You’re scanning your inbox on a Tuesday morning, coffee in hand. An email from what looks like your bank sits near the top. The subject line reads normally. The body text reads normally. Your email provider’s spam filter waved it through without a flinch. And yet somewhere inside that message, tucked between the letters you can see, there’s a block of characters your eyes will never register — and neither did the filter.
That’s ASCII smuggling. And according to Microsoft, spammers are now using it a lot more than they used to.
What’s actually happening here
Let me explain this the way I’d explain it to my mom, because it’s genuinely one of the more elegant tricks in the book.
Every character you read on a screen has a number behind it. That system is called Unicode, and it covers a staggering amount of ground — every alphabet, every emoji, every symbol. But Unicode also includes a block of characters that don’t display as anything at all. They’re not blank spaces. They’re not tiny dots. They render as literally nothing to a human reader.
Software, though, still reads them. It has to. To a program, those invisible characters are just more data to process. So if you encode a hidden message using them and slip it into an ordinary-looking email, you’ve created something like invisible ink — except the recipient’s software is the one holding the black light.
For a long time, this block of Unicode sat around mostly unnoticed. Then people figured out what it was good for.
The AI connection
The first popular use of this trick was against AI systems. If you follow this site, you’ve probably run into the term prompt injection — the practice of sneaking instructions into content that an AI model will read, hoping the model follows those instructions instead of the ones its user gave it.
ASCII smuggling made prompt injection much harder to spot. You could hide a set of instructions inside a document, a web page, or an email, and a human reviewer would see nothing unusual. The AI, reading the raw text, would see the instructions clearly. It’s a mismatch between what people perceive and what machines perceive, and attackers love that kind of gap.
Here’s where the story takes an unexpected turn. Microsoft found this crossover while doing research on prompt injection protection for Defender for Office 365 — work aimed squarely at the AI problem. What their telemetry showed instead was the technique migrating sideways, out of AI attacks and into plain old phishing.
Why spammers want it
Email filters are pattern matchers at heart. They look for suspicious links, known scam phrases, sketchy sender behavior, and thousands of other signals. They’re pretty good at it.
But a filter has to agree with itself about what the text says. If invisible characters are scattered through a message, the string a filter examines may not match the string a human eventually reads. A phrase on a blocklist can be broken apart by hidden characters and slide right past. Meanwhile the person opening the email sees a clean, ordinary sentence.
That’s the whole appeal. It’s not a new kind of scam — it’s the same phishing that’s been around forever, wearing a coat that filters can’t see through. Microsoft reports a sharp increase in this approach across phishing campaigns.
What this tells us about the AI era
This is the part I find most interesting, and it’s why I think it matters for anyone trying to understand where AI security is heading.
We tend to talk about AI attacks as a separate category — its own problem space with its own defenders and its own vocabulary. What this story shows is that techniques don’t respect those boundaries. A trick developed to fool language models turned out to work just as well on email infrastructure that predates those models by decades. The attackers didn’t need to be AI specialists. They just needed to notice that the same blind spot existed in both places.
Expect more of this in both directions. Old attack techniques will get pointed at AI agents, and AI-era techniques will get pointed at everything else. The people finding these overlaps are motivated and patient.
What you can actually do
Not much at the individual level, honestly, and I’d rather tell you that than pretend otherwise. You can’t see invisible characters by squinting harder. This is a problem for the platforms — for the people building filters to normalize text before they analyze it, stripping or flagging hidden characters instead of quietly processing them.
What you can do is keep the habits that work regardless of what’s hiding in the markup. Verify unexpected requests through a separate channel. Be suspicious of urgency. Check where a link actually goes before you click it.
The trick here is clever, but the goal behind it is old and familiar. It still needs you to believe the email. That part hasn’t changed.
🕒 Published: