The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →ASCII smuggling is the use of invisible Unicode characters to hide or alter text that looks ordinary when displayed. In a phishing campaign analyzed by Microsoft in 2026, attackers inserted an invisible character inside finance-related lure words—so a message could show “funding” to a person while its underlying text contained a character between “fun” and “ding.” This can interfere with some text-matching and classification systems, but it does not automatically bypass email security.
What ASCII smuggling means
ASCII smuggling places characters that do not normally render as visible glyphs into text. A recipient may see an ordinary word, while software processing the message receives a different sequence of Unicode code points.
Microsoft’s 2026 analysis focused on Unicode’s Tags block, U+E0000–U+E007F. Tag characters can correspond to printable ASCII characters. They are not the same as ordinary visible letters, even when the text appears unchanged on screen.
The phrase is also used in AI security discussions. A page, document, or email can contain invisible instructions that remain present in the text supplied to an AI model. Whether a model follows them depends on its design, access, and safeguards. The 2026 phishing use Microsoft observed had a different purpose: the tag character was used to break up lure words, not to encode a hidden ASCII message.
Quick wins for a faster PC:
Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How an invisible character can change what software sees
A word split beneath the visible text
Microsoft’s example inserts U+E0020, the invisible TAG SPACE, into “funding.” The visible word can remain “funding,” while the transmitted sequence is fun⟨U+E0020⟩ding.
Why matching may be affected
A literal signature searching for the contiguous string “funding” may not match that altered sequence unless the system first normalizes the text or otherwise accounts for the inserted character. A machine-learning classifier may also tokenize the altered input differently. Those are possible effects, not evidence that all filters or classifiers are bypassed; the outcome depends on each system’s normalization and detection pipeline.
Invisible-character evasion predates the term ASCII smuggling. Microsoft documented earlier phishing uses of soft hyphens (U+00AD) and word joiners (U+2060) to fracture keywords. The later campaign reused that broader evasion idea with a different Unicode range.
Rank #2
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What Microsoft observed in the 2026 phishing campaign
Microsoft Security Research published its analysis on September 3, 2026. Microsoft reported that its technique-specific signature rose sharply on February 9, 2026, and that its Defender for Office 365 telemetry recorded more than 2.3 million messages on February 11. The high-volume phase dropped sharply after May 15, with lower residual activity into mid-June. These figures describe Microsoft’s telemetry for a particular signature and activity cluster, not all phishing or all ASCII-smuggling activity.
The messages used finance-themed lures about business funding, loans, and credit lines. Microsoft associated the tag-character activity with a broader SBA-themed phishing campaign and described the observed phase as sent through infrastructure associated with ActiveCampaign, a legitimate email-marketing platform. The broader campaign existed before the tag-character technique appeared and continued after that specific behavior declined.
Microsoft said roughly 96% of the signature volume was associated with the finance-themed pattern. In its Defender for Office 365 telemetry, more than 99% of the observed messages were flagged by other layers that did not depend on direct tag-character detection. Those included sender, IP, URL, and domain reputation; machine-learning classification; brand-impersonation detection; and authentication checks. These are Microsoft-reported results for the activity it studied, not independently audited measurements or a general benchmark for email providers.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
How defenders can reduce the risk
Normalize text before checking it
Normalize or strip invisible characters, including tag characters, in email subjects and bodies before running keyword, regular-expression, or signature checks. Apply the same principle before sending untrusted text to an AI system that ingests email or other external content. Microsoft’s recommendation is: “The core defensive principle is simple: normalize before you match.”
Use Unicode anomalies as one signal, not a verdict
Unusual characters from the Tags block can be a useful anomaly, but flagging every tag character can create false positives. Legitimate sequences include subdivision flag emojis for England, Scotland, and Wales. Defenders should account for valid use rather than treating every occurrence as malicious.
Layer content checks with campaign signals
Character-level checks are more useful alongside evidence such as sender and infrastructure reputation, URL and domain reputation, authentication results, finance-themed sender patterns, and domain churn. Microsoft’s own telemetry illustrates why relying on one character-level indicator is not enough: other layers flagged the large majority of messages it observed.
Rank #4
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Check the full processing path
Email systems differ in where and how they normalize text. Security teams should test their own pipeline, including what text reaches filters and AI applications. For indirect prompt injection, Microsoft also describes defense in depth: detection can help, but permissions, access controls, and limiting the impact of a successful injection matter too.
Useful evaluation questions include whether normalization happens before matching and model ingestion; whether unusual Unicode is detected with legitimate-use exceptions; whether rendered content is checked with OCR; whether reputation, authentication, URL, and behavioral signals complement content checks; and whether AI applications limit permissions and the effects of successful prompt injection. These are assessment criteria, not a comparison or endorsement of specific products.
What the evidence does—and does not—establish
Microsoft’s report documents a specific campaign and its own Defender for Office 365 telemetry. It does not establish how common ASCII smuggling is across email globally, nor does it show that every email provider handles tag characters the same way. The practical lesson is narrower: invisible Unicode can create a mismatch between displayed text and machine-processed text, so normalize before matching and use multiple independent signals to assess suspicious messages.
Free tools Windows power users keep installed
One-click scans. No signup required.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

