Log in Download Integrations Articles News Pricing FAQ Contact
Русский Қазақша 中文
Spammers embrace "ASCII smuggling": invisible text fools AI mail filters

Ars Technica · September 4, 2026 · 1Cifer

Spammers embrace "ASCII smuggling": invisible text fools AI mail filters

Ars Technica reported that ASCII smuggling, a technique researchers once used to attack AI models, is now widely adopted by spammers. The trick: special Unicode characters invisible to humans are inserted into text — so a message that looks harmless to the recipient reads entirely differently to an AI filter or AI assistant, slipping past defenses.

The danger grows with AI's spread through email: more and more companies let assistants sort mail, produce summaries and even draft replies. An invisible insert can make an assistant summarize a message "in the scammer's favor" or wave phishing into the "important" folder.

For business in Kazakhstan the conclusions are down-to-earth. First, keep mail gateways and filters updated — vendors are learning to strip invisible characters. Second, the staff rule stands and no technique repeals it: decisions about money and access are not made on the basis of a single email, however convincing its AI summary looks. Confirmation over a second channel — a call, a messenger — remains the cheapest defense.

Related stories

Defenders are now embracing prompt injection: AI agents' biggest weakness becomes a defensive weaponEven elite hackers have switched to ClickFix: victims are asked to hack themselvesAn AI assistant hacked via hidden input: a security lesson for every AI adopter

Reading us regularly? Add 1Cifer to your preferred sources in Google — our stories will show up in your news feed more often.

Add in Google

All news →