Threat Intelligence

Phishing Campaign Uses Invisible Characters to Slip Past Email Filters

The Hacker News · 5 Sept 2026
Key Takeaway Don't rely on spam filters alone—train staff to scrutinise unexpected financial emails and verify payment or funding requests through a separate, trusted channel before acting.

Microsoft Security Research has identified a high-volume phishing campaign that uses a clever trick to sneak past automated email defences. Attackers are inserting invisible Unicode 'tag' characters into the middle of common financial lure words, such as splitting 'funding' with hidden characters, so that spam and phishing filters can no longer recognise the word as a whole. To the human eye, the email reads normally, but to a filter scanning text, the disguised word appears as nonsense or is missed entirely.

This technique differs from earlier reports of invisible characters being used to hide hidden instructions for AI systems. Here, the goal is purely evasion of traditional email security tools that rely on keyword and pattern matching. Because the campaign has reportedly reached millions of inboxes, it highlights how attackers continue to find creative ways to slip financially themed lures past filters that businesses rely on for protection.

For small and medium businesses, this is a reminder that email filtering alone is not foolproof. Financially themed phishing emails, often impersonating invoices, funding requests, or payment notices, remain one of the most common ways attackers gain a foothold, and techniques like this show filters can be outsmarted with simple text manipulation.

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.