Microsoft says phishing campaign used invisible Unicode characters to evade email keyword filters

Microsoft says a large phishing campaign hid parts of finance-themed words inside invisible Unicode tag characters so email filters would miss them. The campaign peaked at more than 2.37 million messages in late February 2026, used about 150 sender domains, and ran through mid-June. Instead of hiding prompts for artificial intelligence tools, the attackers used so-called ASCII smuggling to break up words such as financial lures and evade signature, keyword, and regular-expression matching in email defenses.
Why it matters: This matters because it shows attackers adapting an AI-era text-hiding trick for mainstream phishing at very large scale. Organizations should review mail-filter normalization and tokenization so invisible Unicode tag characters are stripped or consistently handled before content inspection.

Sources

Attackers conceal phishing lures using invisible Unicode characters
Bill Toulas 2026.09.06 99% relevant
This article appears to be the same underlying event, adding Microsoft’s campaign metrics, timing, finance-themed lure details, the role of ActiveCampaign-linked delivery infrastructure, and recommended Unicode normalization defenses.
ASCII smuggling isn't just an AI security risk
2026.09.04 100% relevant
The article establishes a distinct phishing campaign and defensive issue: Microsoft documented the underlying event, its scale, timing, and the specific Unicode-based evasion method.
← Back to all stories