News · curated 4 Sep 2026

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Coverage timeline

4 Sep 2026thehackernews.com

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

ASCII smuggling with invisible Unicode is a core prompt-injection primitive, and Microsoft's report shows the same technique crossing over into mainstream phishing, meaning defenders must sanitize hidden Unicode across both AI pipelines and email filters.

Microsoft Security Research reported a high-volume phishing campaign, first observed in early February 2026, that abuses invisible Unicode tag characters (ASCII smuggling) to split financial lure words like 'funding' so email filters fail to parse them. The technique, originally used in AI prompt injection to hide instructions from humans while exposing them to LLMs, has now been adapted by threat actors for traditional phishing filter evasion.