Tendvane

← All articles

ScamsSeptember 5, 2026

Millions of phishing emails slipped through by hiding a character nobody can see

The word in the email said funding. What the filter read was fun, then a character it did not recognise, then ding. That one gap was enough to walk millions of messages past defences that were looking for exactly that word.

Microsoft researchers Noam Kochavi and Sarah Wolstencroft published the details on 4 September. The trick is called ASCII smuggling, and it uses Unicode tag characters, a block of code points that render as nothing at all on screen. Until now they were mostly discussed as a way of hiding instructions inside text that an AI model would obey and a human would never see. This campaign pointed them at ordinary keyword matching instead. The numbers are the striking part: around 21,000 messages on 8 February, 1.3 million the next day, a peak of 2.37 million in a single day in late February, roughly 150 finance-themed sender domains, and a rhythm of weekday bursts and silent weekends that ran on until it faded away after 15 May. The lures aimed at people applying for US Small Business Administration loans, and the mail went out through ActiveCampaign's marketing platform so the sending infrastructure looked entirely respectable.

None of that is something you could spot by squinting at an email, and that is rather the point. A message that lands in your inbox has not been vouched for by anyone; it has merely failed to trip a filter. So judge it by what it wants from you. Money, a login, a document you were not expecting, a deadline. If a mail about a loan, an invoice or a delivery needs you to act, close it and go to the company through an address or app you already had.

If a link did land somewhere it shouldn't and your browser now opens on a search page you never chose, that is what Tendvane's browser hijacked repair wizard is for.

Sources

Download Tendvane