Spammers Exploit ASCII Smuggling to Bypass AI Email Filters

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Cybercriminals have adopted the ASCII smuggling technique, embedding invisible Unicode characters in emails to evade AI-based spam and phishing filters. This has led to a surge in spam and phishing attacks, as AI systems fail to detect malicious content, causing harm to users and communities. Microsoft researchers reported a significant increase in such incidents.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves the use of AI-related methods (hidden ASCII characters processed by language models or AI systems) to conduct phishing attacks that have already caused harm to victims by stealing personal and financial data. The AI system's role is pivotal in enabling the phishing emails to bypass security filters, leading directly to harm. This fits the definition of an AI Incident as the AI system's use has directly led to harm to persons and communities through cybercrime.[AI generated]
AI principles
Robustness & digital securitySafety

Industries
Digital security

Affected stakeholders
ConsumersGeneral public

Harm types
Economic/Property

Business function:
ICT management and information security

AI system task:
Event/anomaly detection


Articles about this incident or hazard