Microsoft has found phishing emails using invisible Unicode characters inside ordinary-looking words to make those words harder for some filters to recognise. A finance-themed message could show “funding” normally to the recipient while the underlying text contains a hidden character between the letters.
The technique does not make every message undetectable. Microsoft says more than 99% of the messages it observed were still flagged by other protection layers. However, the campaign shows why an email can look clean and readable while containing deliberately manipulated text.
Staff should continue treating unexpected funding, loan and credit offers with caution, even when the wording looks professional and the link appears to use familiar marketing infrastructure.
What has Microsoft found?
Microsoft Security Research reported on 3 September 2026 that a high-volume phishing campaign had repurposed a technique known as ASCII smuggling. The technique became widely discussed in AI security because it can hide instructions from people while leaving them available to software or an AI model.
In this campaign, attackers used characters from the same Unicode range for a more traditional purpose: breaking up high-signal words before email filters analysed them. A word still looked complete on screen, but its underlying character sequence was no longer a simple uninterrupted word.
Microsoft’s research focused on finance-themed messages offering business funding, loans and lines of credit. The messages used disposable sender domains and links routed through legitimate email-marketing infrastructure.
How can a phishing email contain invisible characters?
Digital text contains more than the letters and symbols visible on screen. Unicode includes special characters that typical fonts and applications do not display. The campaign inserted characters from the Unicode Tags block, U+E0000 to U+E007F, inside selected words.
Microsoft gives the example of the visible word funding. An attacker can insert an invisible tag-space character between “fun” and “ding”. A person still sees the expected word, while a simple keyword rule may see separate fragments instead.
This is not the same as hiding a complete secret message. In the campaign Microsoft analysed, individual invisible characters acted as separators inside financial lure words. The objective was to interfere with filtering and text classification without making the email look unusual.
How large was the campaign?
Microsoft’s detection signature recorded roughly 21,000 messages on 8 February 2026 and more than 1.3 million the following day. Daily volumes later reached as high as approximately 2.37 million messages.
The high-volume use of this exact technique persisted for roughly three months and dropped sharply after 15 May, with lower residual activity observed into June. Microsoft says the broader phishing campaign existed before the Unicode technique appeared and continued after its use declined.
Approximately 96% of the volume identified by the signature came from finance-themed sender domains. The activity also followed a strong weekday pattern, falling close to zero at weekends before returning.
These figures come from Microsoft’s analysis of Defender for Office 365 telemetry. They describe Microsoft’s observed activity, not the total number of messages sent worldwide.
Does this mean Microsoft 365 email filtering failed?
No. Microsoft says more than 99% of the observed messages were detected by protection layers that did not depend on recognising the hidden Unicode characters directly.
Those layers included sender, IP, URL and domain reputation, spam and phishing classification, email-authentication checks, brand-impersonation detection and analysis of visible content. Microsoft also uses OCR-based analysis, which can evaluate how text actually appears to a recipient.
The lesson is that email security needs several independent signals. A filter based only on literal keywords can be bypassed more easily than a layered system that considers the sender, infrastructure, links, authentication and overall behaviour.
What should users look out for?
- Unexpected offers of business loans, funding or credit.
- A sender domain that is unfamiliar but assembled from reassuring financial words.
- Messages creating urgency around limited funding or immediate approval.
- Links that do not clearly lead to the organisation named in the message.
- Requests for Microsoft 365 credentials, bank details or sensitive business information.
- An email that reached the inbox but still feels unsolicited or out of context.
Do not assume that an email is safe because the spelling looks correct or because it passed through to the inbox. Avoid clicking the link, opening attachments or replying. Use the organisation’s known website or telephone number if you genuinely want to verify an offer.
This complements our guidance on fake IT support requests in Microsoft Teams: the communication channel and professional appearance are not proof of identity.
Microsoft 365 guidance
Are your Microsoft 365 security controls working together?
Concerned about your Microsoft 365 security or configuration? Talk to KES about your current setup and the areas you would like help with. We will discuss your requirements and recommend an appropriate next step.
Prefer a quick starting point? Complete the free Microsoft 365 Security Assessment →
Received a suspicious message? Do not click, reply or forward it normally. Use your established reporting process or contact KES.
What should businesses do now?
- Review Microsoft 365 email protection. Confirm that anti-phishing policies and appropriate preset security policies are enabled and monitored.
- Check licensing and configuration. Microsoft notes that protection coverage depends on product licensing, settings and available telemetry.
- Give staff a simple reporting route. Users should know how to submit a suspicious email without forwarding potentially dangerous content casually.
- Use layered protection. Email controls should work alongside MFA, managed devices and endpoint protection.
- Train around current lures. Finance, loan and funding offers are especially relevant to owners, finance staff and anyone responsible for cash flow.
- Investigate patterns, not just individual wording. Repeated messages, rotating sender domains and similar tracking links may expose a wider campaign.
If a user has entered credentials after following a suspicious link, treat it as a possible account compromise. Follow the steps in our guide to responding to a cyberattack and contact your IT provider promptly.
What does this mean for AI assistants and Copilot?
Invisible Unicode characters first attracted attention because they could hide instructions inside content read by an AI assistant. A person might see an ordinary email while an AI system processes additional hidden material.
Microsoft’s newly reported campaign used the characters for filter evasion rather than hidden AI instructions. Even so, the defensive principle is similar: systems should normalise or remove invisible characters before analysing text.
Microsoft says Defender for Office 365 Plan 2 can detect prompt-injection content in inbound email as part of mail-flow inspection, before the message reaches a user or AI assistant. Microsoft 365 Copilot also has safeguards at the point where the model processes content.
Businesses using Copilot or other AI tools with email should therefore review both AI safeguards and the security of the underlying mailbox. An AI assistant does not replace conventional phishing protection.
What happens if a business ignores this?
A user could follow a convincing finance link, submit Microsoft 365 credentials or provide sensitive company details. Once an account is compromised, attackers may search email, impersonate staff, reset access to other services or send further phishing messages from a trusted mailbox.
The practical risk is not limited to this specific Unicode technique. The campaign shows how quickly methods discussed in AI-security research can be reused in ordinary fraud. Businesses that rely on one filter or one user-training message will struggle as attackers change wording and delivery methods.
Quick answers
What is ASCII smuggling?
ASCII smuggling uses invisible Unicode characters to hide or manipulate text. The characters exist in the underlying data even when a person cannot see them on screen.
Can an email look normal while containing hidden characters?
Yes. An attacker can insert a non-rendering character inside a word while the visible text still appears complete.
Did these messages bypass Microsoft Defender?
Microsoft says more than 99% of the observed messages were flagged by other protection layers, rather than relying solely on detection of the hidden characters.
Were the messages aimed at UK businesses?
Microsoft describes a broad finance-themed phishing campaign rather than a UK-only attack. Funding and credit lures remain relevant to UK SMEs because they target normal business concerns.
Should every finance email be deleted?
No. Treat unsolicited offers cautiously and verify the sender independently before clicking links or sharing information.
The important point
A readable email is not necessarily clean email. Attackers can manipulate the underlying text without changing what the recipient sees.
Modern email security should combine content analysis with sender reputation, link inspection, authentication and behavioural signals. Staff should also have a clear route for checking any unexpected financial offer before they interact with it.
Microsoft sources
- Microsoft Security Research: ASCII smuggling crosses over from AI prompt injection to phishing evasion (3 September 2026).
- Microsoft Learn: Prompt injection protection in Microsoft Defender for Office 365.
Attack techniques, campaigns and product capabilities change over time. Review Microsoft’s current guidance and your tenant configuration before relying on any specific detection or control.