Microsoft researchers spotted something odd in early 2026. A wave of emails promised business funding and fast cash. The messages looked ordinary to the human eye. Yet they slipped through filters that should have caught them cold.
The secret lay in characters no one could see. Invisible Unicode tag characters split apart words like “funding” and “loan.” Filters scanning for obvious scam language came up empty. Recipients saw clean text. The campaign had sent between one million and 2.37 million messages on its busiest weekdays. The Hacker News laid out the numbers.
But this was no ordinary spam run. The attackers adapted a method first described for confusing AI models. They turned the technique against email security tools instead. “Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as ‘funding’ to prevent email filters from parsing them,” the Microsoft Security Research team said.
The activity started in February. It hit high volume for three months. Then it dropped sharply after May 15. Weekends stayed quiet. Mondays brought fresh batches. Peak day came on February 26. The pattern pointed to automation running on a schedule. And the messages tied back to a larger operation that abused the ActiveCampaign marketing platform. Those earlier emails targeted applicants for Small Business Administration loans with AI-written copy.
Top sender domains repeated across the flood. Guardiangrowthfunding.com. Digitalcapitalboost.com. Thebusinessloanexpress.com. Yourlocfunding.com. Advancefundingboost.com. The list went on. Each pushed variations on the same promise of easy capital. Recipients who clicked faced further risks. Some led to credential theft pages. Others dropped infostealers. The exact final payloads varied. The delivery method stayed consistent.
This campaign did not arrive in isolation. Recent reports show phishing volumes climbing across the board. Microsoft alone blocked roughly 8.3 billion email-based threats in the first three months of 2026. The Anti-Phishing Working Group counted more than 971,000 unique phishing attacks in that same quarter. Numbers keep rising. Microsoft Security Blog detailed the scale.
And the tricks grow more sophisticated. Some operators now push legitimate remote monitoring tools instead of custom malware. A separate campaign hit 46 countries. It leaned on tax forms, invoices and shipping notices to trick users into installing signed software from GoTo Resolve, ScreenConnect, ConnectWise or LogMeIn. Nearly half the hits landed in the United States. The approach bypasses signature checks. Trust in familiar business tools does the rest. SC Media covered the findings on September 3.
Debt-relief offers have joined the mix. Check Point blocked nearly 25,000 emails aimed at more than 9,000 organizations in a two-week span last month. The messages skipped malicious links and attachments. They simply urged recipients to call a number. Once on the phone, attackers could extract information the old-fashioned way. No filter could see what happened next. Check Point Blog reported the numbers on August 25.
Phishing kits keep evolving too. The Outsider kit survived a major takedown in June. Google sued. The FBI seized servers and wallets. Yet more than 700 fresh phishing pages appeared within weeks. The kit offered hundreds of templates for banks, brokers, government agencies and more. Affiliates simply kept going. Infosecurity Magazine broke the story on September 3.
AI plays a growing role. Some campaigns generate entire emails with large language models. Others use the same models to polish lures or create convincing images. One analysis found 85 percent of attacks now carry some AI component. Click rates climb when personalization enters the picture. A single stolen credential can open corporate networks, customer databases and financial systems.
So defenders face a moving target. Traditional keyword filters fail when characters disappear. Signature-based detection misses signed legitimate tools. Phone calls bypass email gateways entirely. And the volume keeps climbing. One leaked database of 6.8 billion email addresses surfaced earlier this year. Even a tiny success rate from that list could yield tens of thousands of victims.
Organizations have responded with layered controls. Behavioral analysis catches odd user actions. Multifactor authentication raises the bar. Regular credential audits close old holes. Training still matters. Yet employees remain the weakest link when messages look trustworthy and urgency feels real.
The invisible Unicode trick may fade as filters adapt. Microsoft and others have already updated detection logic. But attackers rarely stop at one method. They test. They iterate. They combine old ideas with new twists. This particular campaign shows how research meant to expose AI weaknesses can be flipped into a practical weapon against everyday defenses.
Security teams now watch for anomalies in character encoding. They monitor sudden spikes in funding-themed messages from unfamiliar domains. They track which remote tools appear in their environments without authorization. The work never ends. Because the inbox never stays quiet for long.
Recent activity points to no slowdown. Tax-themed attacks surged more than 400 percent in the spring. World Cup lures produced a 500 percent jump. New stealer families surface monthly. The economics favor the attacker. Cheap compromised mailboxes, automated sending infrastructure and low-cost kits produce high returns.
One fact stands out. The campaign that used invisible characters ran on a weekly rhythm for months. It reached millions. It adapted an academic technique for criminal gain. And it succeeded long enough to force updates across the industry. That pattern repeats across the threat landscape. Innovation on one side demands faster response on the other.
Invisible Ink in Your Inbox: How Unicode Tricks Flooded Millions of Emails Past Defenses first appeared on Web and IT News.
The Progressive Supranuclear Palsy Market Report provides real-world prescription pattern analysis, emerging therapies, market share…
Eric Trump stood before a crowd in Abu Dhabi late in 2024 and made a…
Apple Inc. has kept its plans for a major iPhone overhaul on schedule for 2027.…
President Donald Trump didn’t mince words on Friday. After a blockbuster jobs report, he demanded…
In the remote town of Tumbler Ridge, British Columbia, a single morning in February shattered…
Fairphone has spent more than a decade proving a point. Smartphones don’t have to break…
This website uses cookies.