



Every week, Indian enterprises receive thousands of phishing emails — spoofed invoices, fake Microsoft 365 login pages, impersonated CISO messages. The attackers are not guessing; they have industrialised their operations with off-the-shelf phishing kits, legitimate cloud infrastructure, and adversary-in-the-middle (AiTM) reverse proxies that bypass multi-factor authentication. In 2025, credential phishing is no longer a threat for the unprepared — it is the dominant initial access vector for ransomware, business email compromise, and supply-chain attacks targeting Indian organisations across BFSI, manufacturing, healthcare, and government.
This post breaks down how modern phishing attacks work, what an enterprise detection posture looks like, and what your SOC needs to catch the ones that get through.
Three structural shifts have made phishing dramatically more effective in the past eighteen months:
For Indian enterprises, the risk is compounded by the volume of bulk phishing targeting Indian domain registrations, the uneven MFA adoption across mid-market firms, and the reality that many organisations have not yet shifted to phishing-resistant credentials such as FIDO2/passkeys.
Understanding the kill chain is the first step to disrupting it:
Attackers harvest employee email addresses, roles, and reporting structures from LinkedIn, company websites, tender portals, and leaked databases. Indian organisations that publish org charts, direct dials, and procurement contacts publicly are handing attackers their targeting list.
A phishing domain is registered — often a typosquat of the target’s own domain or a trusted vendor’s. A valid TLS certificate is obtained automatically (Let’s Encrypt requires no identity verification). The AiTM proxy is configured pointing at the victim’s Microsoft 365 or Google Workspace tenant. The entire setup takes under two hours.
The lure is sent through a legitimate email service (SendGrid, Mailchimp, or even a compromised business account) to bypass SPF/DKIM checks. The email references a real internal event — a vendor payment, a shared document, a compliance deadline. Urgency language (“action required by EOD”) short-circuits careful review.
The victim authenticates through the AiTM proxy, completes MFA, and is redirected to the legitimate portal — experiencing no error. The attacker now holds a valid session cookie for M365, GSuite, SAP, or whatever the lure targeted.
The stolen session is used to search the inbox for invoices and financial approvals (BEC pivot), exfiltrate data to an external share, enrol a new MFA device to achieve persistence, or deploy a remote management tool to the now-trusted device. From initial click to ransomware deployment, recorded dwell times in 2025 incidents average under 72 hours.
Perimeter controls — secure email gateways, URL rewriting, sandboxed detonation — remain necessary but are insufficient alone. The SOC needs layered telemetry that catches phishing at delivery, at authentication, and post-compromise.
When a session cookie is stolen and replayed from a different country or ASN than the user’s normal access profile, that is detectable. Identity platform logs (Entra ID, Okta, Google Workspace) expose authentication country, IP ASN, device fingerprint, and time of last MFA. A rule that alerts on new-country login within two hours of domestic login is simple and high-fidelity.
Attackers immediately add a new authenticator to achieve persistence before the victim notices. Entra ID and Okta emit an event for each new MFA device registration. Correlate: login event from new IP + MFA enrolment within 30 minutes = high-priority alert.
The first action many BEC attackers take is creating an inbox forwarding rule to exfiltrate mail silently. Microsoft 365 Management Activity API and Google Workspace Admin SDK both log these. An alert on any new external forwarding rule creation should be a P1 in any Indian enterprise SOC, given the volume of BEC losses reported by RBI and SEBI regulated entities.
When a user’s browser contacts a domain registered in the last 30 days, that alone is not conclusive — but combined with a typosquat of your own domain, or a domain that appears in zero other organisations’ DNS logs, it becomes a strong signal. Next-generation DNS security and web proxy logs fed into a SIEM enable this correlation at scale.
FortiGate’s application control engine can identify evasive phishing infrastructure even when hosted on legitimate cloud platforms by profiling application behaviour and certificate chain patterns. SSL deep inspection — often disabled for performance reasons — is critical to seeing what is inside HTTPS traffic to new or low-reputation destinations.
No detection strategy is a substitute for eliminating credential phishability in the first place. FIDO2 security keys (YubiKey, FIDO-compliant hardware tokens) and passkeys stored in platform authenticators (Windows Hello, Apple Passkeys) are cryptographically bound to the legitimate origin domain, making AiTM relay attacks impossible — the proxy cannot present the right cryptographic origin to the authenticator.
Migration to phishing-resistant MFA for privileged access, finance teams, and remote-access users should be the top identity priority for Indian enterprises in 2025. The DPDP Act’s accountability requirements make this a governance question as much as a technical one.
“The question is not whether your enterprise will be targeted by an AiTM phishing campaign. It is whether your SOC will see the stolen session before the attacker moves laterally.”
