A trick built to fool AI agents spread into millions of phishing emails
Microsoft researchers found a phishing campaign using invisible Unicode tag characters inside finance words. A recipient still saw words such as "funding," while some filters saw broken-up tokens. Microsoft built the detector while studying hidden prompt injection in email. Its signature jumped from about 21,000 messages on February 8 to more than 1.3 million the next day. It later peaked at 2.37 million messages on one weekday.
Verified 3:37 AM PDT · 2 original sources
The counts come from Microsoft Defender telemetry, so they are a company claim about one vendor's view of the campaign. Microsoft said layered defenses caught most messages. The technique did not invent invisible-character spam. The new part was the Unicode Tags block, which security researchers had recently made prominent through AI red-team work.
Email providers should say whether they normalize characters from U+E0000 to U+E007F before tokenization and filtering. Defenders also need to avoid false positives from the England, Scotland and Wales flag emoji sequences, which legitimately use tag characters.
Audit the story
Original sources
Company claims remain company claims. Follow the reporting and judge the evidence directly.
- Microsoft Security ResearchASCII smuggling crosses over from AI prompt injection to phishing evasion ↗
- Ars TechnicaOnce popular for attacking AI, ASCII smuggling is embraced by spammers ↗
Continue the edition