



Cybercriminals have always targeted people, not just systems. But in 2025, the spear phishing attack has been weaponised with generative AI to a degree that is fundamentally changing the threat landscape for Indian enterprises. Messages that once required hours of manual research to craft now take seconds. The impersonation quality is near-perfect. And the volume is growing exponentially.
For Indian IT leaders and CISOs navigating this environment, the question is no longer whether AI-powered phishing will reach their organisation — it already has. The question is whether your defences are calibrated for this new normal.
Traditional phishing relied on volume: blast a million generic emails and convert a small fraction. Spear phishing adds targeting — a message crafted specifically for the recipient, referencing their job role, colleagues, recent activity, or business context. Historically, that targeting required significant manual effort, which kept volumes low.
Generative AI has removed that bottleneck. Adversaries can now:
The result: security awareness training that teaches employees to “spot poor grammar” or “look for urgency cues” is no longer sufficient by itself. The grammar is impeccable. The urgency is calibrated. The sender name is your CFO’s.
Indian organisations face several compounding factors that make them attractive spear phishing targets:
India’s prominence in global IT services, banking, pharma, and manufacturing means that a successful compromise of a mid-sized Indian firm can cascade into a multinational supply chain. Threat actors are well aware of this.
Wholesale cloud migration, remote-work tooling, and SaaS adoption accelerated post-pandemic. Security architecture in many organisations has not kept pace, creating gaps between what employees can access and what security teams can monitor.
India consistently ranks among the top geographies for BEC losses in global threat intelligence reports. CFO-impersonation fraud — where a threat actor sends a doctored instruction to the finance team to transfer funds to a new account — is a direct descendant of spear phishing. AI makes the impersonation even more convincing.
DPDP Act compliance, CERT-In directives, and RBI cybersecurity circulars are all live concerns for Indian IT teams. Adversaries exploit these by sending fake “compliance notification” emails that appear to originate from regulators or legal counsel, prompting recipients to click urgently.
Understanding the attack chain helps identify where defensive controls can interrupt it.
The gap between steps 3 and 5 is shrinking. Incident responders report attackers moving from initial access to ransomware deployment in under 24 hours in some 2025 campaigns.
No single control eliminates spear phishing risk. Effective defence requires layered, integrated controls across email, endpoint, identity, and network.
Legacy email gateways rely on IP/domain reputation and signature matching. AI-generated lures from freshly registered domains score clean. Invest in solutions that analyse behavioural signals: unusual sending patterns, lookalike domain detection, conversation thread anomalies, and attachment sandbox detonation. FortiMail from Fortinet, which PJ Networks deploys and manages for clients, integrates multi-layer anti-phishing with FortiGuard AI threat intelligence, covering impersonation detection, URL rewriting with real-time inspection, and sandboxing.
Credential harvesting succeeds only when stolen credentials are usable. FIDO2/passkey-based MFA eliminates the replay risk that TOTP-based OTP carries (OTP codes can be phished in real time via adversary-in-the-middle proxies). For organisations not yet on FIDO2, enforce MFA on all externally exposed services — email, VPN, cloud consoles — as a minimum.
Assuming the attacker will eventually get a valid credential, ZTNA limits what they can reach. Rather than VPN’s implicit “trust the tunnel,” ZTNA enforces continuous identity and device posture checks, granting access only to the specific application the user needs — not the entire network. PJ Networks deploys Fortinet’s ZTNA solution, ensuring that even a compromised credential cannot be used to move laterally across the corporate network.
Training content needs to evolve. Simulated phishing exercises should now include AI-quality lures: well-written, contextually relevant, sender-accurate. Employees should be trained to verify any unusual financial instruction through a separate out-of-band channel (a phone call to a known number) regardless of how convincing the email appears.
Many Indian organisations have published DMARC records in monitor or quarantine mode but never enforced reject. Without reject policy, spoofed emails from your own domain will still reach recipients. Audit your email authentication posture and move to p=reject on all domains you own, including parked domains that threat actors could spoof.
AI-generated lures are novel, but the infrastructure — C2 servers, malware families, phishing kit frameworks — often recycles. Integrating curated threat intelligence feeds into your email gateway, firewall, and endpoint platform allows you to block known-bad infrastructure even when the lure itself is unrecognised. FortiGate’s integration with FortiGuard Labs threat intelligence provides this out of the box.
When a spear phishing email bypasses perimeter controls and a user clicks — which will happen, even in well-trained organisations — detection speed and response time determine whether the incident becomes a breach. This is where the platform we deploy and operate for clients, PrahiX Ora, directly supports your security operations.
PrahiX Ora is a unified SecOps platform built by PrahiX Tech Pvt Ltd. It consolidates four capabilities that are individually available but far more powerful when correlated together:
If your organisation is evaluating a unified SecOps platform, or if your current tooling leaves visibility gaps that a spear phishing incident could exploit, speak with our team about how we deploy and operate PrahiX Ora for Indian enterprises.
A successful spear phishing attack that results in credential theft or data exfiltration triggers multiple compliance obligations for Indian organisations.
Under CERT-In’s 2022 directions (amended and re-clarified since), organisations must report cyber incidents — including unauthorised access to IT systems and data breaches — within six hours of becoming aware. The clock starts from awareness, not from confirmation. Spear phishing incidents that result in any access to systems or data are in scope.
Under the Digital Personal Data Protection (DPDP) Act, 2023, data fiduciaries must notify the Data Protection Board and affected data principals of personal data breaches. A phishing-facilitated breach of customer records, employee data, or any other personal data triggers this obligation. Penalties for non-compliance are substantial — up to ₹250 crore per instance in the highest tier.
The practical implication: incident response capability is now a compliance capability. Organisations that cannot detect, contain, and report within regulatory windows face both operational and legal consequences. This is why SOC readiness — not just perimeter security — is the correct framing for board-level cyber risk discussions.
Use this as a gap assessment against your current controls:
AI-powered spear phishing is not a future threat — it is the present reality for Indian enterprises in 2025. The defence imperative is to match the attacker’s capability uplift with an equivalent upgrade in your detection, response, and resilience posture.
That means moving beyond point-solution email security to integrated SecOps: a SIEM that correlates phishing signals across the kill chain, SOAR that automates response within the CERT-In reporting window, and ZTNA that limits the blast radius when a credential is inevitably compromised.
PJ Networks works with Indian enterprises to deploy, manage, and operate exactly this stack — FortiGate next-generation firewalls, FortiMail email security, Fortinet ZTNA, and the PrahiX Ora unified SecOps platform — from our 24/7 NOC/SOC. If you are assessing your spear phishing readiness or need to close gaps ahead of a regulatory audit, reach out to our team for a no-obligation assessment.