securityonline.info 10 Sept 2026, 07:11 UTC

Microsoft Warns of AI-Inspired Phishing Campaign Hitting Millions

Microsoft Warns of AI-Inspired Phishing Campaign Hitting Millions
CyberSIXT Evidence Panel Source marked as original reporting

MICROSOFT threat researchers have disclosed a large-scale phishing campaign that uses AI-inspired ASCII smuggling to evade detection. Beginning around 8–9 February 2026, attackers deployed messages that insert invisible Unicode tag characters inside financial-lure terms (notably around words such as funding, capital and loans) to split terms like “funding” into “fun” + invisible tag + “ding”.

The technique relies on the Unicode Tags block (U+E0000 to U+E007F), which standard fonts don’t render visibly, allowing recipients to read normal-looking text while filters and tokenisers process altered fragments. The campaign reportedly delivered up to 2.3 million emails per day at peak, with tens of thousands of hits detected initially and more than 1.3 million daily detections soon after, ultimately affecting millions of enterprise mailboxes.

The operation appears to have routed through legitimate infrastructure (ActiveCampaign) and used around 150 disposable sender domains, masking destinations with click-tracking links.

The activity is currently unattributed to a named state actor, though researchers describe a strong link to commercial financial fraud operations and correlate it with a Small Business Administration loan scam observed by Fortra. Evidence points to widespread targeting of corporate employees and enterprise email systems, with the attackers concentrating on high-value financial terms.

In response, Microsoft and partners emphasise layered mailbox protections and vocalise the need to audit text normalisation pipelines, strip or normalise U+E0000–U+E007F characters before tokenisation, and employ visual inspection or OCR to render text as users see it. They advise combining sender authentication, IP reputation, and character sanitisation to counter this evolving evasion tactic.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline