India's cybersecurity researchers tallied 265.52 million threat detections across more than 8 million monitored endpoints between October 2025 and May 2026, a pace that works out to roughly 505 detections every minute. Trojans and file infectors accounted for 70% of all malware activity in that stretch, with education, healthcare and manufacturing absorbing 47% of the total threat volume — Mumbai and Maharashtra were hit hardest by both categories.

The bigger shift researchers are flagging isn't the volume, it's the sophistication attackers are now able to buy off the shelf. Security teams tracking India's banking sector describe AI-enabled fraud as a step change from earlier phishing campaigns: attackers are using generative tools to produce convincing, individually tailored lures at a scale that would have required a much larger human operation only a few years ago, alongside AI-generated voice and video used to defeat identity-verification checks at banks and fintech platforms.

India's 2026 threat outlook names this pattern directly, flagging "hyper-personalized AI phishing and mobile banking malware" and "AI-enhanced APTs and strategic deception" among the year's top predicted threats, alongside a newer category researchers call "poisoning the well" — direct attacks on the AI models banks and enterprises are themselves deploying, rather than attacks that merely use AI as a tool. Industry groups are using the trend to press for stronger cybersecurity funding commitments ahead of India's 2026 budget cycle, arguing that a workforce already stretched thin before AI-assisted attacks became common cannot absorb this pace of escalation without material new investment.

AdvertisementIn-Article