Leadership1 publisher3 min readPublished
Microsoft's hunt for email-borne prompt injection instead surfaced a three-month phishing campaign hiding tag characters inside words like funding, which puts both problems on one detection team's desk.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
The provenance of this finding is the part worth an hour of a security leader's attention. The hunting logic was built for email-borne cross-prompt injection, content that reads as harmless but carries hidden instructions for whatever model ingests the raw message, and the same hunt became the starting point for the phishing discovery [3]. That is not a lucky tool reuse. Both attacks lean on one property of the Unicode Tags block: characters that software processes and people never see [7]. Microsoft's own framing is that the intent is inverted while the mechanism holds, with the tag characters either smuggling instructions into a model or obscuring keywords before a detector evaluates them [14]. One signature, written once, covers two threat classes that most orgs fund from different lines.
The board-deck version of that is "AI security research pays for itself in phishing defence," and it is incomplete. Microsoft says the majority of the messages were flagged by layered protections rather than by any single Unicode-specific signal [5]. On the blocking question, then, the new signature was close to marginal; what it bought was visibility. That is the trade-off to price honestly, because visibility work is front-loaded and unglamorous. The first version flagged any code point in the range and was too blunt, firing on legitimate mail that turned out to contain the England, Scotland and Wales flag emojis, which are themselves encoded with tag characters [9]. There are 128 code points in that block [11], and the useful signature is the one that knows which of them are innocent.
After those exclusions, the residual hits were mostly gateways, mailbox providers and researchers forwarding test traffic [10]. That tedious baseline is the entire reason a spike was legible at all: hits rose sharply from February 9, 2026 and stayed elevated on weekdays for roughly three months, running to about early May [4][12]. The weekday shape is consistent with an operation run to a work schedule rather than dumped in one burst, though the telemetry as published supports no stronger reading than that [4].
A skeptic would say this is one vendor's telemetry, one campaign, and existing filters caught most of it. On the blocking claim that is fair, and the record here is single-sourced: Microsoft reporting on its own product [5]. The record does not say who ran the campaign, how many messages moved, whether other providers saw the same February spike, or what the evasion actually bought in delivery. What it does establish is the direction of reuse, from AI red-teaming write-ups and conference talks through 2025 [8] into a high-volume commodity phishing run against keyword parsers [1][2].
So the decision this quarter is narrow and organisational. Whoever writes your rules for handling the U+E0000 range in the mail gateway [6] should be the same people writing them for the assistant that reads the mailbox, because the character range is identical and only the target of the deception differs [14].
Ranked by verification strength, evidence, and original report placement.
Microsoft researchers observed a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized in AI prompt injection research as ASCII Smuggling.
Instead of using the characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them.
The finding emerged from Microsoft Defender for Office 365 prompt injection protection research; the same hunt designed to identify prompt injection risk in email, including hidden instructions for an AI system that ingests the raw message, became the starting point for the phishing-evasion discovery.
In Microsoft telemetry, hits on a hunting signature designed to detect ASCII smuggling increased sharply beginning February 9, 2026, and remained elevated on weekdays for approximately three months.
Microsoft Defender for Office 365 telemetry showed that the majority of the messages were flagged by layered protections rather than by reliance on a single Unicode-specific signal.
The most abused range is the Unicode Tags block, U+E0000 to U+E007F, which contains a shadow copy of the printable ASCII characters (U+E0041 mirrors 'A', U+E0061 mirrors 'a'); it was originally intended for language tagging and is now largely deprecated.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Vendor telemetry, unusually well shown
Every count in this story, the 21,000 messages on February 8, the 1.3 million the next day, the roughly 150 sender domains, comes from Microsoft's own Defender for Office 365 telemetry, and nobody outside the company has seen the underlying data. What lifts it above ordinary vendor disclosure is the method write-up: Microsoft names the false positives that broke its first signature and concedes that its Unicode signal was not what flagged most of the mail. The encoding claims are separately verifiable against the Unicode standard, which is more than can be said for the volumes.
One campaign, counted daily
Attacker uptake is the one thing here measured rather than argued: a signature holding at tens of thousands of hits a day jumped past a million, kept a weekday cadence for three months, and fell away after May 15, 2026. But this is one group of roughly 150 sender domains, not a technique spreading across unrelated actors, and the whole count sits inside one mail provider's view of the world.
Framing outruns the mechanism
Microsoft is conservative about the danger and generous about the novelty. The crossover headline does the work, yet the attacker's actual goal, splitting a lure word so a keyword matcher misses it, is an evasion as old as spam filtering, wearing a code range that AI red teams made famous. The AI connection is real in provenance, since the hunt was built for prompt injection, and thin in mechanism, since no model was targeted in the campaign described.
A detection team writing up its own detection
The throughline is that prompt injection protection work for Defender for Office 365 paid an unexpected dividend, which is also the product argument Microsoft would most like made. The telemetry, the signature and the conclusion all come from the same vendor, with no external validation offered and no indicators released that would let anyone check. Cutting the other way: the post admits its Unicode-specific signal was not the thing that caught the mail, and it publishes its own false positives, neither of which a pure marketing piece would carry.
Mechanism solid, counting unaudited
The split runs straight down the middle of this story. The Tags block, the ASCII shadow copy and the fact that the Wales flag is built from invisible tag characters can all be checked by anyone with a Unicode table and a decoder, while the numbers have no such check available outside Microsoft, and the account in front of us stops mid-sentence before the decline figures are set out. Middling confidence follows from that, not from any doubt about the encoding.
security
Phishing crews adopt the AI red team's invisible Unicode trick to break keyword filters4 publishers
product
Spammers pick up the invisible Unicode block that AI jailbreakers found first1 publisher
product
Claude's Gmail agent turns one approval toggle into your whole outbound policy1 publisher
build
Spammers split "funding" with an invisible Unicode tag to slip past keyword filters3 publishers
Publishers with included, body-backed reporting in this cluster.
1 article · September 6, 2026