Zscaler report highlights India as top APJ Phishing Target

DQChannels Bureau
DQChannels Bureau
Zscaler report highlights India as top APJ Phishing Target

India may be seeing fewer phishing attempts, but the threat is becoming harder to read. According to the Zscaler ThreatLabz 2026 Phishing and Initial Access Report, India remained the APJ phishing target most affected in 2025, even as phishing activity fell 33.4% year over year.

The country recorded 52.8 million phishing attempts, representing 36.6% of all phishing activity across APJ. The bigger shift, however, is how attackers are working. High-volume campaigns are giving way to AI-assisted, highly targeted attacks designed to look more convincing.

Fewer attacks, more convincing tactics

The report points to a clear change in attacker behaviour. Cybercriminals are using AI-powered “text-to-site” tools to create polished phishing pages in minutes. ThreatLabz identified 413,524 AI-generated site instances, with nearly 10% flagged as explicitly malicious.

The Services sector saw a 65.5% year-over-year rise in hits, as attackers targeted trust-based interactions such as billing, onboarding and support renewals.

For India, the APJ phishing target finding also comes with another concern: encrypted attacks. More than 2.65 billion encrypted attack hits were routed globally through traffic associated with India, while over 762 million encrypted attacks targeted Indian organisations.

Encryption and session hijacking add pressure

The report says 95.2% of phishing attempts were hidden within encrypted traffic. Attackers are also using real-time session hijacking kits to bypass multi-factor authentication.

This changes the security challenge. It is no longer only about spotting suspicious emails or links. Attackers are increasingly trying to hide inside normal-looking traffic and compromise active sessions.

Zscaler’s deception telemetry adds another layer. Nearly 90 million hostile interactions from 1.37 million unique attacker IPs were recorded across six months, showing that attackers were probing enterprise identities and collaboration platforms before attempting compromise.

Read More: 

TSC Auto ID Strengthens Partner Ties at ASIRT Synergy Biz Conclave 2026

FITAG Strengthens Leadership Team & Expands Network to 48 IT Associations

ADATA and Supertron partnership targets India’s next growth wave

SentinelOne Murali Urs appointment reshapes channel strategy

Latest Stories