Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-07 ยท updated: 2026-09-07 ยท tags: [incident, phishing, unicode, ascii-smuggling, email-security, microsoft] ยท confidence: high ยท severity: medium ยท affected_sectors: [financial-services, retail, government] ยท au_impact: false

Attackers Conceal Phishing Lures With Invisible Unicode Characters

Microsoft threat researchers described a large-scale phishing campaign using the ASCII-smuggling technique, in which invisible Unicode characters from the Tags block (U+E0000โ€“U+E007F) are inserted inside finance-related lure words such as 'funding' to split them and evade email security filters while remaining visually intact.

Summary

Microsoft's telemetry shows the high-volume phase peaked at up to 2.37 million messages a day in late February 2026, persisted for roughly three months and dropped sharply after 15 May, though the campaign remains active. The technique is already established in AI prompt-injection attacks for concealing malicious instructions; its adoption in consumer phishing signals attackers porting evasion mechanics across threat classes. Users are encouraged to examine sender identity and links in finance-related email regardless of how natural the message appears.

Impact

  • Email security filters bypassed via invisible characters that split known-lure keywords
  • Large-scale delivery of finance-related phishing across consumer inboxes
  • Technique crossover from AI prompt-injection to conventional phishing evasion

Sector

Financial Services

Sources