Microsoft Exposes Phishing Campaign Using Invisible Unicode Characters
Microsoft researchers have uncovered a large-scale phishing campaign that used invisible Unicode characters to evade email security filters. The technique, known as ASCII smuggling, inserts Unicode characters from a specific block into words, making them invisible on screen but breaking up keywords scanned by email security systems.
The campaign peaked at 2.37 million malicious messages per day in late February 2026 and targeted businesses across India and globally that rely on email-based keyword detection as a first line of defence against financial fraud.
Microsoft's Defender caught over 99% of the malicious messages through secondary signals, including sender reputation, IP address analysis, domain verification, and other behavioural indicators. The company recommends stripping or normalising Unicode tag characters before applying keyword detection rules to counter this technique.