Invisible Unicode characters have spent two years as the neat party trick of AI security research: hide an instruction where no human can see it, and watch a language model dutifully obey. Microsoft Security Research has now caught somebody using the very same characters for a far less clever job — chopping the word funding in half so that an email filter would not recognise it.
The findings were published on September 3, 2026 by Noam Kochavi and Sarah Wolstencroft, and they describe a bulk phishing operation that lifted ASCII smuggling straight out of the prompt-injection playbook. The technique abuses the Unicode Tags block, U+E0000 through U+E007F — code points originally intended for language tagging that render as nothing at all on screen while remaining perfectly readable to software. Drop U+E0020 into the middle of a lure word and funding travels as fun + invisible character + ding. The recipient sees an ordinary word. A keyword matcher sees two fragments it has never been told to care about.
The scale was not subtle. Hits on Microsoft’s hunting signature jumped sharply on February 9, 2026 and stayed elevated for roughly three months, with weekday volumes running between 1 and 2.37 million messages before dropping off sharply after May 15, 2026. Volumes collapsed to near zero at weekends and resumed on Monday mornings — automated bulk infrastructure apparently keeping office hours.
The plumbing behind it was equally industrial:
- 148 finance-themed sender domains, generated by recombining a vocabulary of 28 tokens such as advance, boost, capital, funding and loan
- Roughly 98.5% of the messages matched ActiveCampaign envelope patterns, with links pointing at the marketing platform’s tracking domains acemlnd.com and activehosted.com
- The wider financial-lure operation was already on record: Fortra documented the SBA loan phishing campaign behind it in September 2025
And after all that effort, the trick simply did not work. Over 99% of the messages were flagged by protections that had nothing whatsoever to do with the invisible characters — sender reputation, URL and domain checks, OCR reading of image content, and machine-learning classifiers. Obfuscating the text did nothing about the infrastructure sending it.
Better still, the technique backfired. Tag characters are so vanishingly rare in legitimate email that their mere presence became a high-confidence signal, flipping a would-be evasion trick into an indicator of compromise. Microsoft’s practical advice is blunt: normalize before you match, stripping or folding invisible code points out of subject and body text before any keyword, signature or regex logic gets a look at them.
The wider lesson is less comfortable. Attack techniques polished in AI security research do not stay in the AI lane — they drift downhill into ordinary, high-volume criminal spam, where the ideas get reused by people with much cruder ambitions.