Under CERT-In’s 2022 directions, credential phishing incidents that result in unauthorised access to information systems must be reported within six hours of discovery. The clock starts when you know — not when forensics are complete. Organisations that discover a phishing compromise on a Friday evening face the same six-hour window as any other time.
Under the Digital Personal Data Protection Act (DPDP Act), a phishing-driven breach that exposes personal data of customers or employees triggers data-fiduciary breach notification obligations to the Data Protection Board and to affected individuals. Both regulators expect evidence that reasonable security practices were in place — email security controls, endpoint protection, MFA, and documented incident response procedures all count as evidence. Claiming to be compliant is not the standard; demonstrating it through controls and evidence is.
Practically, this means your incident response runbooks must include credential phishing as a specific scenario, with defined steps to:
For many Indian enterprises, the phishing detection gap is not a tool shortage — it is a correlation and response problem. Teams have email gateway alerts, firewall logs, identity platform events, and endpoint telemetry all sitting in separate consoles, with no one joining the dots fast enough to catch a stolen session before persistence is established.
The platform we deploy and operate for clients is PrahiX Ora, a unified SecOps platform built by PrahiX Tech Pvt Ltd. It brings together SIEM, Network Management (NMS), video surveillance (VMS), and SOAR in a single operations view — and each pillar directly addresses the phishing detection and response challenge.
SIEM — Ora ingests logs from Microsoft 365 Management Activity, Entra ID, Okta, FortiGate, FortiMail, endpoint agents, and DNS resolvers into a unified event pipeline. Correlation rules are mapped to MITRE ATT&CK — specifically Initial Access (TA0001), Credential Access (TA0006), and Persistence (TA0003) — surfacing multi-stage phishing attacks that no single source would catch alone. Graph-based attack storyline reconstruction ties the delivery email, the AiTM authentication event, the new MFA device enrolment, and the first lateral-movement hop into a single incident view, dramatically reducing analyst triage time. Tiered log retention (hot, cold, and archive tiers) directly supports CERT-In’s direction that logs be retained in-country for a minimum of 180 days, without inflating near-line storage costs.
NMS — Unified observability across FortiGate firewalls, managed switches, wireless APs, and SD-WAN links means the NOC can see whether a compromised device is generating unusual east-west traffic or unexpected new outbound connections — both common post-phishing lateral movement indicators. LLDP/CDP topology discovery and ML-based anomaly detection flag deviations from baseline that static threshold rules miss, particularly in multi-vendor estates where NOC visibility has historically been fragmented across separate dashboards.
Video surveillance (VMS) — For manufacturing, retail, and multi-site operations, Ora’s ONVIF/Hikvision/Dahua-compatible video surveillance management with video analytics brings physical and network security under one operations view. A phishing-driven credential theft accompanied by unusual after-hours physical access is a combined signal that unified operations visibility can surface — one that siloed tools would never correlate, yet is exactly the kind of cross-domain pattern that sophisticated threat actors rely on.
SOAR — Pre-built playbooks automate the first-response actions that matter most: forcing a session revoke across M365 and Okta the moment a stolen-session alert fires, pushing a block rule to FortiGate for the attacker’s IP, and triggering the evidence-preservation workflow that starts the CERT-In six-hour notification clock. Without automation, consistently meeting the 6-hour CERT-In window is nearly impossible — with Ora’s SOAR connectors, the most time-critical response steps complete in seconds, leaving analysts free to focus on investigation and communication rather than manual containment steps.
If your SOC is manually correlating identity events with firewall logs today, a discussion about deploying the platform makes sense. Contact the PJ Networks team to explore a scoping exercise.
Before investing in new tools, confirm the fundamentals are in place:
Credential phishing in 2025 is not the amateur operation it was five years ago. AiTM kits, legitimate cloud infrastructure, and AI-generated lures have made it the most scalable and effective initial access method available to threat actors targeting Indian enterprises. The organisations that fare best are those that combine phishing-resistant authentication with layered SOC detection — watching identity platforms, DNS, and network telemetry simultaneously — and that have practised their response procedures well before an incident fires the CERT-In clock.
PJ Networks operates 24/7 NOC and SOC services backed by FortiGate, FortiMail, and the PrahiX Ora unified SecOps platform to help Indian enterprises close this gap. Whether you are reviewing your email security posture, assessing your MFA strategy, or preparing your incident response programme for DPDP and CERT-In requirements, our team is ready to assist with a no-obligation security posture review.
Get in touch with PJ Networks at pjnetworks.com to schedule an assessment, or explore the PrahiX Ora platform capabilities at ora.prahix.com.