Mumbai: Phishing attacks in India have surged dramatically, making the country the second most targeted globally and the leader in the Asia Pacific and Japan (APJ) region, according to the latest India findings from Zscaler ThreatLabz 2025 Phishing Report. The study analysed over two billion phishing attempts blocked during 2024 through Zscaler’s Zero Trust Exchange, the world’s largest cloud security platform.
The report highlights that phishing attacks in India accounted for over 80 million attempts last year, representing approximately one-third of all phishing activity in the APJ region. India’s technology sector bore the brunt, with more than 24.5 million attacks, followed by the services and manufacturing sectors with 19.1 million and 17.7 million incidents respectively.
Phishing attacks in India are evolving rapidly, with cybercriminals increasingly leveraging generative AI to craft highly personalised and sophisticated lures designed to bypass defences and exploit human vulnerabilities.
“The phishing game has changed. Attackers are using GenAI to create near-flawless lures and even outsmart AI-based defenses,” said Deepen Desai, CSO and Head of Security Research, Zscaler.
“Cybercriminals are weaponising AI to evade detection and manipulate victims, which means organisations must leverage equally advanced AI-powered defenses to outpace these emerging threats. Our research reinforces the importance of adopting a proactive, multi-layered approach combining robust zero trust architecture with advanced AI-driven phishing prevention to effectively combat the rapidly evolving threat landscape,” added Desai.
Despite a global decrease of 20% in phishing volumes due to improved email authentication protocols, the threat landscape in India remains severe. The report also found that Microsoft was the most impersonated brand worldwide, featuring in 51.7% of phishing attacks.
The rise of AI-powered phishing attacks in India has also led to new tactics, such as abusing popular community platforms like Facebook, Telegram, and Instagram to spread malware and conduct social engineering. Tech support scams continue to be prevalent, with over 159 million attempts globally.
“India’s digital acceleration has made it a ripe target for attackers leveraging advanced AI tools to deceive users and compromise systems,” said Suvabrata Sinha. CISO-in-residence, India – Zscaler.
“The new wave of phishing campaigns is not just opportunistic, it’s calculated, context-aware, and often linguistically tailored to trick even well-trained users. A Zero Trust strategy, reinforced with AI-driven threat detection and containment, is essential to mitigating these highly evolved threats,” added Sinha.
Key departments such as payroll, finance, human resources, and senior executives remain prime targets, due to their access to sensitive information and the ability to approve fraudulent transactions. Cybercriminals are also creating fake AI assistant websites offering services like resume building and graphic design, exploiting the growing trust in AI tools to lure victims.
As phishing attacks in India grow more advanced, the Zscaler report underscores the urgent need for organisations to strengthen defences with multi-layered, AI-powered security strategies.
