-
Scammers now split trigger words like “funding” using invisible characters, so filters can’t catch them.
-
The trick, called ASCII smuggling, first showed up in AI attacks before criminals borrowed it for email scams.
-
Microsoft’s Defender still caught most of these emails, but the sneaky method still slipped past simple keyword filters.

Cybercriminals keep finding clever new ways to dodge spam filters. Security teams at Microsoft just found one of the sneakiest tricks yet. Scammers are now hiding letters inside phishing emails using characters that computers can read but people cannot see.
This method has already fooled artificial intelligence systems before. Now, criminals have turned it against everyday email inboxes, and millions of people have received these tricky messages already.
A Phishing Trick Borrowed from AI Attacks
Security researchers gave this technique the name ASCII smuggling. It hides secret text inside invisible Unicode characters. These characters live in a special section called the Tags block. Computers process the range from U+E0000 to U+E007F without showing anything to the human eye.
People first used this trick against AI chatbots. Attackers would hide secret instructions inside messages. A human reader saw nothing unusual. But an AI model could still read the hidden commands and follow them. That made the technique dangerous for anyone using AI tools to read emails or documents.
Microsoft’s threat research team recently found a different use for this old trick. According to Microsoft’s security blog, attackers stopped hiding secret messages from readers. Instead, they used the invisible characters to break apart risky words.
A word like “funding” could become two broken pieces with a hidden character in between. The recipient still sees “funding” normally. But a filter scanning for that exact word often misses it completely.
The scam started in early February 2026. Then it grew fast. Volumes jumped from around 20,000 messages a day to more than 1.3 million within days. By late February, daily volume peaked at roughly 2.37 million messages.
That surge kept going strong for about three months. Activity finally started dropping after May 15, 2026, though the wider phishing operation never fully stopped.
How the Invisible Letters Fool Email Filters
The scam worked in a simple, repeatable way. Fake companies sent emails promoting business loans, funding offers, and credit services. Words like “capital,” “loan,” “advance,” and “credit” filled these messages. Each of these words also got the invisible-character treatment somewhere inside.
Email filters that hunt for exact keyword matches often fail here. As explained by Microsoft researchers, splitting a flagged word with an invisible character can trick filters built purely on keyword lists. This matters because many spam systems still rely heavily on matching specific risky words inside a message.
A separate dark web listing in May 2026 claimed to sell a $500 method for accessing private Instagram posts and stories, limited to two buyers to avoid detection. Although unverified and suspected to be a scam, the claim highlights continued attempts to bypass social media privacy controls.
Microsoft tracked the pattern closely and found something interesting. The scam followed a strict weekly schedule. Volume dropped sharply on weekends and picked back up every Monday. That pattern suggested a highly organized, automated sending operation rather than random individual scammers.
On February 9 alone, researchers linked 148 finance-themed sender domains to this single campaign. Those domains accounted for about 96 percent of all messages flagged by Microsoft’s new detection tool built specifically for Unicode-tag abuse.
Interestingly, the scam did not fully succeed. Microsoft’s Defender for Office 365 caught more than 99 percent of these messages anyway. The system relied on other clues instead of just keywords.
It checked sender reputation, IP addresses, domain history, and general behavior patterns. So even though the invisible-character trick worked as intended, other safety nets still stopped most of the damage.
The scam also used a surprising delivery method. Messages traveled through infrastructure tied to ActiveCampaign, a legitimate email marketing platform used by real businesses every day. After Microsoft reported this abuse, ActiveCampaign responded directly.
According to the company, its moderation systems treat invisible Unicode characters the same way they treat regular visible text. Heavy or unusual use of these hidden characters gets flagged as suspicious by their systems too.
What Security Teams Should Do Next?
Microsoft shared clear advice for defenders trying to stop this kind of trick. Email security teams should strip out invisible Unicode characters before scanning messages for danger. This step should happen before any keyword, regex, or signature-based check runs. Systems that skip this step may keep missing broken-up trigger words hiding in plain sight.
The same fix applies beyond email inboxes too. Many companies now use AI assistants to read and summarize emails automatically. Those AI tools face the exact same risk that started this whole trend. Normalizing text first, before handing it to an AI model, should reduce the risk of hidden prompt-injection attacks slipping through unnoticed.
This discovery shows something important about modern cybercrime. Techniques built for attacking AI systems don’t stay confined to that world for long. Criminals borrow ideas quickly and reuse them anywhere they might work. A trick invented to trick chatbots ended up hiding inside ordinary loan and credit scam emails instead.
For now, the operation described by BleepingComputer remains active in some reduced form, even after its peak faded. Security teams should treat any unexpected invisible character inside email text as a warning sign worth investigating immediately, rather than something to dismiss as harmless formatting noise.