Remember when the whole AI security world was panicking about a quiet little technique called ASCII smuggling? Back around 2024 and 2025, the worry was that attackers could hide malicious instructions inside prompts using invisible Unicode characters. Tag characters — the kind that carry zero visual weight — could slip a “forget your rules and do this instead” payload right past a model’s guardrails. Humans reading the prompt saw nothing. The model reading the prompt bytes saw a command.
It sounded like a clever hack reserved for people who fight AI. The defenders patched, the attackers moved on, and the technique faded from the headlines. But the underlying trick never died. It just found a more profitable customer: spammers.
Microsoft’s Defender for Office 365 team has been tracking this crossover, and the picture is not flattering for anyone who thought these two worlds were separate. Starting in February 2026, Microsoft observed a sharp uptick in phishing campaigns using ASCII smuggling to hide malicious content inside ordinary-looking emails.ingests text, assume the invisible characters are already looking for a way in.
🕒 Published: