# Microsoft flags Unicode-smuggling phishing campaign

_Friday, September 4, 2026 at 11:57 AM EDT · Security · Latest · Tier 2 — Notable_

![Microsoft flags Unicode-smuggling phishing campaign — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoD4eMYuhLT8HvcHbYe8A4hkhmDH1f4pIWTIm5AXKueqdpY1NS8yNiTtlzS4mdIS8PLY8_zM1uQDNpO1U49HCUoJT8nn2Bpb6krpcYpOSQ3H3Z6fUsm-UkoFvj8fk8oShK0eUhO6px8hox_ZzlnX8tu0pJKpJ3UAF2Vcb3XyBXjCt_8uD8OOkMMgUjv8Pc/s1700-nu-rw-lo-l85-e365/emails.jpg)

Microsoft is alerting customers to a high-volume phishing campaign that used invisible Unicode tag characters to split financial-lure words and evade literal email-filter matching. The company said the activity began in early February 2026 and, during a roughly three-month high-volume phase, reached an estimated 1 million to 2.37 million messages on weekdays. The messages used finance-themed sender domains and were relayed through ActiveCampaign click-tracking infrastructure, according to the report.

## Sources

- [The Hacker News](https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html)

---
Canonical: https://techandbusiness.org/newswire/zdur4hM6fG2ddm6BRZfBOJ
Retrieved: 2026-09-04T20:47:50.399Z
Publisher: Tech & Business (techandbusiness.org)
