Cybercriminals are exploiting a technique known as “ASCII smuggling” to hide malicious instructions inside apparently harmless text, creating a new challenge for users of AI-enabled email platforms. Security researchers have warned that such attacks can manipulate AI assistants into producing deceptive content while the hidden instructions remain invisible to users.
What is ASCII smuggling?
ASCII smuggling involves inserting invisible or non-rendering ASCII Unicode characters into otherwise normal-looking text. These characters are not visible in the usual way to a person reading an email, but an AI assistant may still process and interpret them.
The technique takes advantage of characters that do not normally appear visibly on a screen. Attackers can use them to embed instructions that remain hidden from the recipient while potentially influencing an AI system processing the message.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
How can hidden text manipulate an AI assistant?
A malicious email can contain hidden instructions designed to affect the behaviour of an AI assistant. While the recipient sees an ordinary message, the AI system may process both the visible content and the concealed instructions.
Researchers have demonstrated how such hidden instructions could potentially cause an AI assistant to generate a phishing link when a user asks it to summarise an email.
This creates a particularly difficult situation because the resulting phishing content can appear as part of an AI-generated response rather than as an obvious suspicious link contained in the original email.
Why can this make phishing harder to detect?
Traditional phishing warnings often focus on suspicious links, attachments, unusual senders and obvious requests for sensitive information. ASCII smuggling can make those warning signs less apparent by placing malicious instructions in content that users cannot see.
The technique can potentially bypass security measures designed around visible email content. The danger increases when users trust an AI-generated summary or response without checking the underlying message carefully.
Security researchers warned that attackers may adapt their techniques as AI assistants become more deeply integrated into everyday email services.
What should users do with suspicious emails?
Users should remain cautious about emails claiming to come from police, government agencies, banks or other authorities, particularly when they create urgency or demand immediate action.
If an email claims that a person is under investigation or must urgently contact an official, the recipient should independently verify the claim rather than relying on phone numbers, links or other contact details provided in the message.
Users should also avoid opening unexpected attachments or clicking unfamiliar links, especially shortened URLs or links received through unsolicited messages.
How can users protect their banking and personal information?
Passwords for banking accounts and other important services should be changed regularly, with different passwords used across accounts. Users should avoid reusing the same password for multiple services.
People should also be wary of messages promising prizes, job offers or other benefits while asking for money or personal information. Such offers should be independently verified before any payment or information is provided.
Applications should be downloaded only from official stores such as Google Play Store, Microsoft Windows Store and Apple App Store.
Why are software updates and antivirus protection important?
Users should keep their operating systems and security software updated. Antivirus products should also receive regular updates so that newly identified threats can be detected.
The expert advises against downloading software from unofficial websites or unfamiliar platforms. Files shared by unknown sources should be treated cautiously because they may contain malicious software or other harmful content.
What should victims do after an online fraud?
Anyone in India who falls victim to an online fraud should immediately call the 1930 cybercrime helpline or file a complaint through the National Cyber Crime Reporting Portal.
Quick reporting is particularly important when money has been transferred to fraudsters, as early action can improve the possibility of stopping or tracing the transaction.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.