Phishing Attackers Repurpose AI ASCII Smuggling to Evade Detection

Published September 10, 2026

Attackers are sending phishing emails with hidden Unicode characters that bypass Microsoft's email filters. These invisible tags trick your inbox into showing a fake sender, making it harder to spot scams.

Report priority
Medium

How it works

  • Attackers use invisible Unicode characters to hide fake sender names in emails.
  • Microsoft's email filters normally block obvious phishing tricks, but these Unicode tags slip past them.
  • When you open the email, your inbox displays a fake sender, like a bank or coworker, while the real attacker stays hidden.
  • This makes it easier for you to click malicious links without realizing the email is fake.

What to do

Check your Microsoft email account for suspicious messages from senders you don't recognize. If you see an email that looks legitimate but feels off, like a bank or work contact, hover over the sender name before opening it. If the name changes or looks odd, it could be a fake.

Do not click links or open attachments in suspicious emails. If you think an email might be fake, forward it to Microsoft's phishing reporting tool at Phishing@ or report it directly in Outlook. Enable Microsoft's built-in phishing protection by going to Settings > Mail > Report safety options > More options > Safe Attachments and turning on Safe Attachments if available. Microsoft is working on updates to catch these tricks, but for now, stay cautious with unexpected emails.

Technical details

An attacker sends an email pretending to be from your bank, but the real sender is an attacker's server. The email looks normal at first glance, but the hidden Unicode tags fool Microsoft's filters. When you click a link, you're taken to a fake login page that steals your credentials.

Microsoft uncovered an ASCII smuggling phishing evasion campaign hitting email inboxes. Learn how attackers weaponize invisible Unicode tags.