As cited
Copy frozen at (site build).
ai security
ASCII smuggling isn't just an AI security risk
Microsoft identified a phishing campaign peaking at 2.37 million messages in late February 2026 that used invisible Unicode tag characters inserted within financial keywords to evade content filters. Rather than targeting artificial intelligence (AI) models through prompt injection, attackers split words like 'funding' with invisible characters to defeat keyword matching and signature-based detection. The campaign originated from approximately 150 finance-themed domains, operated exclusively on weekdays through mid-June, and demonstrates how emerging AI security techniques are being repurposed for traditional email-based fraud.
Why it matters: Email administrators and security teams protecting against phishing need to update content filters to normalize and strip invisible Unicode characters before applying keyword or regex matching, as this attack directly bypasses legacy detection methods.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
ai security
ASCII smuggling isn't just an AI security risk
Microsoft identified a phishing campaign peaking at 2.37 million messages in late February 2026 that used invisible Unicode tag characters inserted within financial keywords to evade content filters. Rather than targeting artificial intelligence (AI) models through prompt injection, attackers split words like 'funding' with invisible characters to defeat keyword matching and signature-based detection. The campaign originated from approximately 150 finance-themed domains, operated exclusively on weekdays through mid-June, and demonstrates how emerging AI security techniques are being repurposed for traditional email-based fraud.
Why it matters: Email administrators and security teams protecting against phishing need to update content filters to normalize and strip invisible Unicode characters before applying keyword or regex matching, as this attack directly bypasses legacy detection methods.
- Source published
- First seen by Cybersecurity Tracker