Skip to content
Security

Hackers use invisible text to sneak fake loan offers past email filters

Hackers are slipping fake small business loan offers into your inbox by hiding invisible characters inside normal words. Microsoft says it blocked 99% of these messages, but the campaign is still active. The trick relies on Unicode Tags, a block of codes originally designed for regional flags, now repurposed to confuse spam filters. These characters don't change how the text looks on your screen, but they break the exact keyword matches that email filters use to catch phishing emails.

Matthew Eveland

2 minute read

Security: Macbook Laptop
Photo: Negative Space (CC0-1.0) via Openverse

Hackers are slipping fake small business loan offers into your inbox by hiding invisible characters inside normal words. Microsoft says it blocked 99% of these messages, but the campaign is still active. The trick relies on Unicode Tags, a block of codes originally designed for regional flags, now repurposed to confuse spam filters. These characters don’t change how the text looks on your screen, but they break the exact keyword matches that email filters use to catch phishing emails.

The emails target candidates for U.S. Small Business Administration guaranteed loans. They were sent through the marketing platform ActiveCampaign between February and May. During that time, the scammers used 148 temporary financial domains. Fortra identified 45 unique fake URL domains coming from just 12 sending domains. Each site promised funding within 48 hours for amounts between $4 million and $10 million.

Microsoft reports that spikes reached 2.3 million sends in a single day. The campaign operated at a weekly pace but paused over weekends. Microsoft now recommends treating the presence of these Unicode Tags as an anomaly. They’re rare in ordinary business exchanges. The company used additional layers of Defender for Office 365 to intercept the vast majority of these attempts.

What to check this week

If you run a dental office or a retail shop and receive an unexpected email promising quick, large funding, pause. Check if your email system flags messages with unusual or invisible characters as anomalies. Verify the sender’s domain reputation before clicking anything. Be wary of any offer promising millions within two days. It’s not a loan; it’s a trap.

We’ve seen these invisible text tricks before. They’re clever, but they’re not magic. Your IT person can help you adjust your filters to flag these Unicode Tags. Until then, treat any unsolicited big-money offer with extreme skepticism. If it looks too good to be true, it’s because the sender is hiding something. Literally.

Sources: Brief IA.

Advertisement — 30th West Technology Solutions

30th West Technology Solutions

IT support for Antelope Valley businesses

When you call, you talk to an owner — not a call center.

Veteran-owned · Rosamond · English & Spanish

See what we do

Written by

Matthew Eveland

Matthew Eveland writes SMB Tech News, a weekly read on the security, software and scam news that actually reaches small businesses.

Security