Cybercriminals now exploit Unicode characters invisible to the naked eye to bypass your antiphishing filters and deceive AI tools, including Microsoft 365 Copilot. This technique, called ASCII Smuggling, was until now reserved for attacks against AI models. It has just crossed a new frontier: your business email inboxes.
What is ASCII Smuggling?
ASCII Smuggling involves inserting into an email Unicode characters known as “non-printable” — invisible on screen, but perfectly readable by a machine. To the naked eye, the message appears harmless. To your antispam filter, it contains carefully disguised keywords that evade detection rules.
This technique was first used to inject hidden instructions into AI prompts to manipulate their responses without the user’s knowledge. Attackers realised the same principle applied to email filters — with equally devastating results.

Why Microsoft 365 is in the crosshairs
Microsoft 365 is the ideal target: hundreds of millions of users worldwide, including a large majority of SMBs that rely on Exchange Online and Microsoft Defender for Office 365 to filter their emails.
The risk is twofold. A malicious email can first get through Defender if its detection rules do not recognise Unicode variants. Then, if your SMB uses Microsoft 365 Copilot, an email containing hidden instructions can manipulate Copilot to perform unwanted actions: extract data, draft deceptive replies or transmit confidential information.
The stake for your communication chain
In an SMB, trust in internal communications is a cornerstone. An email that appears to come from a colleague or partner, passing silently through your filters, can trigger fraudulent transfers, disclose customer data or open a gateway into your network.
Attackers are refining their campaigns: short messages, professional tone, spoofed senders. The line between classic phishing and AI-assisted attacks is gradually blurring. This is precisely what Microsoft Threat Intelligence observed and documented this week.
What this means for your SMB
- Enable advanced threat protection: Defender for Office 365 Plan 1 or 2 analyses email behaviour beyond mere keywords, reducing the risk of Unicode-based evasion. If you do not yet have this level of protection, now is the time to discuss it with your Microsoft partner.
- Raise awareness among your teams: an email without a suspicious attachment can still be dangerous. Train your staff to verify the real sender and never act on an urgent request without verbal confirmation or via a second channel.
- Control Copilot permissions: limit Copilot’s access to sensitive data through Microsoft Purview DLP (data loss prevention) policies, so a prompt-injection manipulation cannot exfiltrate your information.
ASCII Smuggling illustrates a deeper trend: techniques born in the AI world are migrating to traditional cyberattacks, rendering conventional defences obsolete. Your SMB, if equipped with Microsoft 365, already has the tools to protect itself — provided they are activated and configured correctly. Want to discuss this? Get in touch with our Axentys experts.