility is fragmented, this unified view is itself a meaningful security improvement.

Video Surveillance (VMS) — Physical and cyber under one operations view: For manufacturing, retail, and multi-site organisations, Ora’s video surveillance module integrates ONVIF-compatible cameras including Hikvision and Dahua deployments with video analytics. The operational value is having physical security events — tailgating at a server room, after-hours badge access — visible in the same operations view as network and security alerts. A suspicious remote access event correlated with an after-hours physical access event at the same facility tells a more complete story than either signal alone.

SOAR — Automated response within CERT-In’s 6-hour window: CERT-In’s 6-hour incident reporting requirement for notifiable cyber incidents is one of the most operationally demanding compliance obligations facing Indian enterprises. Consistently meeting that window through manual investigation and drafting is not realistic without either significant analyst capacity or well-designed automation. Ora’s SOAR module provides pre-built playbooks and automated response actions — including pushing blocklists directly to FortiGate — that compress the time between detection and containment. If your organisation intends to consistently meet CERT-In’s reporting timeline, automation is not optional; it is the only path that scales. Talk to the PJ Networks team about how Ora can support your incident response posture.

The Human Layer: Awareness Training That Keeps Pace

Technical controls reduce risk but cannot eliminate it. The human layer remains critical, and traditional annual security awareness training is no longer adequate when the threat evolves monthly.

  • Simulated phishing with immediate feedback: Running regular simulated phishing campaigns using current lure templates that reflect what attackers are actually sending provides measurable data on organisational susceptibility and delivers learning at the moment of failure, when it is most impactful.
  • Role-specific training: Finance, HR, and executive assistants face different threat profiles than developers or operations staff. Generic training misses this entirely. Role-specific modules focused on the threats each group actually faces produce better outcomes and better engagement.
  • A reporting culture: The single most valuable human-layer outcome is not zero clicks — it is fast reporting. An employee who clicks and immediately reports provides the security team with the earliest possible warning of a live campaign. Actively reward and normalise reporting, removing the stigma from having clicked. One fast report can trigger a response that prevents dozens of subsequent compromises.

DPDP Act Implications of a Phishing Breach

India’s Digital Personal Data Protection Act 2023 adds a regulatory dimension to phishing risk that CISOs must factor into their board-level risk posture. A successful phishing attack that results in unauthorised access to personal data is a data breach under the DPDP Act, potentially triggering obligations to notify the Data Protection Board and affected data principals.

Organisations that have mapped their personal data flows — knowing which systems hold what categories of data for which purposes — are better positioned to assess the scope of a breach quickly and meet notification timelines. Organisations that have not done this mapping will struggle to answer basic scope questions under the time pressure of an active incident.

CERT-In’s 6-hour reporting requirement and the DPDP Act’s breach notification obligations are complementary pressures that both point toward the same operational capability: fast detection, fast scope assessment, and fast, documented response. Investing in that capability now supports compliance with both frameworks — and more importantly, reduces the actual harm that a successful phishing attack causes.

Investments in detection and response capability serve two regulatory masters at once — CERT-In’s 6-hour reporting window and the DPDP Act’s breach notification obligations — while materially reducing the damage from incidents that prevention didn’t stop.

Practical Steps for Indian Enterprise Security Teams

A prioritised action checklist for security teams looking to harden against AI-powered phishing:

  • Enforce DMARC at p=reject for your primary domain and any other domains you use for employee communications. Audit your SPF and DKIM records first to avoid accidentally blocking legitimate mail.
  • Audit your MFA deployment — identify applications using push notification MFA for privileged or financial access and begin migrating to phishing-resistant alternatives (FIDO2/WebAuthn).
  • Review your email gateway configuration — confirm URL rewriting and sandbox detonation are active and logging, not just enabled in configuration.
  • Map your personal data flows if you have not already — this directly accelerates DPDP Act breach scope assessment when an incident occurs.
  • Run a tabletop exercise specifically focused on the CERT-In 6-hour reporting window — understand where the bottlenecks are before a live incident forces the question under pressure.
  • Evaluate your SIEM log retention against CERT-In’s 180-day in-country requirement — many organisations discover coverage gaps when they actually audit what they are retaining versus what they assumed.
  • Deploy ZTNA for remote access to sensitive systems — begin with the highest-risk applications and privileged user accounts, then expand coverage from there.

How PJ Networks Can Help

PJ Networks provides managed security services to Indian enterprises, combining 24/7 NOC/SOC operations with deep Fortinet expertise — FortiGate next-generation firewall, FortiMail secure email gateway, FortiEDR endpoint protection, and Fortinet ZTNA. We deploy and operate PrahiX Ora for clients who need unified SIEM, NMS, video surveillance (VMS), and SOAR under a single managed operations service.

If your organisation is reassessing its phishing defence posture — whether in response to a near-miss, a compliance trigger, or a broader security programme review — we would be glad to discuss where you are and what a practical improvement path looks like. Reach out to the PJ Networks team to start the conversation.

Leave a Reply

Your email address will not be published. Required fields are marked *