ASCII Smuggling Phishing: What to Do With a Funding Email

Daniel Zimmermann
6 Min Read
A magnifying glass reveals a marked gap in a funding word on an envelope.

A business-funding email can look perfectly readable while carrying characters that a simple text filter handles differently. Microsoft’s September 3 research describes invisible Unicode tags inserted into financial lure words. This was email-filter evasion, not hidden instructions to an AI assistant. The observed high-volume phase ran from February into May; a daily signature count exceeded 2.3 million messages, which does not mean millions of victims. Microsoft says other protection layers flagged more than 99% of the messages. [1]

The useful response is to verify the offer and track what you disclosed. You do not need to find an invisible character before reporting an unexpected request for business or financial information.

What the recipient actually sees

Fictional business funding email with a request for company details.
Illustrative example created for this article; not a recovered email. No functional link or hidden characters.

This fictional example illustrates the visible persuasion, not a recovered message or a working Unicode payload:

From: Funding desk <offer@[sender-domain]>
Subject: Business funding review
Your business may qualify for a new credit line. Review the funding offer and provide your company details to continue.
Button: Review offer

There need not be a spelling mistake or a strange-looking letter. A familiar company name, attractive credit terms and a polished button still leave the important question unanswered: did a lender you independently verified send this request?

Do not reply, follow the supplied contact number or use the message’s link as the source of verification. Open the provider’s known official service independently or contact the adviser you already use. If the email claims a government connection, check that claim through the agency’s official channel.

Record the stage, then choose the response

What happened What to do next
You received or read the email Report it through your mail provider or work security process. Reading the visible text does not establish device infection.
You opened the linked form but sent nothing Close it and record the time and address for the responder. Do not revisit the page to experiment with its fields.
You submitted business or financial information List the exact fields disclosed and notify the appropriate finance or security contact. Prepare for follow-up messages that reuse those details.
You entered a password or approved a payment Use the real service from a trusted device to recover account access, or contact the payment provider promptly. These actions depend on what you actually did.

The questionnaire matters even when it never asks for a password. Fortra’s earlier, September 2025 investigation of the broader SBA-themed activity documented collection of company revenue, requested loan amounts, credit scores and contact information. It found no active host-infection attempt upon clicking in that analysis. Those findings concern that observed flow, not every future funding email. [2]

For example, a follow-up caller who knows the revenue figure you submitted may sound informed. That knowledge is a reason to verify their authority separately, not a reason to approve a transfer or share an account code. Give colleagues a factual heads-up about the exposed details without redistributing the suspicious link.

Why a screenshot is not the whole email

A screenshot preserves what the recipient saw. The original message also preserves headers and the underlying text needed for technical analysis. Save or report the message using your organization’s process; avoid copying only its visible paragraph into a chat and discarding the original.

If an administrator investigates, keep the original evidence intact and analyze a separate copy. Compare what a person sees with what the filtering pipeline processes. A successful test should establish how the deployed controls handle the message, rather than assuming that all products normalize text the same way.

Microsoft recommends checking Unicode handling and layered detections. Legitimate flag emojis can contain tag characters, and a shared marketing platform’s infrastructure is not a standalone indicator of malicious mail. [1] A blanket block can therefore disrupt legitimate communication while missing the next change in the lure.

Do not confuse delivery with trust

An inbox placement is not a verified loan offer. Equally, a report about an evasion technique does not prove that your own defenses failed or that opening one email installed malware. Keep the response tied to the original message, the actions taken and the information disclosed.

If you manage a small business, name one person or existing channel for reviewing unsolicited financing requests. That gives staff a practical alternative to making an urgent decision inside the email itself.

References

  1. Microsoft Security. ASCII smuggling in finance-themed phishing and detection limits. September 3, 2026.
  2. Fortra FIRE. Earlier SBA-themed business-information harvesting campaign. September 18, 2025.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?