Find notable cyber news and cases, enriched with sources, timelines, and signals.

High-volume Unicode-smuggling phishing campaign

Campaign
First reported
Last updated
Happening score
H score 29
2 unique sources, 2 articles

Summary

Hide ▲

A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The activity first surfaced in early February 2026 and later reached 1 to 2.37 million messages on weekdays. A broader linked operation used ActiveCampaign to distribute AI-generated phishing emails targeting Small Business Administration loan applicants. The evasion technique increases the odds that malicious emails reach recipients and can complicate reputation-based filtering.

Related Happenings

Microsoft dual phishing campaigns using CEO impersonation and passkey lures

Campaign
H score34 First: 13.09.2026 13:11 Last: 13.09.2026 13:11 Sources 1

About this happening: Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enter...

Microsoft 365 Direct Send phishing campaign tracked to US Eastern business hours

Campaign
H score39 First: 11.09.2026 16:30 Last: 11.09.2026 16:30 Sources 1

About this happening: A phishing campaign abused Microsoft 365 Direct Send to deliver 29,785 confirmed phishing emails across July and August 2026, with activity clustering during US...

SVG voicemail phishing campaign

Campaign
H score42 First: 28.08.2026 16:00 Last: 28.08.2026 16:00 Sources 1

About this happening: The SVG voicemail phishing campaign is a broad-spray operation that delivered 26,589 messages to 5,527 organizations, increasing the chance of email-defense bypass and...

Phishing becomes dominant initial access vector across Cisco Talos incident-response investigations, March-June 2026

Trend
H score30 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: Phishing became the dominant initial access vector across incident-response investigations in March to June 2026, raising the risk of credential theft and follow-on co...

UAT-11764 QR code phishing campaign against organizations

Campaign
H score29 First: 28.07.2026 16:00 Last: 28.07.2026 16:00 Sources 1

About this happening: A persistent QR code phishing campaign attributed to UAT-11764 is stealing Microsoft 365 credentials from organizations and reusing compromised mailboxes for follo...

Timeline

  1. 04.09.2026 18:57 3 articles · 13d ago

    Unicode-smuggling phishing campaign peaks at 1 to 2.37 million weekday messages

    Campaign Scope Update

    On February 26, 2026, the phishing operation reached its peak weekday volume of 1 to 2.37 million messages while using finance-themed sender domains and ActiveCampaign relays to route click-tracking links through "acemlnd[.]com" and "activehosted[.]com". The campaign used lure patterns such as business loan, line-of-credit, and advance-funding messages to push phishing at scale.

    Show sources
  2. 04.09.2026 18:57 1 articles · 13d ago

    Microsoft warns of phishing emails using Unicode tag characters to evade filters

    Initial Disclosure

    Microsoft warned that a high-volume phishing campaign used invisible Unicode tag characters from the Unicode Tags block U+E0000 to U+E007F to split financial lure words such as "funding" and bypass keyword- and literal-based email filters. The technique makes the text appear normal to recipients while complicating reputation-based filtering and can be adapted to traditional phishing and spam campaigns.

    Show sources