<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh" -->

---
title: Microsoft built a prompt injection detector. Then it...
description: Microsoft Defender for Office 365 caught a large-scale phishing campaign using invisible Unicode tag characters (U+E0000 to U+E007F) embedded in words like...
canonical: https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Microsoft built a prompt injection detector. Then it caught a phishing campaign instead. | daily.dev
og:description: Microsoft Defender for Office 365 caught a large-scale phishing campaign using invisible Unicode tag characters (U+E0000 to U+E007F) embedded in words like...
og:url: https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh
og:image: https://api.daily.dev/og/posts/Uur7BjAnH.png
og:image:alt: Microsoft built a prompt injection detector. Then it caught a phishing campaign instead.
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Microsoft built a prompt injection detector. Then it caught a phishing campaign instead.

**[The New Stack](https://daily.dev/sources/newstack)** · 4 min read · 0 upvotes · 0 comments

## Summary

Microsoft Defender for Office 365 caught a large-scale phishing campaign using invisible Unicode tag characters (U+E0000 to U+E007F) embedded in words like 'funding' and 'loan' to dodge spam filters and ML classifiers. A hunting signature for this 'ASCII Smuggling' technique jumped from roughly 21,000 hits to over 2.3 million in three days. The same technique, previously demonstrated against LLMs to smuggle hidden prompt injections, poses a risk to AI agent pipelines that ingest untrusted text, since standard Unicode normalization (NFC/NFD) doesn't strip these tag characters and tokenizers handle them inconsistently. Developers are advised to strip tag characters before text reaches a model, test their specific tokenizer's behavior, and watch for legitimate exceptions like UK subdivision flag emojis that rely on the same tag-character mechanism.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thenewstack.io/unicode-ascii-smuggling-ai-pipelines>

## Questions this post answers

### What is ASCII smuggling and how does it use Unicode tag characters to evade filters?

ASCII smuggling embeds invisible Unicode tag characters, in the range U+E0000 to U+E007F, inside words so the text a person reads differs from what software actually processes. For example, 'funding' can contain a hidden tag character making it fun[U+E0020]ding under the hood, which lets attackers slip past keyword-based spam filters and ML classifiers while showing recipients an ordinary-looking message.

_daily.dev surfaces developer coverage of emerging attack techniques like unicode-based evasion for teams hardening AI pipelines._

### Does Unicode normalization like NFC or NFD remove hidden tag characters used in prompt injection attacks?

No, standard Unicode normalization forms NFC and NFD are not designed to strip Unicode tag characters and won't reliably remove them from text before it reaches a model. Developers building AI pipelines need explicit filtering logic that removes characters in the U+E0000 to U+E007F range rather than relying on normalization alone.

_teams hardening agent pipelines against prompt injection track fixes and gotchas like this one on daily.dev._

### How much did Microsoft's ASCII smuggling hunting signature detections increase during the phishing campaign?

Detections jumped from roughly 21,000 messages the day before the campaign to more than 1.3 million the next day, then passed 2.3 million just two days later. The campaign used invisible Unicode tag characters embedded in financial phishing keywords like 'funding,' 'loan,' and 'credit' to bypass spam filters at scale.

_daily.dev helps security-minded developers keep tabs on fast-moving phishing and evasion campaigns like this one._

## Similar posts on daily.dev

- [When Email Speaks to Machines](https://daily.dev/posts/when-email-speaks-to-machines-tdcjsmpjk) · InfoSec Write-ups · 0 upvotes · 0 comments
- [Ghosts in the Machine: ASCII Smuggling across Various LLMs – FireTail Blog](https://daily.dev/posts/ghosts-in-the-machine-ascii-smuggling-across-various-llms-firetail-blog-y2cc0ahnq) · Security Boulevard · 0 upvotes · 0 comments
- [GhostCode attackers hijack Microsoft 365 accounts with device codes](https://daily.dev/posts/ghostcode-attackers-hijack-microsoft-365-accounts-with-device-codes-czidg2xfc) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#microsoft](https://daily.dev/tags/microsoft), [#phishing](https://daily.dev/tags/phishing), [#prompt-injection](https://daily.dev/tags/prompt-injection)

[View this post on daily.dev](https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Microsoft built a prompt injection detector. Then it caught a phishing campaign instead.","url":"https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh"},"datePublished":"2026-09-04T21:11:59.134Z","dateModified":"2026-09-06T22:28:34.204Z","description":"Microsoft Defender for Office 365 caught a large-scale phishing campaign using invisible Unicode tag characters (U+E0000 to U+E007F) embedded in words like...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b267d1b2b405b8ecbf9dd09ad9634974?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/b267d1b2b405b8ecbf9dd09ad9634974?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"The New Stack","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"The New Stack","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/newstack","url":"https://daily.dev/sources/newstack"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,microsoft,phishing,prompt-injection","timeRequired":"PT4M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"The New Stack","item":"https://daily.dev/sources/newstack"},{"@type":"ListItem","position":3,"name":"Microsoft built a prompt injection detector. Then it caught a phishing campaign instead."}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/microsoft-built-a-prompt-injection-detector-then-it-caught-a-phishing-campaign-instead--uur7bjanh#faq","mainEntity":[{"@type":"Question","name":"What is ASCII smuggling and how does it use Unicode tag characters to evade filters?","acceptedAnswer":{"@type":"Answer","text":"ASCII smuggling embeds invisible Unicode tag characters, in the range U+E0000 to U+E007F, inside words so the text a person reads differs from what software actually processes. For example, 'funding' can contain a hidden tag character making it fun[U+E0020]ding under the hood, which lets attackers slip past keyword-based spam filters and ML classifiers while showing recipients an ordinary-looking message. daily.dev surfaces developer coverage of emerging attack techniques like unicode-based evasion for teams hardening AI pipelines."}},{"@type":"Question","name":"Does Unicode normalization like NFC or NFD remove hidden tag characters used in prompt injection attacks?","acceptedAnswer":{"@type":"Answer","text":"No, standard Unicode normalization forms NFC and NFD are not designed to strip Unicode tag characters and won't reliably remove them from text before it reaches a model. Developers building AI pipelines need explicit filtering logic that removes characters in the U+E0000 to U+E007F range rather than relying on normalization alone. teams hardening agent pipelines against prompt injection track fixes and gotchas like this one on daily.dev."}},{"@type":"Question","name":"How much did Microsoft's ASCII smuggling hunting signature detections increase during the phishing campaign?","acceptedAnswer":{"@type":"Answer","text":"Detections jumped from roughly 21,000 messages the day before the campaign to more than 1.3 million the next day, then passed 2.3 million just two days later. The campaign used invisible Unicode tag characters embedded in financial phishing keywords like 'funding,' 'loan,' and 'credit' to bypass spam filters at scale. daily.dev helps security-minded developers keep tabs on fast-moving phishing and evasion campaigns like this one."}}]}
```

