Zero. That’s how many pixels an ASCII smuggling payload takes up on your screen. Not one. The characters are there in the byte stream, sitting inside a subject line or a display name, doing work, and your eyes render exactly nothing. That’s the entire trick, and Microsoft now says email spammers are picking it up to slip past filters.
If you follow AI security at all, you already know this technique from a different context. ASCII smuggling was an attack on models. You hide instructions in an invisible Unicode block, a human reviewer sees a harmless message, and the model reads the hidden text as a command. Classic prompt injection plumbing. What Microsoft reported is that the same trick has crossed over into ordinary phishing, and the increase in its use in phishing campaigns has been sharp.
The part that should bother you
Not the technique. The direction of travel.
We spent the last few years treating prompt injection The assumption baked into that framing is that AI attack techniques stay in AI. They don’t. Invisible Unicode doesn’t care whether the thing parsing it is a transformer or a regex-based spam rule written in 2014. Both read bytes. Both can be fooled by bytes that humans never see.
So what actually happened here is that researchers hardened AI systems against a class of input, published the technique, and the technique found a second job in email. The AI security work created a playbook, and spammers read it.
How Microsoft found it, and why that detail matters
According to the reporting, the finding came out of Microsoft Defender for Office 365 prompt injection protection research. Read that again. The team looking for attacks against AI features in an email product found the same attacks being aimed at the email product itself.
That’s a useful accident, and it says something about where detection capability now lives. The people staring hardest at adversarial text right now are the ones defending models. They have the tooling, the sample corpora, and the habit of asking “what does this look like at the byte level versus the render level.” Traditional anti-spam teams have been solving a different shape of problem. The overlap turned out to be larger than anyone budgeted for.
What this means if you’re buying AI tools
This is where I get to be the annoying reviewer. Every agent platform, every AI inbox assistant, every “let our model triage your email” product is now sitting on a shared attack surface with your spam filter, and most of them have said nothing about it.
Questions I’d ask any vendor before letting their agent touch a mailbox:
- Do you normalize Unicode before the text reaches the model, or do you pass raw input straight through?
- What happens to invisible character blocks in your pipeline — stripped, flagged, or silently forwarded?
- When your agent shows me a summary of an email, am I seeing what the model saw, or a cleaned-up rendering that hides the payload from me too?
- Does your logging capture the raw bytes, so an incident can actually be reconstructed?
That last one gets skipped constantly. If your logs store the rendered text, an invisible-character attack leaves no trace in your audit trail. The incident report will show a perfectly normal message and a model that inexplicably did something strange.
The uncomfortable symmetry
There’s a version of this story that gets told as “old-school spam meets new-school AI attack,” which is tidy and slightly wrong. The better read is that the distinction was never real. Filters and models are both text classifiers with different internals. Anything that breaks the assumption that displayed text equals actual text breaks both.
Which means the fix isn’t AI-specific either. Normalize input. Strip or flag characters that render to nothing. Compare what a human would see against what the parser receives, and treat any gap as suspicious by default. This is unglamorous input-sanitization work, the kind nobody puts on a product page, and it’s the actual defense.
The technique is not new, and neither is the lesson. What’s new is how fast it moved from research demos against models into live phishing, and how few of the AI tools I’ve reviewed this year have anything to say about it. If a vendor pitches you an autonomous email agent and can’t answer the four questions above, you’re not buying a security product. You’re buying a second parser to fool.
🕒 Published: