Back to BlogEmail Security Insights

What is ASCII smuggling? The invisible-letter trick hiding phishing from filters

StopSpoofingMe TeamPublished 6 min read

On September 3, 2026, Microsoft reported a high-volume phishing campaign that hid invisible Unicode "tag" characters inside lure words such as "funding", so keyword filters would miss them while readers saw nothing odd. Small businesses should keep layered filtering switched on, ask providers to strip invisible characters before scanning, and distrust unsolicited funding offers.

Key takeaways

  • "ASCII smuggling" became known as a way to hide instructions from people while AI tools read them. Microsoft found attackers reusing it to split phishing keywords so filters wouldn't match them.
  • According to Microsoft, signature hits jumped from about 21,000 messages on February 8, 2026 to more than 1.3 million on February 9, and topped 2.3 million a day at the peak.
  • Over 99% of the messages were still flagged by other protection layers, Microsoft says, which is a strong case for layered filtering over simple keyword rules.
  • The mail was relayed through a legitimate email-marketing platform, which Microsoft says may make it look more like normal marketing traffic. Authentication shows who sent a message, not whether it's honest.

What happened?

Microsoft's security researchers published their findings on September 3, 2026. The discovery came out of work on prompt-injection protection in Microsoft Defender for Office 365. The team had built a hunting signature to spot hidden instructions aimed at AI assistants in email. Instead, it lit up with ordinary finance-themed phishing.

Here is what Microsoft reports:

  • The spike. On February 8, 2026, the signature matched roughly 21,000 messages. On February 9, it matched more than 1.3 million, and daily volume later topped 2.3 million.
  • The senders. Most of the mail came from a cluster of roughly 150 finance-themed sender domains. They advertised business loans, lines of credit and advance funding. The domain names were recombinations of the same small vocabulary, such as guardiangrowthfunding[.]com and digitalcapitalboost[.]com (defanged here so they can't be clicked).
  • The schedule. The campaign ran hard on weekdays and went nearly silent every Sunday, a pattern Microsoft calls typical of scheduled bulk sending. The high-volume phase lasted about three months and dropped sharply after May 15, 2026.
  • The delivery route. The mail was relayed through ActiveCampaign, a legitimate email-marketing platform, and most flagged messages carried links rewritten to run through the platform's own click-tracking domains. Microsoft linked the activity to a broader ActiveCampaign-delivered phishing campaign with a Small Business Administration (SBA) theme, which the security company Fortra had documented earlier.
  • The platform's response. Microsoft shared its findings with ActiveCampaign before publishing. The company said that in its content moderation, "messages containing invisible Unicode characters receive the same moderation verdicts as their unobfuscated equivalents."
  • The result. Over 99% of the messages were flagged by Defender layers that didn't depend on spotting the hidden characters. These included sender, IP, URL and domain reputation, machine-learning classification, brand-impersonation detection and authentication checks.

How do invisible letters hide a word?

Unicode, the standard that defines the characters computers use, includes a "Tags" block (U+E0000 to U+E007F). It holds an invisible shadow copy of ordinary letters and symbols. It was originally meant for language tagging and is now largely deprecated, and most fonts and apps don't display these characters.

In AI security research, attackers used that block to write hidden instructions that a person can't see but an AI assistant reads. In the messages it sampled, Microsoft found no hidden instructions. The attackers simply dropped one invisible character, a TAG SPACE (U+E0020), into the middle of high-signal words.

What the reader sees What a naive keyword filter reads Does a rule for "funding" match?
funding f-u-n-d-i-n-g Yes
funding f-u-n + invisible U+E0020 + d-i-n-g No, unless the filter removes invisible characters first

The attackers' bigger prize, Microsoft says, is machine-learning filters. These can break text into tokens, and an invisible character in the middle of "funding" can turn a familiar word into unfamiliar pieces.

The idea isn't new. Spammers have used zero-width spaces (U+200B), no-break spaces (U+00A0), soft hyphens and lookalike letters to break keyword matching for years. What's new is the choice of the Tags block, which became famous through AI research in the past year, and the scale.

The fun part: Microsoft's first, overly simple version of the detector kept firing on some perfectly legitimate emails. Every one contained the flag emoji of England, Scotland or Wales. Those three flags are built from tag characters.

Why does this matter for your business?

The lures were business-funding offers. Loans, credit lines and advance funding are a natural hook for owners watching cash flow. Microsoft says these lures resembled patterns often associated with fraud or credential-harvesting funnels.

Keyword rules are easy to dodge. If you rely on mail-flow rules that flag words like "wire transfer" or "invoice", they still help, but this campaign shows a word can look identical to a person and different to a machine.

AI assistants read what you can't see. If you let an AI tool summarize or act on email, hidden characters are a way to feed it instructions. Microsoft recommends applying the same clean-up step before email content reaches AI tools.

Authentication isn't a trust badge. SPF, DKIM and an enforced DMARC policy stop criminals from forging your domain. They don't judge the intentions of a sender using its own domains, and Microsoft notes that mail sent from a reputable marketing platform with established reputation and authentication may look more like ordinary marketing traffic. We saw the same lesson in BEC emails that passed SPF and DKIM earlier this summer.

What should you do now?

  1. Keep layered filtering on. Microsoft's data is the reassuring part: reputation, URL analysis and machine learning caught what the keyword trick was designed to beat. Avoid broad allow rules or "bypass spam filtering" exceptions that switch those layers off.
  2. Ask your provider one question. "Do you strip or normalize invisible Unicode characters, including the Tags block, before running content rules?" Microsoft's core advice is to "normalize before you match."
  3. Don't make keyword rules your only defense. If you maintain custom mail-flow rules, treat them as an extra layer, not the main one.
  4. Check your AI tools. If an assistant reads your mailbox, ask the vendor how it handles hidden characters and prompt injection.
  5. Teach one simple habit. Unsolicited loan, grant or credit-line offers by email should be treated as suspect. Go to the lender or agency by typing its address yourself, and never click through from the email.
  6. Lock down your own domain. You can't stop strangers from registering finance-themed domains, but you can stop them from sending as you. Run our free domain scanner to see whether your SPF, DKIM and DMARC records are in place.

For a broader look at defenses against machine-generated lures, see our AI phishing defense guide.

Frequently asked questions

What is ASCII smuggling?

ASCII smuggling uses invisible Unicode characters, mainly from the Tags block (U+E0000 to U+E007F), to hide content inside text that looks normal. It became well known in AI security for hiding instructions from people while AI assistants read them. Microsoft has now documented the same characters being used to break up phishing keywords so email filters miss them.

Can I see the hidden characters in an email?

Not in a normal email view, and that's the point: the word "funding" looks exactly like "funding". You shouldn't need to inspect messages yourself. Detection belongs in your email filter, which should normalize text before scanning it. Your part is to treat unexpected money-related offers with caution, whatever they look like.

Are the England, Scotland and Wales flag emojis dangerous?

No. Those flag emojis are legitimate and are built from Unicode tag characters, which is why Microsoft's first version of its detector kept flagging them. Microsoft excluded them and calls them the one routine exception in legitimate mail. A tag character inside a word like "funding" is a different story.

Would DMARC have blocked these emails?

An enforced DMARC policy protects the domain it's published on from being forged. These messages used the campaign's own disposable finance-themed domains, relayed through a legitimate marketing platform, so DMARC on your domain doesn't cover them. Microsoft didn't publish per-message authentication results. It says over 99% were caught by layers including reputation, machine learning and authentication checks.

Sources

  1. Microsoft Security Blog — ASCII smuggling crosses over from AI prompt injection to phishing evasion (September 3, 2026)
  2. Hazetec — Microsoft Warns of Phishing Campaign Using Invisible Unicode to Bypass Email Filters (September 4, 2026)
  3. Microsoft Security Blog — Email threat landscape: Q2 2026 trends and insights (July 23, 2026)

Editor's note: This article was researched and written with AI assistance. Every factual claim was checked against the sources listed above; see our fact-check process for details.

Related Topics

ASCII smuggling phishinginvisible Unicode characters in emailUnicode tag characters phishingphishing filter evasionhidden characters in emailsbusiness loan phishing emailsnormalize before you match

Ready to Secure Your Email?

Check your domain's email security status with our free scanner, or get professional help setting up DMARC, SPF, and DKIM.