AuraTracer智迹闻
中文

EVENT DOSSIER

ASCII smuggling isn't just an AI security risk

2026-09-05 03:23 Cybersecurity 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
3mentions
SummaryAI generated

On February 8, 2026, fraudsters used ASCII smuggling technology to insert invisible Unicode characters in emails to evade keyword matching, launching a global phishing attack targeting the financial sector. The campaign lasted three months, with over 2.37 million emails sent, primarily from approximately 150 temporary domain names during working hours. Microsoft researchers noted that although this attack did not involve AI-generated prompts, it successfully breached traditional email filtering mechanisms. To counter this threat, Microsoft recommends that defenders verify the consistency of character normalization and tokenization in their email processing pipelines, and monitor specific behavior indicators such as high volumes during working hours, financial topics, and temporary domain names to identify potential attacks.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
MicrosoftNoam KochaviSarah Wolstencroft

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Microsoft × Noam Kochavi1Microsoft × Sarah Wolst…1Noam Kochavi × Sarah Wo…1

SignalsSIGNALS

Keyword heat
  • Microsoft1
  • Noam Kochavi1
  • Sarah Wolstencroft1

All reports (1)SOURCES

T The Register en 2026-09-05 03:23

ASCII smuggling isn't just an AI security risk

Microsoft researchers Noam Kochavi and Sarah Wolstencroft discovered that fraudsters used ASCII smuggling techniques (inserting invisible Unicode characters between words to evade keyword matching) to launch large-scale phishing attacks. These attacks began on February 8, with a peak of over 2.37 million emails, and declined gradually by mid-June after lasting for three months. The attacks primarily targeted financial-related topics, sent from approximately 150 temporary domain names, showing a pattern of high activity on weekdays and low activity on weekends. Researchers noted that although this technique is commonly used in AI security to hide prompt injection instructions, no such content was found in this incident; instead, it was used to break through traditional email filtering mechanisms. Microsoft recommends that defenders protect themselves by verifying whether the processing of tag characters follows consistent rules and by scanning specific behavior indicators such as “high activity on weekdays and temporary domain names for financial topics” to identify threats.