Cybersecurity
Microsoft flags phishing campaign using invisible Unicode
Microsoft said a phishing operation used invisible Unicode tag characters to split lure words, evade email filters and send millions of messages a day before activity dropped in May 2026.
- Microsoft said attackers used invisible Unicode tag characters to split finance-related lure terms so email filters were less likely to match them.
- Microsoft said the campaign began in early February 2026, peaked on 26 February and fell sharply after 15 May 2026.
- Microsoft estimated weekday volume at between 1 million and 2.37 million messages and said the activity largely paused at weekends.
- Microsoft said the campaign was linked to a wider phishing effort that used ActiveCampaign to send AI-generated emails to Small Business Administration loan applicants.
Microsoft said the campaign inserted invisible Unicode tag characters into ordinary-looking lure words so that recipients still saw readable text while filters were less likely to recognise the terms. The company said the method let attackers evade keyword and signature checks.
According to Microsoft, the activity entered a high-volume period for about three months before dropping sharply after 15 May 2026. It said weekday traffic ranged from 1 million to 2.37 million messages, with a peak on 26 February and little activity at weekends.
Microsoft said the operation was connected to a broader phishing campaign that used ActiveCampaign to distribute AI-generated emails aimed at Small Business Administration loan applicants. Fortra's FIRE team had disclosed that related campaign in September 2025 and said it was collecting business and financial details for later spear-phishing.
ActiveCampaign said it had tested its content-moderation systems against messages containing invisible Unicode characters and that such emails received the same moderation outcome as unobfuscated ones. It also said heavy use of the technique was treated as a suspicious signal, while Microsoft said legitimate marketing infrastructure could make the traffic harder to filter by reputation.
Named in this story
Companies
- Microsoft
- alerted to the phishing campaign and published the findings
- ActiveCampaign
- its platform carried the emails and it responded on moderation
Organisations
- Microsoft Security Research team
- explained how the invisible characters were used
- Fortra Intelligence and Research Experts (FIRE) team
- disclosed the related campaign in September 2025
Governments and agencies
- Small Business Administration
- its loan applicants were among the earlier targets
How the source tells it
The piece reads as a technical security alert, with repeated emphasis on novelty, scale and urgency.
- novelty It explicitly marked the character choice and the campaign scale as the new element.
- urgency The lead framed the story as a warning and stressed an active phishing operation.
- scale emphasis It repeated million-message estimates, a daily peak and weekday volume figures.