Include:
Tech
Cybersecurity
Business Strategy
Channel Insights
Stay Connected
Acer America
Acer America Corp. is a computer manufacturer of business and consumer PCs, notebooks, ultrabooks, projectors, servers, and storage products.

Location

333 West San Carlos Street
San Jose, California 95110
United States

WWW: acer.com

ChannelPro Network Awards

hello 2
hello 3

News & Articles

October 2, 2026 |

What is ASCII smuggling? Email phishing attacks expose a deeper trust problem

The real phishing problem isn’t how clever the attacks are getting. It’s that email still starts from a position of trust.

How attackers hid email phishing attacks in plain sight

A phishing campaign that sent as many as 2.37 million messages per weekday shows how attackers can exploit a problem that has followed email for decades. Because email was designed to accept communication from previously unknown senders, modern defenses must continually determine which messages should be blocked, quarantined or delivered.

Using telemetry from Defender for Office 365, Microsoft Security researchers said the campaign surged in February 2026, with weekday traffic ranging from roughly 1 million to 2.37 million messages before dropping sharply after May 15. The finance-themed emails promoted business funding and lines of credit. Microsoft connected the activity to a broader Small Business Administration-themed phishing operation previously documented by Fortra.

The attackers used an unusual variation of an old evasion technique. They inserted invisible Unicode tag characters inside financially significant words. To a recipient, “funding” still looked like “funding.” Underneath, however, an invisible character split the word, potentially preventing literal keyword rules, regular expressions or some machine-learning systems from interpreting it normally.

Microsoft described the technique as a variation of “ASCII smuggling,” a term popularized by AI prompt-injection research. In those attacks, Unicode tag characters can encode hidden instructions intended for an AI assistant. This campaign used characters from the same Unicode block for a different purpose: inserting an invisible separator inside financially significant words so some email-security systems might no longer recognize them normally.

“A string can therefore carry a message that is not readable to a human but will be processed by any language model or other software that receives a copy of the email content,” wrote Noam Kochavi and Sarah Wolstencroft in a recent Microsoft blog on the attack.

Microsoft noted that the campaign did not encode a hidden message. More precisely, it used invisible-character insertion with a code point associated with ASCII smuggling.

That raises a broader question: Why can such a small manipulation still create problems for modern email security?

The campaign did not defeat defenses

It is important to note that Microsoft’s security did not broadly fail, even though the technique initially created an opening for cybercriminals. Microsoft said other layers of protection flagged more than 99% of the messages in its telemetry, including sender and domain reputation, authentication checks, machine-learning models and brand-impersonation detection.

In this case, the company advised defenders to normalize or strip invisible Unicode characters before applying content-based detection. That recommendation addresses the immediate technique. But it does not address the larger issue. Attackers can change domains, wording, encoding and delivery methods faster than defenders can build specific detections for every variation.

Catching more than 99% of a campaign demonstrates the strength of layered email defenses. It also exposes their structural limitation. At this scale, even a small residual can create meaningful risk. Every new evasion technique forces defenders to identify another variation. The question is therefore not whether layered detection works. It does. But detection capabilities alone should not determine how much trust a message receives. That is where the story becomes less about Unicode and more about the underlying trust model of email itself.

The email phishing attack problem that predates AI

Mailprotector founder and CEO David Setzer argues that the core issue dates back to the origins of email. “Email is not an app owned by anyone. It’s the expression of the SMTP protocol which was created for the ARPANET. It was created as an open protocol because the closed network controlled trust,” Setzer said. Email developed in an era when access to the underlying network itself provided much more control than today’s open internet.

An attacker does not need to make a message perfect. They only need to avoid enough signals to get past enough layers. That creates an ongoing cycle: attackers introduce a new evasion technique, defenders add another detection, and attackers adjust again.

What if email started from the opposite assumption?

Setzer’s argument is to reverse that model. “If we’re ever going to solve this problem, we have to flip the email’s trust assumption. We’ve been fighting the wrong side of asymmetric warfare for too long.” That means instead of treating incoming mail as legitimate until something identifies it as dangerous, organizations should treat messages as untrusted until the sender or message earns permission.

That shifts the question from: “Can we find what is wrong with this message?” to: “What evidence do we have that this message should be trusted?” The distinction matters because phishing techniques will continue to change even if defenders successfully block this particular Unicode trick.

Why MSP email security has to move beyond detection

For MSPs, the campaign highlights the limits of focusing only on individual phishing techniques and simulations. Providers still need layered email defenses, authentication controls and up-to-date detection capabilities. Those controls remain essential.

But attackers can continually change the signals those systems evaluate. A model built around verification rather than assumed trust could reduce the burden on users trying to identify convincing phishing messages and on MSPs responding to each new evasion technique as it appears.

“Considering over 90% of attacks are delivered through email and the increasing speed at which the attacks are evolving, MSPs should remain focused on strong layered email security as a core tenet of their security program,” Setzer said. “And that program now more than ever needs to be centered on questioning trust.”

What a zero trust approach to email security looks like for MSPs

In practice, a zero trust approach to email means treating every message as potentially untrusted until multiple signals establish confidence.

What changes under a zero trust model is how uncertainty is handled. A message that passes content inspection should not automatically gain full access to the recipient or be allowed to prompt a sensitive action. Mail from an unfamiliar or insufficiently verified source should be treated differently. It could be quarantined, stripped of active links and attachments or opened in isolation. It can also be subjected to additional verification before a payment, credential submission, or data transfer is permitted.

Organizations can verify sender identity and domain authentication, check whether the message matches a known communication pattern, restrict risky links or attachments, and scrutinize senders, devices or behaviors that fall outside the norm. Instead of relying on one filter to decide whether an email looks malicious, the system continually evaluates whether it can trust the message, sender and requested action.

The Unicode trick may be new. The trust problem is not. And that may be the more important lesson for MSPs: the long-term challenge is not just detecting the next phishing technique. It is reducing how much trust email gets by default.


Zero trust is no longer optional; it’s the new baseline for cybersecurity. Join ChannelPro and your peers for an interactive virtual event on December 2, 2026 to learn how MSPs can implement zero trust frameworks that strengthen defenses, simplify compliance and open the door to scalable, premium security services.

➡️ Register now


Jonathan Browning is executive director of content and engagement for ChannelPro Network. He has been a leader in the IT channel for close to a decade. He’s an avid fan and early adopter of technology. He believes that the managed services industry is the most important driver of economic growth and human innovation in today’s world.

Featured image: DALL-E

Related News & Articles

Free MSP Resources

Editor’s Choice


Explore ChannelPro

Events

Reach Our Audience