Advisory
Published 2026-09-03
Verified 2026-09-19

Microsoft: finance phishing uses invisible Unicode tag characters to evade email filters

Microsoft Security Research (3 September 2026) documents a high-volume phishing campaign that inserts invisible Unicode Tags-block characters (U+E0000-U+E007F) inside finance lure words such as funding so human readers still see the word while keyword/regex filters miss the contiguous string. Telemetry tied to a Defender for Office 365 hunting signature rose from about 21,000 hits on 8 February 2026 to more than 1.3 million the next day, stayed elevated on weekdays for roughly three months, and dropped sharply after 15 May 2026 (weekday peaks cited up to about 2.37 million). Microsoft links the Unicode-obfuscated wave to a broader ActiveCampaign-relayed SBA/finance-themed phishing cluster previously described by Fortra, with disposable finance-themed domains and click-tracking via ActiveCampaign hosts. Defenders should strip or normalise Unicode tag characters before keyword detection, hunt U+E0000-U+E007F outside legitimate subdivision-flag emoji use, and treat marketing-platform abuse as a reputation-filter complication.

Product
Email filters / Microsoft Defender for Office 365 hunting context
Exploited in Australia?
unknown
Patch to
Normalise/strip Unicode Tags before content matching; hunt tag-character smuggling; review ActiveCampaign-origin finance mail

Primary: Microsoft Security Blog (3 Sep 2026) ยท Vendor: The Hacker News (4 Sep 2026)

tech email identity ai