Knowbe4 iconKnowbe4Sep 21, 2026

Millions of Phishing Emails Use ASCII Smuggling to Bypass Security Filters

A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft. This technique, known as "ASCII smuggling," has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.

Millions of Phishing Emails Use ASCII Smuggling to Bypass Security Filters

Share this story

Send the public story page.

Useful takeaways from this story.

A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft.

This technique, known as "ASCII smuggling," has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.

Building the complete brief

The page is ready to read now. The fuller skim-friendly version will appear here automatically.

The useful part

A massive phishing campaign is using invisible Unicode tag characters to evade security filters, according to researchers at Microsoft. This technique, known as "ASCII smuggling," has grown popular over the past year for launching AI prompt injection attacks, but the same tactic can hide suspicious text in emails.

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app