On September 3, 2026, Microsoft's security team published findings on a phishing campaign that should not have worked. Microsoft's security researchers found the campaign reached weekday volumes of up to 2.37 million messages, peaking on February 26, 2026, by hiding its lure words from the AI classifiers built to read them. The trick is called ASCII smuggling: burying invisible Unicode "tag" characters inside a keyword so a human reader, or a preview pane, sees ordinary text while the string a model actually parses has been quietly split apart. It is the same class of trick researchers had spent the past two years warning about in AI chatbots and prompt injection. Now it was aimed at the filters guarding the inbox.
The consensus read of this story is a familiar one: attackers have a new way to defeat the AI systems marketed as smarter than old keyword-matching spam filters, and inboxes are exposed until the filters catch up.
Almost all of a campaign built to evade AI detection came from one place.
It is worth slowing down on that. The same campaign that carefully disassembled its own words to fool a semantic classifier did almost nothing to disguise where it was coming from. Microsoft's researchers found that about 92 percent of the campaign's volume traced back to a single network block, and about 98.5 percent of the messages matched one shared sending pattern tied to the ActiveCampaign marketing platform. A filter with no idea what the words meant, one built only to notice that nearly every message in a flood was coming from the same IP block and the same sending signature, would have flagged this campaign in minutes.
How a filter gets talked past
Security Boulevard reports, citing Microsoft's findings, that the trick worked by inserting a single non-rendering Unicode tag character inside a financial lure word such as "funding", so the word still looked normal to a human recipient while the altered underlying text could defeat exact keyword matches and machine-learning filters. To the human eye, the word simply read "funding." A filter parsing the raw text saw two fragments joined by a character no keyboard produces and no screen renders.
The scale of the escalation is what forced Microsoft to notice. The Register reports, citing Microsoft's findings, that detection went from flagging about 21,000 of these messages on February 8, 2026 to more than 1.3 million the next day, a jump of more than 60 times overnight. The same reporting found the campaign ran from roughly 150 finance-themed sender domains, continued at that volume for about three months, and dropped sharply after May 15, 2026.

This was not a new criminal operation. The Hacker News reports that the underlying phishing operation was first disclosed in September 2025 by Fortra's Intelligence and Research Experts (FIRE) team, which found it collecting detailed business and financial information, the kind used to build convincing, targeted spear-phishing later. ASCII smuggling did not create the operation. It gave an already-running, finance-themed lure a way to keep growing past the exact defense meant to stop it.
The infrastructure gave it away
The campaign's content evasion and its infrastructure told two different stories.
The lesson is not that invisible characters are an unstoppable weapon. It is that a defense built entirely around reading meaning has a blind spot exactly where a much cruder defense does not. A model trained to classify intent from text will miss a keyword it never actually sees. Whether the check comes from a trained model or just a simple rule, noticing that a flood of mail shares one sending signature does not require reading a single word.

That gap matters beyond one email campaign, because the same bet, that an AI model reading behavior can catch what a human or a simple rule would miss, is exactly the bet India has made with its payments system.
India is building the same kind of shield
UPI is not a side player in global digital payments. A Press Information Bureau release marking UPI's tenth anniversary, citing NPCI data, reports that the network processed 24,161.69 crore transactions worth about ₹314 lakh crore in FY2025-26, making it about 49 percent of the world's real-time payment volume in 2025-26. Any blind spot in the AI systems now watching that network would sit on top of close to half of all real-time payments made anywhere on earth.
UPI's scale, in the year ending March 2026
| Metric | FY2025-26 |
|---|---|
| Transaction volume | 24,161.69 crore transactions |
| Transaction value | About ₹314 lakh crore |
| Share of global real-time payment volume | About 49 percent |
Source: Press Information Bureau, citing NPCI data.
Reserve Bank of India has already moved fraud detection onto AI, not for message content but for account behavior. A Press Information Bureau release on RBI's fraud-prevention framework reports that MuleHunter.AI, an AI and machine-learning tool for mule-account detection, is live in 26 banks and being scaled up further, alongside a newly incorporated national body, IDPIC, mandated to detect and analyse digital-payments fraud in real time using AI, machine learning and big-data analytics. The figures for FY2025-26 point to a defense that is working. The Reserve Bank of India's Annual Report 2025-26 shows card, internet and digital-payment fraud cases reported by banks fell from 13,332 cases, worth ₹517 crore, in FY2024-25 to just 293 cases, worth ₹29 crore, in FY2025-26.

The honest objection
The strongest case against reading too much into that collapse is in the RBI's own numbers. The same Annual Report shows that the drop in card, internet and digital-payment fraud cases came even as total bank fraud value across all categories rose from about ₹32,803 crore in FY2024-25 to about ₹48,021 crore in FY2025-26, a roughly 46 percent jump in total fraud value even as the total number of fraud cases across all categories fell. A single category falling to near zero while the total value grows by that much is also consistent with fraud simply moving to categories the AI tools do not yet cover, not with fraud being defeated. That case deserves to be taken seriously; a bank supervisor reading only the 293 would be reading half the report.
It does not, however, explain away the size of the drop inside the one category MuleHunter.AI and IDPIC were built to watch. Cases falling from 13,332 to 293 in a single year is a bigger move than definitional reshuffling alone tends to produce, and it lands in FY2025-26, the same year the RBI took its AI tools live at scale. Both things can be true at once: the AI-monitored category improved sharply, and the broader fraud problem did not shrink with it.
The Signal
The ASCII-smuggling campaign and India's fraud-detection build-out are not the same system, and nothing in either dataset says one predicts the other. But they rest on the identical premise: that a model reading meaning or behavior will catch what a simpler check would miss. The Microsoft campaign is the counterexample. It beat the sophisticated defense and would have tripped the crude one instantly. The question worth watching is not whether MuleHunter.AI and IDPIC can read a mule account's behavior. It is whether anyone is still checking the boring signals, the shared IP block, the shared sending pattern, the account opened from the same device as a thousand others, that a model trained to look for something cleverer might learn to stop noticing.
Reporting basis: the message-volume, timeline and infrastructure-concentration figures are per Microsoft's Security Blog, as also reported by The Register, SC Media and Security Boulevard, all citing the same underlying Microsoft Threat Intelligence research; this is one origin recarried by four outlets. The total FY2025-26 bank fraud value figure and the percentage change from FY2024-25 are The Signal's calculation from the same RBI Annual Report 2025-26 table cited above. The September 2025 origin of the underlying phishing operation is per The Hacker News's report of the Fortra Intelligence and Research Experts (FIRE) team's disclosure. UPI's transaction and value figures are National Payments Corporation of India data, via a Press Information Bureau release. The MuleHunter.AI and IDPIC details are from the Reserve Bank of India and the Government of India, via a Press Information Bureau release. The fraud-case figures are from the Reserve Bank of India's own Supervisory Returns, as published in its Annual Report 2025-26. The overnight increase described as more than sixty times is The Signal's calculation from those same reported figures.



