News · curated 4 Sep 2026
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
First reported thehackernews.com
Coverage timeline
Single-source advisory — first reported, latest, and curated coincide.
Why it matters
ASCII smuggling with invisible Unicode is a core prompt-injection primitive, and Microsoft's report shows the same technique crossing over into mainstream phishing, meaning defenders must sanitize hidden Unicode across both AI pipelines and email filters.
Microsoft Security Research reported a high-volume phishing campaign, first observed in early February 2026, that abuses invisible Unicode tag characters (ASCII smuggling) to split financial lure words like 'funding' so email filters fail to parse them. The technique, originally used in AI prompt injection to hide instructions from humans while exposing them to LLMs, has now been adapted by threat actors for traditional phishing filter evasion.