Invisible Unicode Phishing Wave Slips Past Email Filters

What happened
Microsoft's Security Research team is warning about a "high-volume phishing campaign" that sends millions of messages while using invisible Unicode tag characters to slip past email filtering. The reporting we're working from came through feeds.feedburner.com: Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters.
The clever part is how mundane it is. Invisible Unicode tag characters have been discussed mostly as a way to hide prompt instructions from humans while feeding them to AI models. Here, per Microsoft, the attacker used them differently: to chop up financial lure words like "funding" so filters never parse the word at all. A human reading the message in Outlook sees normal, believable business language. The filter sees fragments that don't match anything on its list. Details beyond that, such as which sending infrastructure was used, which regions were hit hardest, and whether specific Microsoft 365 protections already block it, are worth verifying directly against Microsoft's own advisory rather than assuming.

Why this matters for Pittsburgh small and mid-sized businesses
Almost every client we support runs on Microsoft 365, and most of them assume the built-in filtering catches the obvious stuff. It usually does. This campaign is a reminder that content-matching is the softest layer in the stack, and that "financial lure words" is a bullseye painted on the exact conversations our client base has every day.
Think about who reads those emails locally. A 40-person accounting firm in the middle of a client funding conversation. A law firm's finance manager who moves escrow and settlement money and expects wire instructions from people she's never met in person. A specialty manufacturer in the Mon Valley chasing a supplier deposit. A physician group's billing coordinator working through payer correspondence. In every one of those roles, an email about funding, invoices, or payment changes is not suspicious, it's Tuesday. If the filter doesn't flag it, the only remaining control is a busy human making a snap judgment.
The compliance exposure follows right behind. Under HIPAA, a mailbox compromise that exposes PHI can become a reportable breach with a 60-day notification clock, and the investigation cost usually dwarfs the fraud itself. FTC Safeguards puts CPAs and financial services firms on the hook for documented controls, not good intentions. SOC 2 auditors will ask how you detect and respond to credential theft, and they'll want evidence. And for our defense contractors, CMMC practices around identification, authentication, and awareness training are assessed, not self-graded, so a phishing-driven credential compromise touching CUI is a finding waiting to happen.
There's also the AI angle worth naming out loud. The same invisible-character trick is being used elsewhere to smuggle instructions into content that AI tools read. If you're rolling out Copilot or an internal assistant this year, hidden text in documents and email is now part of your threat model. That belongs in your AI readiness assessment and your acceptable-use policy, not in a post-incident review.
What to do about it this week
- Confirm what your tenant is actually running. Check whether you're on Exchange Online Protection alone or have Defender for Office 365 with Safe Links and Safe Attachments enabled, and verify the policies are applied to every mailbox, including shared and executive ones. "Licensed" and "configured" are different states.
- Turn on impersonation and anti-spoofing protections. Enable user and domain impersonation protection for your finance, executive, and billing staff, and verify SPF, DKIM, and DMARC are published and enforcing on every domain you own, including lookalikes and old marketing domains.
- Pressure-test one wire process, on paper. Pick your highest-risk payment workflow and require out-of-band verbal verification to a known-good phone number for any new or changed payment instructions. No email-only approvals, no exceptions for the boss. Write it down and have finance sign it.
- Close the identity gap behind the phish. Phishing-resistant MFA, blocked legacy authentication, conditional access that limits sign-ins from unmanaged devices, and alerting on new inbox rules and mail-forwarding changes. Most business email compromise cases we see hinge on a forwarding rule nobody noticed.
- Brief the humans on this specific trick. A five-minute all-hands note beats a quarterly module: messages about funding, invoices, or payment changes may look completely normal and still be malicious, so verification is based on the request, not on the wording.
- Fix your reporting path. Deploy the Report Phishing button and make sure reports land somewhere a person triages the same day. Tell staff explicitly that reporting a false alarm is always the right call.
- Add hidden-text handling to your AI plan. Before any new AI workflow automation touches inbound email or client documents, decide how content gets sanitized and who reviews the output. Ask your vendors what they do about invisible characters.
If your tenant hasn't had a documented configuration review in the last year, treat items one and two as a project and put it on the technology roadmap now rather than after an incident.
How we help
PGH Networks runs Microsoft 365 hardening, cybersecurity monitoring with EDR and MDR, security awareness training, and managed IT for small and mid-sized businesses across Pittsburgh, and we map that work to the HIPAA, SOC 2, FTC Safeguards, and CMMC frameworks our clients get audited against. If you'd like us to review your tenant configuration and payment-verification process against this campaign, we'll tell you plainly what's solid and what isn't.
Call 724.888.7007 or reach us through the contact form to get on the schedule.
Related reading

US Now the Top Target in a 46-Country RMM Phishing Wave
A remote-monitoring phishing campaign across 46 countries now targets the US most heavily. What Pittsburgh SMBs should verify and lock down this week.

SynkLoader Malware Is Hiding in Microsoft Teams Chats
A new malware family called SynkLoader is being pushed through Microsoft Teams phishing with a fake lock screen. Here is what Pittsburgh SMBs should do this week.

CISA Warns: Windows Task Host Flaw Now Fueling Ransomware Attacks
CISA confirms ransomware gangs are exploiting a Windows Task Host flaw. Here is what Pittsburgh SMBs should verify, patch, and hunt for this week.