Invisible Unicode Used to Evade Finance Phishing Filters

Microsoft Secure · Medium sophistication
Last updated September 3, 2026

Microsoft researchers reported a real, high-volume phishing campaign that used invisible Unicode “tag” characters to break up finance-related lure words (like “funding”) so email filters wouldn’t detect them. The emails looked normal to recipients but contained hidden characters in the underlying text, helping the campaign send millions of finance-themed phishing messages over several months.

Key findings

  • Microsoft observed a real, high-volume phishing campaign that inserted invisible Unicode tag characters into finance lure words to evade detection.
  • Signature hits spiked starting February 9, 2026, peaking at “over 2.3 million messages” in a day, and persisted for roughly three months with a weekday-only cadence.
  • The campaign used Unicode Tags block characters (U+E0000 to U+E007F), inserting single invisible separators inside words (e.g., “funding” split by TAG SPACE U+E0020).
  • Most messages clustered around ~150 finance-themed sender domains with business loan/line-of-credit/advance-funding lures.
  • Microsoft notes this is an old evasion idea (breaking keywords with invisible characters), but new in its character choice (Unicode Tags block) and scale.

Who’s being targeted

  • Commonly targeted roles: Finance, Accounts Payable, Executive assistants, Business operations, All employees (email users).
  • Affected industries: Small and medium businesses (general), Finance-themed marketing/loan-related targeting (cross-industry).
  • Attack channels: email.
  • Impersonated: A business lender or funding provider using a finance-themed sender domain.

Awareness takeaways

  • Treat unsolicited ‘business funding’ or ‘line of credit’ emails as suspicious, especially when they come from unfamiliar domains.
  • If an email seems to be ‘dodging’ scanning (e.g., odd copy/paste behavior or inconsistent text), report it, attackers can insert invisible characters that humans won’t notice.
  • Security teams should verify that email security tools normalize/handle Unicode tag characters, not just common zero-width spaces.

Red flags to watch for

  • Sender domain is disposable and finance-themed rather than a known lender
  • Email contains manipulated text that ‘looks normal’ but includes hidden/invisible characters
  • High-pressure/unsolicited funding or credit offer sent in bulk
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

There’s a new finance phishing wave where the scam text looks normal to you, but not to our filters. Microsoft caught a campaign sending millions of emails that secretly split words like 'funding' with invisible Unicode tag characters so keyword filters miss them. These come from random loan domains, promise fast business funding or a line of credit, and push you to click through and fill out an application with your business and identity details. If you get an unsolicited business funding or line-of-credit email from an unknown domain, don’t click, report it to security and delete it.

Similar attacks

Invisible Unicode Used to Evade Phishing Filters

Invisible Unicode Used to Evade Phishing Filters

Microsoft reports criminals are using “ASCII smuggling” (invisible Unicode tag characters) to hide finance-related phishing keywords inside emails so detection rules miss them. The campaign used many disposable, finance-themed sender domains and was relayed through infrastructure tied to the…

September 7, 2026
Phishers Hide “Funding” With Invisible Unicode

Phishers Hide “Funding” With Invisible Unicode

Microsoft reported a real, high-volume phishing campaign (up to millions of emails per day) that hid key “loan/funding” lure words using invisible Unicode characters to slip past email filters. The emails used disposable finance-themed domains and were often routed through ActiveCampaign…

September 4, 2026
DocuSign Share Lure Steals Microsoft 365 Sessions

DocuSign Share Lure Steals Microsoft 365 Sessions

Researchers described an active phishing operation using real DocuSign notifications to trick employees into opening a fake “remittance-advice” document and clicking a hidden malicious link. The attack routes victims through legitimate Microsoft/Google pages before landing on an…

August 28, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026
Criminals Use AI Pretexts to Bypass Guardrails

Criminals Use AI Pretexts to Bypass Guardrails

Research from Cisco Talos and CrowdStrike says criminals are building AI into everyday operations, from writing malicious code to scaling fraud infrastructure. The reports describe real prompt logs where attackers use simple “authorized testing” claims to trick AI tools into helping them, plus…

August 6, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026