Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 342, Issue 1IT Vendor NewsMicrosoft

ASCII Smuggling Crosses Over from AI Prompt Injection to Phishing Evasion

Microsoft, Thursday, September 3rd, 2026

Microsoft found phishers using invisible Unicode tag characters, an AI prompt-injection trick, to break up filter keywords.

Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII smuggling.

Rather than hiding instructions from people while exposing them to AI models, the attacker used the characters to split financial lure words such as 'funding' so email filters could not parse them.

The finding emerged from Microsoft Defender for Office 365 prompt injection protection research. It illustrates how evasion techniques developed against AI systems are now surfacing in conventional phishing operations.

more →  ·  More from Microsoft →