type: incident ยท created: 2026-09-07 ยท updated: 2026-09-07 ยท tags: [incident, phishing, evasion, unicode, campaign] ยท confidence: high ยท affected_sectors: [finance, technology] ยท au_impact: true
Attackers Conceal Phishing Lures Using Invisible Unicode Characters
Microsoft threat researchers described a large-scale phishing campaign using the ASCII-smuggling technique, in which invisible Unicode characters from the Tags block (U+E0000โU+E007F) are inserted inside finance-related lure words (such as "funding") to split them and evade email security filters while remaining visually intact.
| Attribute | Detail |
|---|---|
| Technique | ASCII smuggling (invisible Unicode U+E0000โU+E007F) |
| Peak volume | Up to 2.37 million messages/day (late February 2026) |
| Duration | ~3 months; dropped sharply after 15 May 2026, still active |
| Source | Microsoft (via BleepingComputer) โ Tier 2/4 |
The technique is already established in AI prompt-injection attacks for concealing malicious instructions; its adoption in consumer phishing signals attackers porting evasion mechanics across threat classes. Users are advised to examine sender identity and links in finance-related email regardless of how natural the message appears.