Email security

Massive phishing campaign hid malicious signals in plain sight

Account takeovers

A phishing campaign sending as many as 2.37 million messages per weekday used invisible Unicode characters to disguise financially significant words from some email security detections. Microsoft researchers observed traffic ranging from roughly 1 million to 2.37 million messages on weekdays during the campaign’s February 2026 surge. The emails promoted business funding and lines of credit and were connected to a broader Small Business Administration-themed phishing operation.

Attackers inserted invisible Unicode tag characters inside words such as “funding.” Recipients saw the word normally, but the hidden character could break the underlying string and interfere with literal keyword rules, regular expressions or some machine-learning systems. Microsoft described the technique as a variation of ASCII smuggling, although attackers used the characters to evade email detection rather than conceal instructions for an AI model.

The technique did not broadly defeat Microsoft’s defenses. The company said other protections caught more than 99% of the messages in its telemetry, including reputation, authentication, machine-learning and impersonation controls. But the campaign demonstrates the challenge of relying on detection alone: at massive scale, even a small percentage of messages slipping through can create risk, while attackers can continually change domains, wording and evasion techniques.

For MSPs, the bigger lesson is to question how much trust email receives by default. Layered filtering and authentication remain essential, but providers can also apply zero trust principles by scrutinizing unfamiliar senders, restricting risky links and attachments, and requiring additional verification before sensitive actions such as payments or credential submissions. The Unicode technique may be new, but the underlying email trust problem is not.

Zero trust is no longer optional; it’s the new baseline for cybersecurity. Join ChannelPro and your peers for an interactive virtual event on December 2, 2026 to learn how MSPs can implement a zero trust framework that strengthens defenses, simplifies compliance and open the door to new revenue.

Source: ChannelPro

You can skip this ad in 5 seconds