Channel sheet · CH-31 · gain 2 min · logged September 29, 2026

Content & SEO in the AI EraDirect input

Microsoft: ASCII Smuggling Moves From AI Prompt Injection to Phishing

Microsoft reports invisible-character ASCII smuggling, first used against AI prompts, is now evading email security filters in phishing campaigns.

By Sophie Lindqvist2 min read348 words

Signal notes

  1. Microsoft says ASCII smuggling has moved from AI prompt injection into phishing campaigns
  2. The technique uses invisible Unicode characters that render blank but carry hidden payload content
  3. Email security tools that only inspect visible text or rendered content can miss the hidden payload
ASCII smuggling crosses over from AI prompt injection to phishing evasion - Microsoft
Input monitorASCII smuggling crosses over from AI prompt injection to phishing evasion - Microsoft — AI-generated

Microsoft reports that ASCII smuggling, a technique first seen in AI prompt injection attacks, has crossed over into phishing campaigns as a way to slip past email security tools.

The technique relies on invisible Unicode characters. An attacker embeds instructions or payload text using characters that render as blank space in a normal email client or chat window. A human reader sees nothing unusual. Software that processes the raw bytes, however — an AI model, a security scanner, or a downstream parser — sees the hidden content.

In the AI context, researchers have documented attackers using these invisible strings to smuggle instructions into large language models, effectively bypassing input filtering. Microsoft now says the same trick is showing up in phishing emails, where it serves the opposite goal: keeping malicious content out of the view of automated defenses rather than injecting instructions into them.

The crossover matters for security teams for a straightforward reason. Email gateways and anti-phishing products typically inspect visible text, URLs, and attachments. Encoding part of the payload in invisible ASCII-adjacent Unicode codepoints means that inspection layer can miss the attack entirely, while the target's mail client still displays a convincing lure.

Microsoft's disclosure lands as enterprises continue to grapple with prompt injection as a class of AI-era threats. The fact that tooling and techniques built for attacking AI systems are being recycled against conventional infrastructure suggests the attack surface is converging rather than splitting into separate "AI security" and "email security" domains.

For operators, the practical takeaway is defensive coverage. Filters that only match on rendered or visible content are blind to this class of payload. Defenses that inspect raw message bytes, including Unicode normalization and detection of unusual codepoint sequences, close that gap. Security teams should verify their email hygiene stack actually inspects the raw stream rather than the sanitized display version.

The technique also underlines an older lesson: Unicode is a feature for internationalization and a liability for parsing. Any system that trusts input because it "looks clean" on screen is making an assumption that invisible characters make unsafe.

via Google News — AI email marketing (Source)

Filed under

  • microsoft
  • phishing
  • ascii-smuggling
  • unicode
  • prompt-injection
Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Staff writer covering business strategy at Mart Signal.

14 articles

Bus out

Next article ›