Security.io Intelligence DeskFriday, 4 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Email Security · Executive briefing

ASCII smuggling moves from prompt injection into phishing evasion

Invisible Unicode tag characters associated with AI prompt injection are now being used to split financial lure words before email filters parse them.

Email SecurityAI SecurityThreat Intelligence
Why it is in today’s brief

Microsoft’s September 3 disclosure is new: a technique previously treated mainly as AI prompt-injection research appeared in sustained high-volume phishing telemetry. The enterprise decision changed from watching an AI-security curiosity to validating canonicalisation across email filters, archives and AI-connected inbox workflows. It warrants inclusion because it adds a distinct email-control decision rather than another vulnerability or supplier incident.

Read first

Microsoft observed a sustained, high-volume phishing campaign using invisible Unicode tag characters to obfuscate financial lure words. Security teams should validate canonicalisation and detection across email gateways, archives and AI-connected inbox workflows.

Act now

Scan inbound mail for Unicode code points U+E0000 through U+E007F.

Accountable owner

CISO with email security, security engineering, SOC, e-discovery and AI-governance owners

Decision horizon

Detection validation today; pipeline and AI-inbox control review within 30 days.

AssessmentHigh confidence
Emerging riskCampaign-specific infrastructure, broader platform telemetry, weaponised attachments or evidence that mailbox-connected agents acted on hidden instructions.

What happened

Microsoft said telemetry hits on a hunting signature rose sharply from February 9, 2026, and remained elevated on weekdays for approximately three months. On September 3, 2026, Microsoft published its finding that invisible Unicode tag characters were being used in a high-volume phishing campaign. The observed phishing operator inserted invisible Unicode tag characters into financial lure words before email filters parsed them. Microsoft described the technique as ASCII smuggling because the hidden characters can carry machine-readable text that typical fonts and interfaces do not display.

The relevant Unicode Tags block is U+E0000 to U+E007F; Microsoft noted that U+E0041 mirrors “A” and U+E0061 mirrors “a” while remaining invisible in typical interfaces. Email and AI text-processing systems mechanically receive the hidden code points even when typical user interfaces do not render them. Microsoft said the majority of observed messages were caught by layered protections rather than a single Unicode-specific signal.

No specific AI agent or framework was identified in the cited sources. No underlying AI model or version was identified in the cited sources. No campaign-specific sender domains, malicious URLs, payload hashes or named actor were identified in the cited publications. Attribution posture: Microsoft did not name an actor behind the campaign, and responsibility remains unresolved. The cited source did not publish the specific indicators described as No campaign infrastructure or payload identifiers were published in the selected sources.

Why this matters now

The campaign exposes an interpretation gap rather than a single signature gap. A human can see an ordinary financial lure while filters, search tools, archives and AI assistants process additional invisible code points. If each layer canonicalises differently, investigations and controls may disagree about what the message contained.

The same mechanism cuts in both directions. Attackers can use invisible characters to fragment keywords before conventional email detection, while hidden text can also be read by AI systems that ingest raw content. Organisations connecting inboxes to summarisation, triage or action-taking agents therefore need a consistent text representation before untrusted messages reach those workflows.

Microsoft’s observation that layered protections caught most messages is important. The response is not to replace existing email security with one Unicode rule. It is to test whether normalisation, behavioural detection, link analysis, sender controls and downstream AI safeguards continue to operate when visible and machine-readable text differ.

The decision for security leaders

Require a controlled canonicalisation stage before email content reaches keyword detection, search indexes, archives, data-loss controls or AI workflows. Preserve the original message for evidence, but ensure security decisions operate on a consistent, reviewable representation of the text.

Validate controls with a purpose-built test corpus containing Unicode tag characters inside financial, credential and urgency lures. Compare what the user interface renders with what the gateway, SIEM, archive, e-discovery platform and any mailbox-connected AI service receives. Record every disagreement as a control defect.

Constrain AI-connected inbox workflows independently of text normalisation. Hidden characters are untrusted input, but canonicalisation is not authorisation. Agents that can send messages, retrieve sensitive data, create tickets or invoke business tools need deterministic permission boundaries and confirmation for consequential actions.

Evidence of closure

  • A test corpus produces consistent canonical text across every inspected mail-processing layer.
  • Gateway and downstream detections alert on hidden Unicode inside finance and credential lures.
  • Telemetry preserves both original code points and the canonicalised investigation view.
  • An approved inventory records every mailbox-connected agent and its permitted actions.

The Security.io assessment

Microsoft’s telemetry supports a real phishing-evasion campaign, but it does not establish that invisible characters universally bypassed email security. The reported majority of messages were detected through layered protections, indicating that sender, behavioural, link and content signals retained value even when individual lure words were fragmented.

The security significance is the divergence between visible and machine-readable text. That gap can undermine triage, hunting, e-discovery and AI workflows even when the message is ultimately blocked. Organisations need to know which representation informed each decision and retain enough evidence to reconstruct the transformation.

The observed activity is not evidence of autonomous AI offensive capability. Attackers configured ordinary message content with hidden Unicode characters; software then processed those characters mechanically. The defensible enterprise response is aligned parsing and constrained downstream authority, not speculative claims about model intent or intelligence.

Questions for the morning meeting

  • Can the SOC prove what users, filters and AI assistants each received?
  • Which mailbox-connected agents can take consequential actions?
  • Are raw and canonical message forms preserved for investigation?
  • Who owns text normalisation across the mail-processing pipeline?

Related intelligence

Shared decision context

Appointments, dinners & sponsored intelligence

Current paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →